Page 1 of 2

Virus infection! Are music files OK?

PostPosted: Mon Dec 22, 2008 5:32 pm
by The KIDD
Hey Gang,

I know its been mentioned to not use the same computer for recording and internet usage.Well, that was good advice becuase now Ive got that nasty malware/virus that reeks havoc on the net not letting you go where ya wanna go. Cant access G mail, Myspace etc.It masked itself as a anti virus program and cant uninstall it becuase it doesnt show up under add/remove programs..Ive un plugged the internet.So far, Ive been about to run Cool edit without any probs ..It runs sluggish but it runs.Ive been porting my session files to another computer and Avast (AVG) hasnt detected anything on the good computer.Anyway, just wonderin if virus areknown to infect music files?..I had been running adware on the bad computer every 2-3 days but noticed weird things were happenin like this "certificate authorization error"pop up that wouldnt let me get my mail etc. I was told , believe it or not, That I didnt need anti virus that this adware would remove anything that found its way in...Like I say , I cant use the internet and sometimes the computer takes 2-3 tries to boot AND and takes 1-2 times of "End Program" to finally shut down BUT, I can record.. Paleopete even tried to help but this thing aint going away even after adware removes it.Anyway, I know there alot to this and Ill prolly have to re-formatt but I was just wanting to see if anyone ever had infected music files.The virus is called "Virtumonde" and there like 5 little links that show registry paths its infected.

Thanks , John

PostPosted: Mon Dec 22, 2008 5:38 pm
by RyanStrain3032
http://www.avast.com/eng/download-avast-home.html

That's Avast...The best free anti-virus program ever. It finds things that even Norton, McAfee, and PCcillin combined could never find.

After I installed it, before I even started a scan, it IMMEDIATELY found 13 viruses/trojans.

Your music files SHOULD be fine. Just install this and run a scan.


But if that doesn't work, consult a technician...And if he can't do anything, you may be forced to reformat your computer. Just backup important files: music/pictures/documents/finance files. Then put in the Operating System CD and restart, then choose to reformat your drive.

Let's hope it doesn't come to that though.

PostPosted: Mon Dec 22, 2008 5:47 pm
by The KIDD
Hey Ryan,

Thanks man.I do have avast on this computer. Its been on here since I got it..However, on the new computer I use to record on, I could find the free version and just assumed it wasnt free anymore.Anyway, the virus will not let you download anything..I cant even go to the site.Id already tried..You cant go ANYWHERE like that..Thats part of the way it reeks havoc.If someone had it on a CD, I might be able to.Yeah , Ive been porting my music files to this computer and Avast hasnt detected anything.So..??..Im gettin LOTS of exercise though..The studio is in the basement and Im stairs 2nd floor...Im gonna wear out this thumb drive... :lol: I wonder if I could copy the AVG files from this computer to the bad one? Would it install it???

John

PostPosted: Mon Dec 22, 2008 6:42 pm
by Chippy
I agree AVAST is very good.

PostPosted: Mon Dec 22, 2008 8:45 pm
by Andragon
John, send me your e-mail address through Myspace.

PostPosted: Tue Dec 23, 2008 4:08 am
by Paleopete
Read this for virtumonde removal instructions. Now that I know what it is, I know what to look for. It can be removed. not sure if Spybot will remove it or not, but it might, I don't remember. It's been a while since I had to deal with it.

LINK:

http://www.bleepingcomputer.com/malware ... virtumonde

Print it out if possible or copy and paste into a text file so you can refer back to it later. DO NOT try to run Hijack This yourself, it's a great tool but you have to know exactly what you're doing, it can trash Windows pretty good if you remove the wrong registry entry. I added this note because you might have someone recommending hijack this.

I'll try to keep an eye open for this thread to check your progress, and if possible offer some more assistance or info.

PostPosted: Tue Dec 23, 2008 5:19 am
by The KIDD
Hey Paleopete,

I wish I could down load something like that BUT, with this virus , I cant even navigate the net.I cant even go to google. What ever I get to remove this will have to come from a disk..

Thanks anyway,
John

PostPosted: Tue Dec 23, 2008 11:28 am
by Chippy
Step 1.
FREE: Spyware Malware Removal Tool
http://www.superantispyware.com/superan ... vspro.html
Install and Run...... Once complete.

Step 2.
FREE: Registry cleaner
http://www.snapfiles.com/download/dleusingregistry.html
Install and Run...... Once complete.

Step 3.
Home Edition Avast
http://www.avast.com/eng/download-avast-home.html

If anyone uses these it would be great to donate to the top two and purchase avast. It's polite and they are very good tools and people will develop more for us.

Hope this helps?.

PostPosted: Wed Dec 24, 2008 2:59 pm
by Paleopete
John: If we manage to get together today I'll try to have everything with me to deal with it. Already have most of it on a USB drive ready to go.

PostPosted: Wed Dec 24, 2008 3:03 pm
by Starfish Scott
Dear computer forlorn..

When your system is so fuct that it won't let you get online or dl anything, just remove the files you wish to keep.

(This is why you have a CD RW)

Then reload.

If you crap is so banged up, I'd rather doubt that installing anything will bring it back to full power without a reload. (if it will even install)

But be my guest and try, I always laugh when I see machines that take 24+ turns of the wear bar to actually come to desktop.

Usually it's about 4 turns at worst case scenario unless you are running JUNK.

PostPosted: Thu Dec 25, 2008 12:55 am
by The KIDD
Hey Capn,
So what your sayin is that even with a authentic XP disk, this HD may not formatt?..Id heard that after getting this type of trojan..BUT, how do ya know whether youve totally gotten rid of it?..Ive heard that it can bury itself in the boot sequence or something like that..We're gonna wipe the HD clean tonite using an XP disk. Even Paleopete brought some virus killer exe's over on his way back and the puter wouldnt let ANY of them downlaod.Its so saavy that its done away with "folder options"..I cant get into my applications data folder..Hell, I dont even have a tab for it anymore in " My Computer"All I care about is gettin my sound card drivers back that I had (old creative) and MAYBE gettin in there in the applications foler and gettin my adobe audtion presets for EQ , FX etc. Man , its been weird through this whole mess.. Adobe has been runnin fine??? AVG on the other comuter has not detected any viruses in the sessions WAV,s and MP3 Ive ported over. BUT, after tonite , I gues Ill find out f Im gonna have to buy another HD.

John

PostPosted: Thu Dec 25, 2008 5:09 am
by MattFSax
use this : http://siri.geekstogo.com/SmitfraudFix.php

it's the best virus removal program. It goes right into the programming of your computer to remove the viruses, it's great. Theres detailed instructions on the page.
oh and it's free :)

PostPosted: Thu Dec 25, 2008 4:19 pm
by Starfish Scott
I reload about 15 machines every 3 days +/- 3 machines.

One thing I noticed, when it's bad it's generally worse than you think.

Take notice of how many processes you have once your machine is configured. And then how many turns on the windows wear bar it initially takes to come to desktop.

So if you are taking 5 turns and about 22 processes and you suddenly develop more processes or more turns to come to desktop, you have an issue.

As for a windows disk? I made an ISO of a windows disk and I keep one at home, 1 at the shop and 3 in the car. As long as your key is ok, you shouldn't have an issue. (although I have seen this before as well) Reload as often as you must, every 6 months is recommended.

And don't forget your chipset driver before and after you do video drivers.

PS ANYONE knows to run cleaners/anti-virus stuff in safe mode. To do otherwise means that you run the risk of it coming back via sys restore.

Take the files you want to keep, scan for virus, copy to storage and remove. Then reload.

Hijack this is a joke. It doesn't remove anything unless you know what it is.

Lavasoft ad aware
Spybot s+d 1.61?
x-cleaner
bazooka scanner
possibly win defender if you can get it not to be a resources hog..

We run these 5 in order to clean your system. If said system should even whimper afterwards, it gets reloaded. Nod32 is another one we use if it's really bad.

MANY systems are not clean after this and get reloaded. WE use Sysandra and 3dmark and it averages about a 30-40% resources gain cleaned vs reloaded. (quantitative results do not lie)

Do what you will do in SAFE MODE, KID. If it still acts funny, break HD under heel of foot and replace it.

(We do see cases of cleaned machines that still manage to retain malware/trojans/etc and those are the ones we crush under foot)

I'd love to give an explanation, but I don't have one. If we reload it and it keeps a virus/malware, we immediately replace HD.