Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Strange virus

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
Rawss.
Grandmaster Cheater Supreme
Reputation: 3

Joined: 14 Nov 2007
Posts: 1687
Location: Glasgow, Scotland

PostPosted: Sun Feb 27, 2011 5:10 pm    Post subject: Strange virus Reply with quote

Okay so about an hour ago I got this pop-up message on my computer but when it came up I pressed 'enter' because I was sending a message so I didn't get a chance to read the message because when I pressed enter it started this programme called 'system tool'.

I've never seen this programme in my life and I really don't remember installing it or whatever, but it started scanning my computer and then I got a message saying that I had 8 viruses and I needed to delete userinit.exe

I tried opening my antivirus but it wouldn't let me open anything (even taskmanager) and I kept getting notifications which told me to start my antivirus and whenever I clicked them it took me back to this programme.

I checked online and it looks as if deleting userinit.exe is a bad move. I reset my laptop and the problems still there but I can open programmes now and I'm virus scanning just to see if it'll show up.

Also, like 20 minutes ago it changed my desktop background to the attached image.

I tried booting up in safe mode and trying to locate the programme and delete it but it doesn't seem to be installed anywhere, so I'm kinda worried. I have googled some stuff but it just confused me more and I couldn't find anything relating to Windows 7 so I was wondering if any of you knew what the hell I've done?
Back to top
View user's profile Send private message Send e-mail AIM Address
Choycolate
Master Cheater
Reputation: -1

Joined: 18 Oct 2008
Posts: 284

PostPosted: Sun Feb 27, 2011 5:46 pm    Post subject: Reply with quote

Ok thats is a funny virus. U can try restoring u PC if its premade. Or u can just reinstall Ur OS. or http://answers.yahoo.com/question/index?qid=20080308115127AAtyOEM
_________________
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Hero
I'm a spammer
Reputation: 79

Joined: 16 Sep 2006
Posts: 7154

PostPosted: Sun Feb 27, 2011 5:59 pm    Post subject: Reply with quote

Get malwarebytes and scan. It normally removes weird shit like this. If you must, try scanning in safe mode.
Back to top
View user's profile Send private message
Kardi
Expert Cheater
Reputation: 1

Joined: 03 Jul 2008
Posts: 204
Location: + rep me!

PostPosted: Sun Feb 27, 2011 6:48 pm    Post subject: Reply with quote

Find out the process of the virus if you can. Often with this crao you need to delete shit even after malwarebytes.
Back to top
View user's profile Send private message MSN Messenger
InternetIsSeriousBusiness
Grandmaster Cheater Supreme
Reputation: 8

Joined: 12 Jul 2010
Posts: 1268

PostPosted: Sun Feb 27, 2011 8:51 pm    Post subject: Reply with quote

rockista80 wrote:
Ok thats is a funny virus. U can try restoring u PC if its premade. Or u can just reinstall Ur OS. or http://answers.yahoo.com/question/index?qid=20080308115127AAtyOEM

^this

malewarebytes should also find the file.
Back to top
View user's profile Send private message
ZacTheSin
I post too much
Reputation: 6

Joined: 09 May 2006
Posts: 2657

PostPosted: Mon Feb 28, 2011 5:32 pm    Post subject: Reply with quote

Lol this virus.

I see it like 10 times a day.

Anywho, boot into safemode then run Combofix.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

DO NOT DOWNLOAD IT FROM COMBOFIX.ORG

The scan will take about 20 minutes max.

_________________
If someone helps you, why not Rep them?
Back to top
View user's profile Send private message
Rawss.
Grandmaster Cheater Supreme
Reputation: 3

Joined: 14 Nov 2007
Posts: 1687
Location: Glasgow, Scotland

PostPosted: Wed Mar 02, 2011 1:31 pm    Post subject: Reply with quote

Hey guys

Thanks for the feedback. I downloaded SAF but the problem I have now is that my laptop keeps shutting down, so I can't complete a scan. Do you know any way around this?
Back to top
View user's profile Send private message Send e-mail AIM Address
AhMunRa
Grandmaster Cheater Supreme
Reputation: 27

Joined: 06 Aug 2010
Posts: 1117

PostPosted: Wed Mar 02, 2011 1:44 pm    Post subject: Reply with quote

Under Startup and Recovery, under System Failure uncheck "Automatically Restart". Control Panel | System | Performance if it's hardware or software related should show you an error message before shutting down.
_________________
<Wiccaan> Bah that was supposed to say 'not saying its dead' lol. Fixing >.>
Back to top
View user's profile Send private message
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Wed Mar 02, 2011 2:37 pm    Post subject: Reply with quote

More details: http://www.bbc.co.uk/news/technology-12608651

You can try to boot into recovery mode and restore your system to an earlier time.
Back to top
View user's profile Send private message
ZacTheSin
I post too much
Reputation: 6

Joined: 09 May 2006
Posts: 2657

PostPosted: Thu Mar 03, 2011 3:06 pm    Post subject: Reply with quote

Or you can just run the damn virus removal program I suggested.

D:<

_________________
If someone helps you, why not Rep them?
Back to top
View user's profile Send private message
AhMunRa
Grandmaster Cheater Supreme
Reputation: 27

Joined: 06 Aug 2010
Posts: 1117

PostPosted: Sat Mar 05, 2011 7:40 am    Post subject: Reply with quote

No need to run anything to clean it. You can if you like. My daughter got this on her computer Thursday night. I fixed it yesterday manually it took 10 minutes.

If your account is not administrator you can clean it in less than 10 minutes from SafeMode.

Boot to Safe Mode, run regedit under your user account. Navigate to HKCU\Software\Microsoft\Windows\CurrentVersion\Run Look for an entry that sorta looks like the word schizto. The virus is using Run32dll.exe to call a dll that is the actual virus. Removing this entry from the registry disabled it. The offending dll is located in C:\Users\<USER>\AppData\Local\djksjdlkajw.dll. Once it was deleted, rebooted into Windows ran complete scan, came up clean, no more pop up windows.

If you run an account that has administrator privies then you may need to reformat and reinstall. If administrator privilages are present it could propagate to every other user account. You would need to clean them all. And it could also affect other system exe's or dll's.

_________________
<Wiccaan> Bah that was supposed to say 'not saying its dead' lol. Fixing >.>
Back to top
View user's profile Send private message
ZacTheSin
I post too much
Reputation: 6

Joined: 09 May 2006
Posts: 2657

PostPosted: Mon Mar 07, 2011 4:16 pm    Post subject: Reply with quote

AhMunRa wrote:
No need to run anything to clean it. You can if you like. My daughter got this on her computer Thursday night. I fixed it yesterday manually it took 10 minutes.

If your account is not administrator you can clean it in less than 10 minutes from SafeMode.

Boot to Safe Mode, run regedit under your user account. Navigate to HKCU\Software\Microsoft\Windows\CurrentVersion\Run Look for an entry that sorta looks like the word schizto. The virus is using Run32dll.exe to call a dll that is the actual virus. Removing this entry from the registry disabled it. The offending dll is located in C:\Users\<USER>\AppData\Local\djksjdlkajw.dll. Once it was deleted, rebooted into Windows ran complete scan, came up clean, no more pop up windows.

If you run an account that has administrator privies then you may need to reformat and reinstall. If administrator privilages are present it could propagate to every other user account. You would need to clean them all. And it could also affect other system exe's or dll's.


The djksjdlkajw.dll is actually a randomly generated name. It changes.

There will still be trace files in the computer. I recommend running combofix rather then jumping into the registry - which is very dangerous. It's not like I do this for a job or anything.

_________________
If someone helps you, why not Rep them?
Back to top
View user's profile Send private message
AhMunRa
Grandmaster Cheater Supreme
Reputation: 27

Joined: 06 Aug 2010
Posts: 1117

PostPosted: Mon Mar 07, 2011 7:01 pm    Post subject: Reply with quote

I do, 2 days now and no further sign of infection.
_________________
<Wiccaan> Bah that was supposed to say 'not saying its dead' lol. Fixing >.>
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites