Virus help please...

Hey,

Heres the scenario: I was helping my friend charge his ipod at my house, plugged it in and for the life of me dont know why I clicked "Images.exe" which had a folder icon. Double-clicked it, whatever it was executed, and im like "aaah how could I fall for that!!!" Now I'm sitting here with some sort of virus that wont let me run any executable file, not even windows task manager, for longer than 3seconds. The glimpse I get at the task manager shows this qm4920.exe entry that never was there before.

When I searched myadsl for previous virus threads, Firefox somehow closes before I get to read the thread, but I can read other threads fine. Can't install any anti-virus programs and Trend's house call wont work now.

System is running WinXP Pro sp2.

Any help is appreciated.

Oh, formatting/re-installing is out of the question... just backed my contacts and other data from my cellphone to pc, as the cellphones gone for repairs.

Thanks in advance.

The best and only way that works is ti install the drive as a 2nd to an already protected system. AS SUGGESTED BY GRU
THE BADDIES ALSO TEND TO HIDE IN THE RESTORE FOLDER.
You should also disable restore clean the drive and then re-enable the restore folder (System Restore).

MPN Moenie panic nie.
 
I think your best option would probably be to hook it up to an uber-secure PC so it can sort it out for you :)
 
Thanks for ALL the help hey! I tried a lot of methods here which didnt work :( The msconfig trick would have worked if this thing didnt keep closing the exe. Also, I couldn't browse this thread as it wouldnt let me, would close firefox after a few seconds so I had to resort to printscreening the replies very quickly, lol!

In the end I said ***kit and formatted and reinstalled less my phone info :( Oh well, installing plenty AV now... I enjoyed my AV-less trip on the net while it lasted. :P

Thanks alot :) !
 
Thanks for ALL the help hey! I tried a lot of methods here which didnt work :( The msconfig trick would have worked if this thing didnt keep closing the exe. Also, I couldn't browse this thread as it wouldnt let me, would close firefox after a few seconds so I had to resort to printscreening the replies very quickly, lol!

In the end I said ***kit and formatted and reinstalled less my phone info :( Oh well, installing plenty AV now... I enjoyed my AV-less trip on the net while it lasted. :P

Thanks alot :) !

Pity you couldn't hang in there with us for a while. You could also have done a recovery install.

Better luck next time (He He He)
 
Last edited:
HAHAHHA just saw it left me a .txt on C:\ titled: "Baca Bro!!"

" BRONTOK.C[22]



Sedikit Jawaban u/ Membungkam Mulut Sesumbar 'MEREKA'.

Nobron = Satria Dungu = Nothing !!!
Romdil = Tukang Jiplak = Nothing !!!

Nobron & Romdil -->> Kicked by The Amazing Brontok




[ By JowoBot ]"

AVG picked up the I-Worm/Brontok.cg virus.
 
Hey,

Heres the scenario: I was helping my friend charge his ipod at my house, plugged it in and for the life of me dont know why I clicked "Images.exe" which had a folder icon. Double-clicked it, whatever it was executed, and im like "aaah how could I fall for that!!!" Now I'm sitting here with some sort of virus that wont let me run any executable file, not even windows task manager, for longer than 3seconds. The glimpse I get at the task manager shows this qm4920.exe entry that never was there before.

When I searched myadsl for previous virus threads, Firefox somehow closes before I get to read the thread, but I can read other threads fine. Can't install any anti-virus programs and Trend's house call wont work now.

System is running WinXP Pro sp2.

Any help is appreciated.

Oh, formatting/re-installing is out of the question... just backed my contacts and other data from my cellphone to pc, as the cellphones gone for repairs.

Thanks in advance.

Try and run the .exe files by changing the file type and use the right click "Run As" or change the .exe to .com or .xxx and run

See
http://support.microsoft.com/kb/310585


I cleared a similar problem on a clients computer with Avast.

http://www.avast.com/eng/avast-virus-cleaner.html


You may also use AVG Vcleaner.exe renamed to Vcleaner.com

See
http://www.avguk.com/doc/34/uk/crp/4/ndi/67751

http://www.cybertechhelp.com/forums/showthread.php?t=11147

Companion virus
Affects: Any operating system.
Replication: A companion virus will rename either itself or its target file in an attempt to trick the user into running the virus rather than another program. For example, a companion virus attacking a file named GAME.EXE may rename the target file to GAME.EX and create a copy of itself called GAME.EXE. Alternatively it may simply rename itself to GAME.COM and rely on the user running 'GAME' from a command prompt as the operating system would then run GAME.COM rather than GAME.EXE.

Naming: There is no standard naming convention for this type of virus.
 
Last edited:
Why? They produce the viruses to remain in business.

I've heard that theory before... Any proof of that?

Same here. Heard that rumour, but would like proof.

In general, the majority of virus/trojan/r00tkit writers do it for the money as their experience is best suited for nefarious purposes and there's crooks and ne'er-do-wells out there who want to obtain your banking and other information by any means whatsoever.
 
I've heard the rumors too, don't take them too serious. If just one disgruntled employee supplied proof about a company doing that, then they'd go out of business. Somehow it just dont seem worth it to me
 
I've heard the rumors too, don't take them too serious. If just one disgruntled employee supplied proof about a company doing that, then they'd go out of business. Somehow it just dont seem worth it to me

Why would they need to write malware anyway? The malware writers make so much cash from their creations that they will keep on doing it and there are so many malware apps out there that the AV companies can't catch them all quickly enough. If anything I am sure that the AV companies would prefer there to be fewer pieces of malware cause that would make their jobs easier ;)
 
Top
Sign up to the MyBroadband newsletter
X