Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

TorchTheWitch

(11,065 posts)
Sun Jun 28, 2015, 03:21 AM Jun 2015

Huge Emergency!!!

Last edited Sun Jun 28, 2015, 06:51 AM - Edit history (1)

UPDATE: I found this page that gives you various ways to get rid of what at this point I'm about as sure as I can be is called Trojan.Poweliks...
http://malwaretips.com/blogs/remove-explorer-exe-virus/
None of the suggested ways to get rid of this thing work as whoever is responsible for the infection has corrupted all of the suggested software so that they won't work. For trying to use MalwareBytes it won't let you open the Run dialog box or let you update MalwareBytes. For the HitmanPro, something happens with Windows system files it finds where the files that show up as being infected are mysteriously hijacked and removed from the program so you can't delete them. For RogueKiller, I'm almost done the scan, but I think the evil person that is responsible for this trojan has corrupted everything it tells you in the guide at malwaretips to use to get rid of it. HELP!

_________________________________________________________________

I think I may have a hideous virus. Nothing at all that I'm doing is working. Around noon on Saturday (technically yesterday now since it's after midnight) I tried to download a video from YouTube of the Boston Gay Men's Chorus because I thought I saw my brother in the video. He's been a tenor with them for many years (the rest of us are tone deaf shower singers, but he was blessed with a gorgeous voice). I used FlashGot to try to download the video to my computer since in trying to watch videos on YouTube I've always had massive buffering problems. As a side note, the guy I thought was him just can't be since my brother would have much more gray hair than whoever it was that I thought was him, but they do look amazingly alike).

I think there must have been a virus attached to that file or some other video file on the page. This was the first time I've tried using FlashGot because I've always used to use Video Download Helper, and for some reason that automatically updated to a new version that doesn't work anymore as all it would let me do is a screen capture of a video (lots of other people had the same problem, and it's not fixed yet). So I got the FlashGot Add-on from Firefox and used that instead.

Because I'd never used it before, I think I accidentally told it to download all the videos on the page at YouTube, and there were 26 of them, so it could be another video than the one I wanted to download that may have come with a virus. I tried to stop the download and couldn't figure out how, so I did a reboot, and suddenly my entire computer went to crap with the massive slows and not finishing starting up everything on the desk top.

I tried to delete the one YouTube video that had started to download and it told me that some other file was using it and it wouldn't delete. Except I didn't have anything open, so I'm thinking that there was a virus attached to that video that won't let me delete it, but I have no idea what file that would be (the one that says it's using the video file).

I went into my task manager and saw that the explorer.exe file was sucking up 97% to 100% CPU. This had happened once before years ago, and I got rid of it by updating IE to version 8 which is the last version that can be used with XP (I have XP Pro and have never had the money to upgrade, and until this it's been just fine).

I went into Safe Mode and tried to do a MalwareBytes scan, but it was out of date and wouldn't let me update it. That was the first notion I got that this was a virus. I also always have AVG running, and it catches everything. AVG won't let me update either. So, then I'm REALLY thinking that this is a horrible terrible virus.

In Safe Mode I did a System Restore, and for the first time EVER using XP it "says" it worked, except that the blue line that indicates that it's restoring to a later date never came to the end, and the automatic reboot happened as if it was finished restoring, and that damn video is still there, I still can't delete it for the same reason, and I still have the same problem with explorer.exe sucking up 99% to 100% CPU. No change. Still have the problem. And now I think that this virus fiddled with System Restore as well because that has NEVER worked in XP (my fix it computer guy told me the last time he was here that XP always had issues with System Restore not working).

AVG tried to do an automatic update like it normally does every night and it won't complete. I don't know if that's because of how slow the computer is running or because of some virus, and I'm thinking it's a virus since it's not letting me get rid of this video I tried to download that started this mess, and I can't update either AVG or Malwarebytes even in Safe Mode, and AVG never caught it to begin with.

I've tried everything I can think of to fix this mess, and I can't figure it out. I left a message for the computer fix it guy, and found out that he merged his company with another one, they have a new name, and he didn't call me back because apparently they now close at 3pm on Saturday and he won't be back in the office until noon on Sunday. The bigger problem is that it now costs $99 per hour of his time, and I've never paid anything close to that before, and he always used to charge the set rate for as long as it took to fix the problem, and if for some reason he couldn't fix it, he charged nothing at all.

I only have about $100 to my name. I also finally got the notice last Thursday on my door that I'm to be physically removed from here at noon on July 6th if I'm not gone before then, and I still can't find a way to get out of here. I've been doing writing work for crowdsource for a couple of weeks like crazy, but they pay a fraction of minimum wage, and I still have about $50 of work still pending in the editing pool. Worse, I can't get into paypal with this computer virus or whatever the hell it is because every time I try because the computer is going so damn slow it's timing out before I even can get logged in to see if any more money has come in yet from my work that I can transfer to my bank account and use.

I HAVE to get my computer working right again, and I don't think I'll ever be able to afford to have my computer guy come out to fix it. Every single moment right now is vital or I'm going to be out on the street and lose all my stuff and my dog, and my new job that hasn't bloody started yet!

That's another thing... I FINALLY got a long term temp job with a medical supply company through one of the agencies I've been dealing with, but I had to take a urine drug test on Friday, and Monday I still have to do a vision test, and the company doesn't get the results for a few more days after that, so I don't even think the job will start until I've already been thrown out, though I'm still struggling to find a way to avoid that somehow. I HAVE to get this computer fixed of whatever this problem is as fast as I possibly can. This is just the worst time in the world for this to happen!

Can anyone help me to fix this problem? I'm not very computer savy. But nothing I've tried has done anything, and every time I reboot it seems to get worse. Right now the internet seems to be doing ok, though it takes a loooooong time to get a page to open. It took me nearly 15 minutes just to get into DU, but once a Firefox page opened it seems to move along ok at that point (I hope).

7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Huge Emergency!!! (Original Post) TorchTheWitch Jun 2015 OP
To get Malwarebytes to work if blocked follow these steps. hobbit709 Jun 2015 #1
ok, trying this now - UPDATE: shit it won't even let me get into "My Computer"! TorchTheWitch Jun 2015 #2
Have you tried downloading to removable media? teach1st Jun 2015 #3
I don't have a removeable drive TorchTheWitch Jun 2015 #4
Not even a thumb drive? teach1st Jun 2015 #5
no, never have TorchTheWitch Jun 2015 #6
Just wanted to say thanks for the attempted help TorchTheWitch Jul 2015 #7

hobbit709

(41,694 posts)
1. To get Malwarebytes to work if blocked follow these steps.
Sun Jun 28, 2015, 10:01 AM
Jun 2015

1. go to My computer, select C: drive
2. Go to Program Files and open the folder
3. Open the Malwarebytes folder
4. Go to the Chameleon folder and open it, if there's a subfolder Windows open it
5. Find mbam-chameleon.exe and double click it.
6.It will open a command prompt window and ask you to hit enter.
7. when it finishes killing malicious processes and updating it will open the regular Malwarebytes program and start scanning.

TorchTheWitch

(11,065 posts)
2. ok, trying this now - UPDATE: shit it won't even let me get into "My Computer"!
Sun Jun 28, 2015, 05:01 PM
Jun 2015

It's corrupted that too! Any other suggestions? I downloaded ComboFix, but it says not to use it without help by someone that knows how, so I don't dare try to use it, but now that I have downloaded it I'm afraid it's corrupted that by now, too. I'm at a total loss!



teach1st

(5,935 posts)
3. Have you tried downloading to removable media?
Sun Jun 28, 2015, 09:12 PM
Jun 2015

Download the tools to a removable drive and try (in safe mode) to run them directly from the drive.

Try running Rkill (from Bleeping Computers) from the drive first. It's supposed to help kill those stubborn processes which apparently have hijacked your machine. http://www.bleepingcomputer.com/download/rkill/

Then, without restarting, run any of the other tools.

I have had good look with Emsisoft Emergency Kit: http://www.bleepingcomputer.com/download/emsisoft-emergency-kit/

Depending on what has a hold of your computer, you may want to run in safe mode with no networking first, and then go back to safe mode with networking so your tools can update. (Hitman Pro won't run without networking.)

I've used ComboFix without problems, but I have experience. You might want to think of it as a last resort.

Do you have an install disk for your operating system?

TorchTheWitch

(11,065 posts)
4. I don't have a removeable drive
Sun Jun 28, 2015, 11:52 PM
Jun 2015

I don't know anyone that does either. I've also never had my own operating system disc since Windows 98. They don't give them to you anymore, and I think that's criminal. At this point I'd rather have Windows entirely replaced and put back on those programs I have on disc. Every time I try something else to fix this evil thing even in Safe Mode it only spreads and gets worse.

I have to spend all the money I have left for the fix it guy to come and deal with this evil thing. I don't even know why I'm doing it since at noon on the 6th I'll be physically removed from here and have nowhere to go and nowhere for my stuff to go and nowhere for Yoshi to go. There's just things I need to use the computer for before that day comes. This was just the last straw.

teach1st

(5,935 posts)
5. Not even a thumb drive?
Sun Jun 28, 2015, 11:56 PM
Jun 2015

You can use a thumb drive (other names people use are USB stick, flash drive) to download the programs to.

TorchTheWitch

(11,065 posts)
6. no, never have
Mon Jun 29, 2015, 04:26 AM
Jun 2015

I didn't even know what one was until about a year ago. I can't even have ever afforded to upgrade from XP, I certainly couldn't afford anything so luxureous as one of these external drive widgets I never had a reason to have anyway except for something like this.

I'm not seeing how it would make any difference anyway. Anything I downloaded I did in Safe Mode, and this dastardly virus STILL corrupted them all. As soon as some new program hits the computer whether in Safe Mode or not regardless where it comes from it gets corrupted with this beast. This thing won't let me open My Documents, or the run dialog box or program files, the search is corrupted and EVERYTHING. I don't even think the fix it guy will be able to put anything on here that works. Windows is just going to have to be wiped out and put on again I think. At this point with everything I tried and all the times I had to reboot it just spread the beast even further.

This is exactly why it makes me so blistering mad that since Win98 you don't get a physical disk anymore of your operating system for exactly these kinds of things. Twice when I had Win98 I got some kind of thing I couldn't figure out how to get rid of (and back then I never heard of any of these fix it programs if they even existed back then), and I just wiped out Win98 and put it back on again with the disc they USED to give you back then so you didn't have to spend the money to have someone fix it. Hell, back then computer fix it people didn't even come to your house. I used to have to go to a place that was expensive as hell and bring the computer to them, AND pay them $75 just to get them to fix it in three days. And that place still exists and still does great business.

Sorry, I don't mean to sound angry at you, and I'm not at all. This was just the last straw, and I just can't take any more.



TorchTheWitch

(11,065 posts)
7. Just wanted to say thanks for the attempted help
Fri Jul 3, 2015, 07:23 AM
Jul 2015

Worst evil beast virus EVER! Even my saintly computer fixer guy couldn't kill it. He came over Monday and wrestled with the beast for 3 hours. Even he said he's never fought any beast this hard and lost. He took my computer back to his shop and wiped it out though he was able to save most of my emails, and documents, etc. I did lose all my bookmarks but that was my fault for forgetting to copy them and having him save that file, too. He had to put in a new hard drive. And he had already replaced mine this same time last year. Almost exactly a year to the day actually.

At least it doesn't seem to have gotten my paypal and bank passwords, and I had no idea that firefox was saving all my passwords for everything on the computer to begin with... what an incredibly stupid idea! Thankfully, I didn't dare go into either paypal or my bank while the beast was eating all my info or it would have gotten them. The beast was sending back everything it found to the creator of the wretched thing. Not even ComboFix in safe mode from a clean copy of his own could kill it or any of the other super-duper special "evil computer thing killers" that he had could... programs I've never heard of that computer fixer people probably have to buy. The second anything landed on the computer to kill it, the beast immediately found and corrupted.

I couldn't get my computer back until late in the day on Wednesday. My saintly fixer only charged me $99 for all that work that just had to have taken even more hours and hours back at his shop and let me back date the check for a month. He's done this kind of stuff before, and I know it can't be just for me... he's just a super good guy. Of all the bills I have that I can't pay (which is all of them) somehow I have to find a way to get him paid in a month more than all the others.

So, thanks for trying, but this horrible beast was just not killable even by an expert with super-duper killer stuff and hours of trying.



Latest Discussions»Help & Search»Computer Help and Support»Huge Emergency!!!