Virus - NOD won't run in safe mode

Discussion in 'ESET NOD32 Antivirus' started by Amine, Sep 19, 2008.

Thread Status:
Not open for further replies.
  1. Amine

    Amine Registered Member

    Joined:
    Sep 19, 2008
    Posts:
    3
    I installed ESET NOD32 antivirus business edition soon after this problem. Is the non business edition better? I have both.

    Preface-Like this title says, it starts scanning and it couldn't open page.sys or pagefile.sys or something like that. So the command prompt stops and ESET NOD 32 business edition stopped running. I wish I could remember exactly but I can't reset now, running another scan (not in safe mode, works there)


    system specs:

    Windows XP Home, version 2002, SP2.
    Toshiba Satellite Laptop 1.73GHz, 512MB RAM



    Help me figure out what I'm dealing with, and how to fix it.

    Okay, somehow I have spyware on my computer and have no idea how. The websites I was visiting were definitely trusted. I didn't download anything besides trusted torrents, and only a few before this happened, just .avi and .mkv. They can't be turned malicious can they? I dunno.

    I felt like I got the virus from someone on AIM, without accepting any files. He messaged me saying 'hey who are you.' That's not important, just that I still don't know how he knew me. He did give me his real name cuase I checked his s/n on google and saw his myspace. So that makes me think it wasn't him.

    Here's what does and doesn't work so far. My desktop background went bright blue with a window saying I have spyware. As far as I know, windows doesn't do that. A window popped up saying to install anti-spyware wanting me to click to install.. Uhh.. hell no I wasn't doing that. Seemed like part of the virus. I can't physically change my background the tradtional way. The desktop tab in display properties is simply gone. There's only "themes, Appearance, and Settings." I can only imagine what else is messed up. System restores still don't work either.



    About 2 and a half hours ago this happened. So I'm like duh, system restore. All my restore points were gone. Crap. Then I of course ctrl+alt+del bringing up the processes list. I immediately saw new files which I didn't recognize. I think like 5 of them. I got rid of them and went into msconfig to disable everything that looked bad at "startup," and at "boot."


    Internet explorer would be running in the processes without me opening or seeing it anywhere. So I would end that process, and it would come back 30 seconds later or so. The other files are METAMA~1.exe and METAMA~2.exe. No clue what those are probably doing. Another file I've seen before was msiexec.exe or something like that. Damn I wish I remembered. But I know I've seen that on another infected PC before. The last 2 files were just random letters and characters .exe that were probably running the show. I think I found it .tt3E6.TMP.exe

    Okay I just found 5 files are starting with a . looking similar to what I just said above. NOD found them clean... but I know they're malicious somehow, so quarantined them. I found another thing in startup, ARGSMMSG.exe, which is definitely a trojan, but it was disabled at startup already. I removed that with RegCure.


    I don't know what to do next. I'm going to restart my comp and see how things look, and I'll update from there.
     
  2. Amine

    Amine Registered Member

    Joined:
    Sep 19, 2008
    Posts:
    3
    Okay here's a quick update. I got a PM to try freedrweb.com/ but for some reason I received a "Page Load Error." I'm guessing it's the virus' doing because I never had that error before tonight.

    Also, the internet explorer that constantly reappears in my process menu has the user name "SYSTEM". It's supposed to be user name "Mine"

    I found out it was being opened via svchost.exe through a process manager program. But now after I found that out I noticed I had like 6 svchost.exe. Normally I had like 2 or 3 I think. So the one was using over 20,000K memory, I ended that process tree and nothing bad happened. I tried 'end process tree' on another one and my computer had to reset because I closed the real one. Gah, I have no idea what to do. I'm doing a full scan of my hard drive with updated ESET NOD32.

    I put all the metamail files in quarentine because NOD couldn't find anything malicious about it, I dunno.

    What should I do?
     
  3. ASpace

    ASpace Guest

    What is the version of the program (the business edition) ? 3.0.xxx what ?
     
  4. Amine

    Amine Registered Member

    Joined:
    Sep 19, 2008
    Posts:
    3
    It's version 3.0.669.0

    I'm trying that CureIT from download.com instead now.


    edit: By the way, the file NOD gets stuck on in safe mode is pagefile.sys, then it said error cannot open or something like that.

    edit again: problem solved with malwarebytes. Thanks
     
    Last edited: Sep 19, 2008
Thread Status:
Not open for further replies.