I have an AntiVirus Soft problem!

Solved/Closed
empyrean - Mar 21, 2010 at 12:21 PM
 empyrean - Mar 21, 2010 at 05:14 PM
Hi
I got the virus above which disables me from doing anything.

I've run Hijack This (under a diff. name)... Failed.
I've tried running under Safe Mode which results in the Blue Screen of Death ... Failed.
I've run MalwareBytes ... Failed.
I've tried changing the Internet Explorer LAN setting to run "without Proxy"... Failed.

I'm running out of options. Can anyone help?
Related:

6 responses

Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Mar 21, 2010 at 12:58 PM
Hello,

I think that you forgot on important step which to stop the process.

Here is the complete recipe to poison the Trojan Horse and sent it to the glue factory. Remember to follow each step exactly, do not skip any.

If you dont succeed, there are other ways to skin a cat, I mean Horse.

The virus changes the internet settings to use a proxy server, hence you can't browse.

1. Start Internet Explorer
2. Click on the Tools menu and then select Internet Options
3. Click on the Connexions tab
4. Click on Lan settings at the bottom
5. Uncheck "Use a proxy server for your LAN
6. Click OK

Now you should be able to browse.

As mentioned this Trojan Horse is self protective so you must terminate the processes associated with it otherwise it will keep regenerating itself.

7. Download Process Explorer on your C::

https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer

8. Run the tool and spot any unusual processes, it may be numeric or called, antivirus, security, psecurity, dr.guard, etc.

9. Terminate the process or processes.

10. Download Malwarebyte to your desktop

https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/

Again you must outwit the virus

11. Rename MBAM to Explorer.exe... that should fool the Trojan Horse

12. Install Malwarebyte and from the main page, second tab. make an up-date.

13. Please request a FULL system scan which should take at least 90 minutes.
During the process you may be asked to reboot your computer, please do so.

14. Delete all the items found that are in red.

15. Reboot your system and connect to internet. Should you find that your browser is slow, there may be traces of a redirecting trojan.

If such is the case, download and install Spybot Search and Destroy. Upon the installation process you will be given a choice of component, uncheck "Tea Timer" as it sometimes interferes with regular antivirus programmes.

https://ccm.net/downloads/security-and-maintenance/4561-spybot-search-destroy/

16. Run a scan and delete the items found.

17. Download and install CCleaner

https://www.ccleaner.com/ccleaner/download

18. Scan your registry for error and clean your temp files.

19. Once your computer is clean and working normally just to be on the safe side
*Turn off system restore and wait 30 seconds,
*Turn it back on and create a new restore point.

This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.

It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.


After all this typing, I would sure appreciate your feedback

Best regards
0
Hi

I'm applying all your recommendations at this time. I will keep you posted.
Thank you in advance.
0
arrghhh

I tried everything you said to the letter.

I booted up and the same issue.

if i re-format the HD will this fix the problem?

thanks
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Mar 21, 2010 at 04:16 PM
Please do not reformat your HD, save yourself the trouble.

If you did not find the process to terminate that means it is still there.

Here is another way to send that horse to the glue factory without reformating.

Please download Combofix which is a very powerful virus killer, equivalent to a super hero. It is to be used with moderation and only as a last resort.

Download from here:

http://www.combofix.org/download.php

Before running Combofix, ensure:

1. You disconnect your modem
2. Close all applications
3. Disable your antivirus

Please be sure to let give me a report

Thank you
0
Ambucias
Thanks, I am d/l'ing combofix and will try it.
I will keep you updated.
Thanks so much again! ... hope it works
0
Ambucias!!

Thank you my friend!!!
your recommendation for Combofix worked like a charm!!!

You just saved me from reformatting, and a headache!!!

Thank you so much, Ambucias, you are a Genius!
0

Didn't find the answer you are looking for?

Ask a question
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Mar 21, 2010 at 05:08 PM
I am happy it worked.

I suspect that there was another virus in your machine other than antivirus soft.

Now that your system is clean, one last recommendation.

Turn off your system restore for 30 seconds

*Turn it back on and create a new restore point.

This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.

Thank you for your feedback.
0
Ambucias

I've done just that. Also d/l'ed microsoft essentials security (free).

My friend, thank you so much once again!!!
0