Annoying Virus, need help.

Status
Not open for further replies.

Snuckles

CAGiversary!
Feedback
20 (95%)
I'm getting this annoying redirect virus. Go to google search something, click on link and when I do another tab opens up going to weird websites like http://www.ave99.com/search.php?q=firefox
and other stuff. Another tab will open every so often and its Defender Registry Download!

My computer has been restarting as well every 30 minutes or so saying a DCOM error but I turned the "windows auto restart on error" thing off to try and figure this out. I scanned with AVG, malware, hijack this and nothings coming up. Anyone have any info before i go to some local shop.
 
Used combofix and it seemed ok, restarted scanned but before it could finish I got the blue error report saying"windows detected a problem and has shut down etc. If this is the first time restart the machine..." blue error screen. bah..deal with this in the morning. THanks for the help. gonna try your other links tomorrow.
 
BSOD SUCKS. im having the same situation with 2 laptops...
easy fix is to try system restore. doesnt work for me tho. My HDD probably crashed so i need a new one. But safe mode works for some reason
 
Which malware scanner are you using? You should try Malwarebytes Anti-Malware. Restart your computer in safe mode and then run it.
 
Try running Combofix in Safe Mode if running it in normal startup didn't help.

Then try Ugamer_X's suggestion. Malwarebytes makes a fine scanner.
 
When you are doing removals, try to install your scanners, and if you know how to, get a PE boot disk. If you cannot find one or do not know how to operate within a PE environment, reboot in safe mode with command prompt, browse to your program file directory and running the scanners from there. This way, none of your network adapters start which can often trigger a reinstall of spyware/maleware

Great scanners are: Spyware Doctor, Panda Antivirus and Hijackthis if you can copy/submit your report or know what your looking for (typically any search engine hooks 018's and extra button 023's and things that look outta place or are just C:/23426262435 just random numbers)

After your done scanning in safe mode, reboot into normal and scan again. Hopefully that will takeout the nastiest.

P.S. You will want to keep hitting F8 to get to your boot options, and you should also go to the very bottom and choose "Do not automatically restart my computer on system failures." This will allow you to see what the BSOD stop code is (if you see 0x0000008e then your stop code is 0x08e. and etc....) If you can post that code it can point to a lot of things, but if anything you removed a piece of the spyware that was attached to a system32 file and your file structure is freaking out
 
If using combo fix, malwarebytes and MS malicious software removal tool doesn't work you have just found the perfect time to upgrade to Windows 7.
 
I had this same almost same problem a while back when my browser searches were being hijacked. :bomb:
If any suggestions from above still won't fix your problem, then it's time to find some professional help. There are a couple of message boards dedicated to helping the poor masses of getting rid of the spyware epidemic. They're free though sometimes you have to wait 2 days to a week before someone can help you.
 
Combofix could get rid of fucking herpes. If that doesn't fix you up, you're in trouble. Malwarebytes would also be a good one to run. When people bring computers over for me to fix, I usually install and run Avast Antivirus -- it has an option to run a boot-time scan, so it can check out your system before Windows starts up.
 
I'm also having this problem, and will run through the remedies. Thanks, everyone.

I already ran Malwarebytes, and while it removed things (hopefully related to the issue), the problem/virus/trouble still returned. :bomb:
 
My usual method of removing viruses. Remember to do updates after installing / before using each one;

1 - use CleanUp and CCleaner to remove all temporary files from the machine.
2 - Combofix first
3 - Malwarebytes Antimalware
4 - Superantispyware (has to be installed in regular mode, can be scanned in safe mode)
5 - Lavasoft Adaware (same as above). AAW is particulary good at finding "Hijacks" over the above
6 - Hijackthis to analyze the running program. The most common problem is things under your "Hosts" files. Most people should have nothing under hosts. If it's really bad you can't delete the entries, you have to delete your hosts file with a boot CD (it will recreate itself, clean)

That solves most of my virus removal jobs. Sometimes I have to run Spyware Doctor as well (have to download it through Google Pack). If you're still having problems after all that consider reinstalling Windows.
 
Thanks for all the help people. Will definlately put this to work today. If I am still having trouble then I'ma go to a pro around here and just get it fixed. I'd like to do it soon, i'm afraid of watever damage this may cause. Gonna download these things, run em and i'll report back later. thanks!
 
[quote name='PR Mega X']Combofix could get rid of fucking herpes[/QUOTE]
lol, truth. Combofix was a lifesaver when I picked up the vundo trojan a while back.
 
Like others, I'd recommend both Combofix and Malwarebytes. Both are great programs.

A Hijackthis log would be good in looking things over, if you can tell what's out of place and what's good.

BigPopOV mentioned CCleaner. This is good at getting rid of temporary files, and fixing registry errors. We actually use that at work (and I use it at home), and it does a good job.
 
I had the search engine issue as well for the longest time. I did a system restore a year ago and it worked fine, then I got it again, so I did a complete windows reinstall. That worked fine til about 4 months later I got the same thing yet again, and my system was really bogged down. After that I just said F it and lived with it.... "UNTIL NOW!"

"Billy Mays here with a fantastic new product.... Combofix!"

Seemed to do the job, thanks to those who recommended it. My system is a little bogged down still, but the search engine issue seems to be corrected so far, so good.
 
Yeah that's a nasty little one. I picked up my first major virus last month (almost 20 years of jacking around on PCs with no major problems and then POW). One of the symptoms was the search engine meddling and I couldn't download/install anti-virus/malware programs. I ended up formatting the HDD and reinstalling XP SP2 and I don't know if there are still residual effects or if my XP cd was fux0r3d because certain windows features are missing/still don't work right. (No calculator, paint, etc)
 
If you can't download / install certain programs, there's a couple of nifty tricks,

1 - Rename the program. Change mbam-setup.exe to word.exe, it will fool a good amounmt of viruses that block mbam-setup specifically. Sometimes after installing, you need to go into the Program Files and rename the installed EXE as well.

2 - Most viruses that hijack the running programs on the machine rely on a startup program (that you cannot remove from msconfig). If you start the machine in Safe Mode, hit CNTL ALT DEL for the Task Manager ASAP, and kill any programs that pop up under Applications really fast, you prevent it from running and blocking the AV program install.

3 - As an addendum to the second, another technique is to have Combofix on your desktop (put it with a flash drive if you can not download it), frantically click on it as the machine starts. If CF beats the malacious program on start, CF will continue and run its removal. Most of those programs cannot actually kill an already running process, only prevent you from running them

Fun stuff.
 
[quote name='BigPopov']If you can't download / install certain programs, there's a couple of nifty tricks,

1 - Rename the program. Change mbam-setup.exe to word.exe, it will fool a good amounmt of viruses that block mbam-setup specifically. Sometimes after installing, you need to go into the Program Files and rename the installed EXE as well.

2 - Most viruses that hijack the running programs on the machine rely on a startup program (that you cannot remove from msconfig). If you start the machine in Safe Mode, hit CNTL ALT DEL for the Task Manager ASAP, and kill any programs that pop up under Applications really fast, you prevent it from running and blocking the AV program install.

3 - As an addendum to the second, another technique is to have Combofix on your desktop (put it with a flash drive if you can not download it), frantically click on it as the machine starts. If CF beats the malacious program on start, CF will continue and run its removal. Most of those programs cannot actually kill an already running process, only prevent you from running them

Fun stuff.[/QUOTE]
This. I've had to give MBAM a fake name many times while fixing issues on friends' computers.
 
Are you still having problems? Ive had a viruses that kept redirecting me to fake antivirus sites and one time it almost killed my computer. It would only start on safe mode. I didnt know what to do so I started thinking about turning to geeksquad. haha Anyways, I'd highly recommend this site for computer troubles, bleepingcomputer.com

They have help me thoroughly cleaned out the infections.

Goodluck.
 
If you end up paying for tech service, go with one of the local companies rather than Best Buy's Geek Squad. It will be much cheaper and you will (most likely) get a much better technician.
 
Update:


I wanna thank everyone for their opinions and links and help. I tried everything listed above and other forums. Talked to a microsoft help/answer person and still didn't get this fixed. Ended up reformatting completely.

AVG kept finding about 57 spyware/adware everyday, the same ones and it said it deleted them but the next day they were back. Malwarebytes also found a trojan horse proxy or something and said it was deleted but all my problems kept persisting and got worse. I didn't want my computer to get permanently injured so I just restarted.

Thanks for all the help on this though.
 
[quote name='Snuckles']Update:


I wanna thank everyone for their opinions and links and help. I tried everything listed above and other forums. Talked to a microsoft help/answer person and still didn't get this fixed. Ended up reformatting completely.

AVG kept finding about 57 spyware/adware everyday, the same ones and it said it deleted them but the next day they were back. Malwarebytes also found a trojan horse proxy or something and said it was deleted but all my problems kept persisting and got worse. I didn't want my computer to get permanently injured so I just restarted.

Thanks for all the help on this though.[/QUOTE]


You get Windows 7?
 
CF doesn't really do much against browser addons (hijacks, popups). SuperAntispyware, Adaware and a manually analyzing hijackthis usually work best there. It also never seems to fully clean things up. It will remove 95% of what it removes, but there will still be traces leftover here and there.

That's why you need to run 4-5 programs in a row. What one misses, the other will detect, and so on.
 
I've found that if Combofix and Malwarebytes throw up their hands and say fuck it, or atleast get it in a state that it's much more usable....you are done.
 
I had this problem earlier this week, I would get random pop ups and anytime I clicked a search result it got taken to an ad site.

Norton 360 didn't get rid of it, I tried Avast and that didn't work either. I have SuperAntiSpyware and MalwareBytes already downloaded and downloaded some more Anti Spyware programs, nothing worked. After hours of trying to get rid of it ComboFix did the trick.
 
[quote name='YoshiFan1']I had this problem earlier this week, I would get random pop ups and anytime I clicked a search result it got taken to an ad site.

Norton 360 didn't get rid of it, I tried Avast and that didn't work either. I have SuperAntiSpyware and MalwareBytes already downloaded and downloaded some more Anti Spyware programs, nothing worked. After hours of trying to get rid of it ComboFix did the trick.[/QUOTE]

Yeah this was the worst virus i've ever dealt with. Malware and AVG kept finding things but I guess they never REALLY deleted it. or it kept renaming itself, I have no idea.
 
I don't understand why this is always such a big problem for people. First of all, the tools for removal today are just awesome. Secondly, I have had probably one major bout with trojans personally (years ago). After I finally got it solved, I downloaded FF (and never used ie again), removed every last bit of Norton from my system, installed AVG, disabled Windows Messenger, never installed another toolbar outside of Google's and also installed what has now been bought by MS and become Windows Defender today. And I have never had another issue, really. I have had a few warnings, but AVG and Defender make pretty light work of it.

Now I use Chrome, AVG and do periodic scans with Malwarebytes and never really find anything on my system at all.

But for those who do have problems, there is golden advice in this thread. There is no use trying to live with a crapped up computer. When I fix people's computers these days, I just have a USB drive with CCleaner, AVG and MalwarebytesAM on it.
1 - I will usually first disable any network card.
2 - Then I root out all traces of Norton/Symantec from the system (with permission, of course).
3 - Then I run CCleaner to get rid of all useless clutter and registries.
4 - Then I run a quick scan with MAM.
5 - Re-boot into safe mode and run a full scan.
6 - Then reboot normally and run another scan. I have never had anything else pop up at this point. (But if you do, from what others have said in here, Combofix might be able to finish the problem off. But always reboot and scan with whatever you are using again afterwards to make sure nothing is re-installed.)
7 - Then I install AVG Free (Avast! is a good one as well). During install, it will want to connect to it's servers online, so you'll need to enable the network again.
8 - Hide all traces of ie and use Chrome from now on.

[quote name='QiG']Yeah that's a nasty little one. I picked up my first major virus last month (almost 20 years of jacking around on PCs with no major problems and then POW). One of the symptoms was the search engine meddling and I couldn't download/install anti-virus/malware programs. I ended up formatting the HDD and reinstalling XP SP2 and I don't know if there are still residual effects or if my XP cd was fux0r3d because certain windows features are missing/still don't work right. (No calculator, paint, etc)[/QUOTE]

Are you sure they don't exist? I have seen that happen before. You probably just need to find the program and add the shortcuts to the Accessories tab manually. It's been a long time since I have used XP, but I believe if you type the commands "calc" or "mspaint" into the run box, it should pull up the programs. But on a much more important note, why are you still on XP?

[quote name='Malik112099']Slap yourself. Hard.[/QUOTE]

Seriously. I was only waiting to get a new HDD before I upgraded. I ordered the HDD last week. I bought Windows 7 Pro when it showed up this week. Today I wonder why I waited. Goodbye noisy computer, goodbye slow OS, hello available processes and RAM. Windows 7 is amazing.
 
Sounds like you have a rogue program and not a virus. If you do a search on the internet for "win xp antivirus 2008" or "coreguard" I'll bet you find they are exactly like what you have. It is a program that sends pop-ups to your desktop and tells you that your infected in order to scare you into going to their website and buying their software.

If you install malwarebytes and run a scan or two it will clear it up for you. Malwarebytes is designed to pick up the things your antivirus misses, just like this. You can find links to malewarebytes and other free software at the site below....
 
Status
Not open for further replies.
bread's done
Back
Top