Welcome to Gaia! :: antivirus pro help D: | Forum

Register FaceBook Login Login

 

 
GST

Welcome to Gaia's forums, where millions of members gather to discuss random stuff, make new friends,
complain about life, argue about nothing, laugh at dumb pictures, discuss serious issues and/or curse like sailors.

Lurking is creepy. Quit skulking in the shadows and join the conversation!

Register to reply

Advertisement
Tags: antivirus  help 
Share:  
forum:43, topic:55941937
< 1 2 3 4 5 6 >
here, this may help.


Spyware and Adware need the computer mostly working, because if you're not using it, then spying on your habits and displaying advertisements is useless.

That said, there are a few, horribly, horribly nasty types of infection, that render your computer almost useless, can redirect your web browser to it's own pages, restore themselves from a half-removed state, and refuse to let you do anything useful until you pay them. They're holding your computer ransom with a nuculear bomb, so to speak, and require special tools (SWAT TEAM!) to take care of.

They can be called many names, but a main classification of them can be called Smitfraud, Virtumonde, and Vundo.

http://urlcut.com/fixer_of_rogues

That is an updated tool that will attempt to remove all known deep infections. Follow all the instructions exactly (remember safe mode when it says to!) and give it time to do it's job.

After downloading it, open a folder, any folder. Go to "Tools" at the top menu, and click "Folder options". When a new window comes up, go to the the "view" section. Find and UNcheck "hide file extensions for known types", save the changes. Then rename the text file you got from roguefix from .txt to .bat, that way you can run it. Feel free to recheck the box afterwards, it's only needed to be off so that you can run roguefix.

If you cannot run that one, try these backups.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
http://siri.geekstogo.com/SmitfraudFix.php



Fixing Redirections


DNS is "Domain Name Server". A DNS server keeps information which web address relates to which IP address on the internet (like how google.com is 74.125.45.100). It's sort of like how "Jack's house" means "123 Oak Tree Lane" in the real world.

A - Cleaning Your Hosts File

The HOSTS file is a file on windows that holds information about DNS entries on your own computer, it's usually used to bypass a normal DNS server for whatever reeason. Usually it's only used to block things (by making the browser try to go to a non-internet IP address when you try to visit a specific site), like to block bad sites, or your parents might use it to block myspace or something. Unfortunately infections will add entries that make real sites redirect to fake sites... so this might need to be undone.

If you're on XP...
In your start menu, go to "run".
Type in the below code, without spaces.
% Windir % /System32/drivers/etc/

Press enter, a window show open. In there, find a "hosts" file. Right-click it, "open with", and open it in notepad.

If you're on Vista...
1) Browse to Start -> All Programs -> Accessories
2) Right click "Notepad" and select "Run as administrator"
3) Click "Continue" on the UAC prompt
4) Click File -> Open
5) Browse to "C:>Windows>System32>Drivers>etc"
6) Change the file filter drop down box from "Text Documents (*.txt)" to "All Files (*.*)"
7) Select "hosts" and click "Open"

If you see any mention of sites you KNOW are safe (if it mentions safer-networking.org or ebay.com other sites you know of, especially ones you'd download security software from or that the infections is blocking you from visiting), then you'll want to remove them.

Start by erasing all of those bad lines. Go to save it, and when you do, make sure you click the "save as type" box when saving, and select "all files", then save the file as "hosts" without the ".txt" ending. If that fails for some reason, and you know you don't need any of the redirects in the hosts file, just delete it. See if you can get to the websites again after you're done with that. If not, restart back into safe mode and try again.
 
     
 
Ok, you're missing the point, and making this more difficult than it has to be. The answer to your problem is in the sticky you're failing to adhere to.

You're telling us you followed the sticky, but we know you did not, at least not as completely as you would suggest.

You are obviously skipping steps in the sticky. I don't know how many steps you are missing, but I know you're missing some. Odds are, those steps you have skipped are the ones that wil take care of your lingering problems.

If you want to completely eliminate your problems, and all traces of them, and protect against future infections, I can't stress how important it is to follow the instructions in the sticky IN THEIR ENTIRETY. This means skipping no steps, installing all of the programs, doing all of the scans in the right ways.

So far, you have not done that. Anyone in this forum who has read the sticky (which is most of the regulars) can tell that you've not done everything the sticky suggests.

Please. Just follow ALL of the instructions in the sticky, starting at the very beginning. Even the useless ones that you don't think apply. They will take care of all of your problems.

There is no way in the course of this thread you did all of the scans the sticky requires. Time simply does not allow it.
     
i did all that...all i now need help with is the stupid antivirus pro...for some reason...maybe because its new....but that was the only thing not delted...everytihng i eman all the other trogens and malware....GONE D<....but antivirus pro...still here
 
     
 
Genji Gincosu
i did all that...all i now need help with is the stupid antivirus pro...for some reason...maybe because its new....but that was the only thing not delted...everytihng i eman all the other trogens and malware....GONE D<....but antivirus pro...still here
Did you do it in safe mode, or normal?
     
JayDi Blaze
Genji Gincosu
i did all that...all i now need help with is the stupid antivirus pro...for some reason...maybe because its new....but that was the only thing not delted...everytihng i eman all the other trogens and malware....GONE D<....but antivirus pro...still here
Did you do it in safe mode, or normal?


safe mode...as i was told to do
 
     
 
The Last Rydian
I wrote the sticky.

You have not followed the sticky.
I know, because the sticky tells you to post something you haven't posted.

GO AND FOLLOW THE STICKY!
GO AND FOLLOW THE STICKY!
GO AND FOLLOW THE STICKY!
GO AND FOLLOW THE STICKY!
GO AND FOLLOW THE STICKY!
     
Genji Gincosu
JayDi Blaze
Genji Gincosu
i did all that...all i now need help with is the stupid antivirus pro...for some reason...maybe because its new....but that was the only thing not delted...everytihng i eman all the other trogens and malware....GONE D<....but antivirus pro...still here
Did you do it in safe mode, or normal?

safe mode...as i was told to do
Ok, just a sec. lemme upload a tool for ya.
 
     
 
Remember what I said in my first post about you continually lying to us and that leading to people not wanting to help?

We're fast approaching that point.

How many times to we have to say that the sticky has you posting information that you have not posted, thusly, we know you have not followed all of it's steps? We have solid proof you have skipped something.

Just admit that you've followed some of the steps but not all, or concede that you may have overlooked something. But insisting that you have done things that you clearly have not done will make it seem like a waste of time to help you.
     
again and again truly i am not trying to be rude but i said that all the stuff the sticky did worked but for some odd reason antivirus pro...the new antivirus thing is still there even thought the other stuff is gone
 
     
 
Just to make sure I'm getting the right version, mind giving me a hijackthis and combofix log, so I know what is where? run both in safe mode, poste to paste2.org.
     
Bolweevil
Remember what I said in my first post about you continually lying to us and that leading to people not wanting to help?

We're fast approaching that point.

How many times to we have to say that the sticky has you posting information that you have not posted, thusly, we know you have not followed all of it's steps? We have solid proof you have skipped something.

Just admit that you've followed some of the steps but not all, or concede that you may have overlooked something. But insisting that you have done things that you clearly have not done will make it seem like a waste of time to help you.


sir have you been reading any of my posts.. > _ >....not trying to be rude but for some reason you dont seem to see me thanking you and the sticky for it helping...maybe i didn't read everything but idk i did what i needed in the advanced parts like an hour ago....when i did that my computer was fixed...hmm...i just took a screen pic to show this little...you will see it....this is anti virus pro and it will not go away
 
     
 
Dude, I'm trying to help you, would you post the logs so I can help?
     
C/T's minister of pissyness
Genji Gincosu
Bolweevil
Remember what I said in my first post about you continually lying to us and that leading to people not wanting to help?

We're fast approaching that point.

How many times to we have to say that the sticky has you posting information that you have not posted, thusly, we know you have not followed all of it's steps? We have solid proof you have skipped something.

Just admit that you've followed some of the steps but not all, or concede that you may have overlooked something. But insisting that you have done things that you clearly have not done will make it seem like a waste of time to help you.


sir have you been reading any of my posts.. > _ >....not trying to be rude but for some reason you dont seem to see me thanking you and the sticky for it helping...maybe i didn't read everything but idk i did what i needed in the advanced parts like an hour ago....when i did that my computer was fixed...hmm...i just took a screen pic to show this little...you will see it....this is anti virus pro and it will not go away


So, you haven't actually done half the steps.

Follow EVERY step of the WHOLE sticky. you STILL haven't done some of the steps. Trust us. WE know ABSOLUTELY that you haven't done certain steops.
 
     
Anarchy per intentio

http://img197.imageshack.us/img197/6227/zoidsig.png
 
JayDi Blaze
Dude, I'm trying to help you, would you post the logs so I can help?


very sorry but where do i go again sad
     
Genji Gincosu

sir have you been reading any of my posts.. > _ >....not trying to be rude but for some reason you dont seem to see me thanking you and the sticky for it helping...maybe i didn't read everything but idk i did what i needed in the advanced parts like an hour ago....when i did that my computer was fixed...hmm...i just took a screen pic to show this little...you will see it....this is anti virus pro and it will not go away
I see you repeatedly insisting you've done the things mentioned in the sticky, and you go on to elaborate on the problems you're still having.

Have you been reading our posts?

There are steps in the sticky that have you deliver information to us. You have obviously not done these steps. These steps, and the ones immediately before, and after them are very important to the troubleshooting process.

What I have been trying (and failing) to get you to do is go back and redo the guide so that you include these missed steps, and hopefully, get closer to resolving your issue. You have only done a small portion of the guide. It doesn't work effectively if you do that.
 
     
http://tinyurl.com/yjq8h58
http://badges.mypersonality.info/badge/0/5/55785.png
http://tinyurl.com/9n5zf
< 1 2 3 4 5 6 >

Quick Reply

Enter both words below, separated by a space:

Can't read the text? Click here

Submit

We will be phasing out support for your browser soon.

Please upgrade to one of these more modern browsers.