Infected with virus that my antivirus can't get rid of.
Welcome, Guest. Please login or register. Did you miss your activation email?


Britec Computer Tech Help Support Forums  « Virus Removal « Virus/Trojan/Spyware/Malware « Infected with virus that my antivirus can't get rid of.
Pages: [1] 2 3
  Print  
Author Topic: Infected with virus that my antivirus can't get rid of.  (Read 1780 times)
spinner456
Jr. Member
**
Posts: 56


View Profile
« on: April 04, 2011, 01:04:47 AM »

I just got hit with one of those fake antivirus viruses.I took a screen shot.First I ran Malwarebytes, then super anti-spyware, then, AVG, then tried Kaspersky, but it wouldn't work.The update kept failing....something about and expired license.Malware and super-anti initially found a few bugs and got rid of them, but this thing is still on my computer, but now the scans aren't finding anything.


« Last Edit: April 04, 2011, 01:09:05 AM by spinner456 » Logged
tmy
Hero Member
*****
Posts: 673



View Profile WWW
« Reply #1 on: April 04, 2011, 01:14:39 AM »

 Azn SPINNER456,
these can be a little awkward to get rid of, I suggest you take a look at this first because it will give you a better understanding of what you need to be doing to get the thing out of your system.                        

<a href="http://www.youtube.com/watch?v=aJVjjS4XCeI" target="_blank">http://www.youtube.com/watch?v=aJVjjS4XCeI</a>


Good luck and take care if your still having trouble check back on the forum and we can see if we can help you out further

 Wink



tmy


 Bye
« Last Edit: April 04, 2011, 03:33:22 AM by Britec » Logged

www.stannic.com.au  Home Computing Services And Repairs
spinner456
Jr. Member
**
Posts: 56


View Profile
« Reply #2 on: April 04, 2011, 02:07:46 AM »

First of all, thanx for responding so fast.You guys are on it. Second, after running the rogue killer it looks like the virus stopped running.Those pop ups are gone.i'm going to scan my system again.This is the second time you guys have helped me save my system and this time in a matter of minutes. You Rock Kiss

Thank you.
Logged
tmy
Hero Member
*****
Posts: 673



View Profile WWW
« Reply #3 on: April 04, 2011, 03:13:53 AM »

 Azn spinner456
pleased to help out take care          Wink


tmy



 Bye
Logged

www.stannic.com.au  Home Computing Services And Repairs
spinner456
Jr. Member
**
Posts: 56


View Profile
« Reply #4 on: April 04, 2011, 06:56:51 AM »

It looks like I spoke too soon.Now my services, like  windows audio and firewall/internet connection sharing, keep crashing.I even ran combofix.exe which I think fixed it last time, but it's still doing it.
Logged
BJseal91
Hero Member
*****
Posts: 699



View Profile
« Reply #5 on: April 04, 2011, 07:01:40 AM »

what is the error saying
Logged
tmy
Hero Member
*****
Posts: 673



View Profile WWW
« Reply #6 on: April 04, 2011, 07:08:58 AM »

 Azn spinner456,
just make sure you have followed the instructions in the video as the rouge killer will only stop the process from starting and not remove it from your system completely. Run a scan using one of the bootable Anti virus boot cd's

http://www.briteccomputers.co.uk/forum/virustrojanspywaremalware/free-bootable-antivirus-rescue-cds-download-list/

Please post the error your seeing as BJseal91suggested, take care


 Wink


tmy


 Bye
Logged

www.stannic.com.au  Home Computing Services And Repairs
spinner456
Jr. Member
**
Posts: 56


View Profile
« Reply #7 on: April 04, 2011, 07:36:36 AM »

Usually something like generic host process for win32 services encountered a problem and needs to close, but now there's no error message.There's just this moment when the explorer looks weird.you ever turn your themes service off?It looks like that.Then my services just stop.
Logged
spinner456
Jr. Member
**
Posts: 56


View Profile
« Reply #8 on: April 04, 2011, 08:42:23 AM »

I'm looking at your videos on youtube, i'm a subscriber by the way, should I make this SARDU disk?Can I boot one of these from a usb stick instead of a CD?Another problem I have is that the tabs I had open on firefox were a casualty of this whole thing.I had like 9 tabs open when this all happened yesterday.After rebooting after running malwarebytes the first time I opened firefox and they were gone instead of the session restore that usually opens.If I use a system restore point, will I get my tabs back?
Logged
Britec
Administrator
Hero Member
*****
Posts: 3497



View Profile
« Reply #9 on: April 04, 2011, 09:11:49 AM »

Step 1

Please Boot to Safe Mode with Networking...

Please download and run the below tool named Rkill

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.com
* Rkill.scr
* Rkill.pif
* Rkill.exe

* Double-click on the Rkill desktop icon to run the tool.
* If using Vista or Windows 7 right-click on it and choose Run As Administrator.
* A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
* If not, delete the file, then download and use the one provided in Link 2.
* If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs (it can take a few trys to get it to run).
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.
-------------------------------------------------------

Step 2

How to run a scan with Malwarebytes' Anti-Malware

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform Quick Scan", then click Scan.
          o If the program won't start, go to MBAM's program folder (normally C:\Program Files\Malwarebytes' Anti-Malware), rename mbam.exe to a random file name (keep the .exe extension) and double-click on it to start the program.

    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note Below)
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.



Troubleshooting MBAM Problems


Some malware targets Malwarebytes' Anti-Malware and other cleaning tools to prevent you from using them to clean your system.

Unable to Run MBAM

If you attempt to run the installer for MBAM and it won't run, or starts and closes, using Windows Explorer go to the folder you saved the install program and try renaming it to one of the following file names:

    * iexplore.exe
    * explorer.exe
    * userinit.exe
    * winlogon.exe
    * mbam.scr



Then double-click on the renamed file to try to run it. If that doesn't work, try one of the other file names above. If you are still unable to run the MBAM installer, then download and run this program to try to kill the malware process:

------------------------------------------------------------------------
Step 3

Download SuperAntiSpyware


    * Load SuperAntiSpyware and click the Check for Updates button.
    * Once the update is finished click the scan your computer button.
    * Check Perform Complete Scan and then Next.
    * Superantispyware will now scan your computer and when its finished it will list all the infections it has found.
    * Make sure that they all have a check next to them and press Next.
    * Click Finish and you will be taken back to the main interface.
    * Click Preferences and then click the Statistics/Logs tab. Click the Dated Log and press View Log and a text file will appear.
    * Copy and Paste the log to this thread.
Logged



spinner456
Jr. Member
**
Posts: 56


View Profile
« Reply #10 on: April 04, 2011, 02:05:45 PM »

Another problem I have is that the tabs I had open on firefox were a casualty of this whole thing.I had like 9 tabs open when this all happened yesterday.After rebooting after running malwarebytes the first time I opened firefox and they were gone instead of the session restore that usually opens.If I use a system restore point, will I get my tabs back?
Logged
spinner456
Jr. Member
**
Posts: 56


View Profile
« Reply #11 on: April 04, 2011, 02:30:30 PM »

I ran bitdefender and it found a trojan and a few other things.It's been half an hour and no service crash yet.usually it would have happened by now, so I think I might have gotton it.
Logged
Britec
Administrator
Hero Member
*****
Posts: 3497



View Profile
« Reply #12 on: April 04, 2011, 04:05:35 PM »

Did you follow the steps I posted? can I see the log files from the scan?
Logged



spinner456
Jr. Member
**
Posts: 56


View Profile
« Reply #13 on: April 05, 2011, 12:21:09 AM »

I already did all of that before I came here and they all came back clean which is why I needed more help....which I put in my original post.Can someone answer my questions?
Logged
BJseal91
Hero Member
*****
Posts: 699



View Profile
« Reply #14 on: April 05, 2011, 12:39:00 AM »

What Question are you applying to the services or the virus?
Logged
Pages: [1] 2 3
  Print  
 
Jump to: