1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

Virus/Spyware Help: Antivirus System PRO

Discussion in 'BBS Hangout' started by TL, Dec 1, 2009.

  1. krnxsnoopy

    krnxsnoopy Member

    Joined:
    May 16, 2005
    Messages:
    10,870
    Likes Received:
    1,549
    First, I had Avast but the virus wouldn't let me install malaware bytes. I tried everything; renaming it (to winlogon.exe), dl onto flash drive, etc. It basically wouldn't let me install it and that was problem number 1. My second problem was it wouldn't let me run task manager. One thing you should remember is that you can close a program by pressing Alt-F4 instead of task manager. This way you won't have to click on any popups caused by the virus.

    What worked for me is I rebooted my computer on Safe-Mode with Networking and I was able to run malawarebytes there. After scanning the crap out of the computer, it found a couple viruses. Then I ran Avast again. This time it detected a couple more trojans/viruses that it didn't detect in regular mode. After then, I did a system restore to the earliest date I could find.

    After all this, I loaded up in regular mode and ran Avast again. Avast suggested I reboot the computer and let Avast do a complete computer scan. I selected yes, and waited for a couple hours. The next time I booted up my computer normal, I noticed the virus was finally completely gone. No more popups, no more error messages. I'm still crossing my fingers and hoping it won't come back. I took me two days to get my computer back to normal. Good luck hope it helps.

    Here are some links I used.

     
  2. Kyakko

    Kyakko Member

    Joined:
    Aug 15, 2002
    Messages:
    2,161
    Likes Received:
    39
    btw system restore is under program files->accessories->system tools->system tools
     
  3. Uprising

    Uprising Member

    Joined:
    Dec 29, 2000
    Messages:
    43,073
    Likes Received:
    6,599
    Download CodeStuff Starter. It'll allow you to stop any processes that start when the computer turns on with out your permisision.

    I've removed this Malware rogue antivirus program from 5 systems already, and MANY MANY other very similar malware.

    Malwarebytes should get rid of it once you use codestuff starter.

    Find it here: http://codestuff.tripod.com/products_starter.html

    Malwarebytes: http://download.cnet.com/Malwarebyt...4572.html?part=dl-10804572&subj=dl&tag=button

    Don't forget to rep me. :p.....i keeed.
     
    #23 Uprising, Dec 1, 2009
    Last edited: Dec 1, 2009
    2 people like this.
  4. SwoLy-D

    SwoLy-D Member

    Joined:
    Jul 20, 2001
    Messages:
    37,618
    Likes Received:
    1,456
    ^ That's gotta be good STUFF right there, sir. I always trust your help. :eek: no lie.

    And don't be all ghetto asking for REP like the rookies do, man! :p You get it 'cuz you earn it, not 'cuz you asked for it!!
     
  5. Uprising

    Uprising Member

    Joined:
    Dec 29, 2000
    Messages:
    43,073
    Likes Received:
    6,599

    haha, I know. I added that in with an edit when I fixed a link. I failz...I knowz... :eek:

    EDIT: hahaha....thanks.
     
  6. Rocket River

    Rocket River Member

    Joined:
    Oct 5, 1999
    Messages:
    65,157
    Likes Received:
    32,853

    Download Malwarebytes and hiJack this. . .
    In Safe Move look for the Folder [I think it is under c:\Program Files\antiviruspro or some such]

    Rocket River
     
  7. Rocket River

    Rocket River Member

    Joined:
    Oct 5, 1999
    Messages:
    65,157
    Likes Received:
    32,853
    oops . . .and delete the folder
    Clear everything looking suspicious with HiJack this.
    and run Malwarebytes


    Rocket River
     
    1 person likes this.
  8. DrNuegebauer

    DrNuegebauer Member

    Joined:
    Mar 29, 2000
    Messages:
    12,676
    Likes Received:
    9,861
    This will work!

    To make it even easier:

    1. Turn off your PC
    2. Turn it back on
    3. AS SOON as you can access your start menu, click in that little 'search' box at the bottom, and type "msconfig" - a panel will come up.
    4. Select the 'Startup' tab at the top of this panel, then scroll down and deselect the boxes for the spyware program (I think they are called xsys or something similar - look for the ones with the words 'antivir' in the title)

    That'll stop it from loading. Now just update your spyware/ virus protection, scan your PC and you should be fine.

    If you're STILL having problems accessing the internet, open your internet connections, and DEselect the 'use a proxy server' option - the program sometimes sets itself as a 'proxy' (which explains why you can't access the internet)

    Hope that helps.
     
    1 person likes this.
  9. Yao Wink

    Yao Wink Member

    Joined:
    Apr 23, 2003
    Messages:
    847
    Likes Received:
    0
    I suffered from this crap a few weeks back. It had disabled my antivirus programs, would not let me download anything, and ultimately locked me out to the point where I could not boot up in safe mode. I had burned a Kaspersky recovery disk and ran it, but my operating system was screwed by then.

    I ended up removing the hard drive, hooked it up to an adapter that converted it to an external hard drive. After transferring files over to my other computer, I had to reinstall my operating system to get things to work correctly.
     
  10. JaWindex

    JaWindex Member

    Joined:
    Jan 21, 2005
    Messages:
    1,993
    Likes Received:
    31
    Make sure you know what you're deleting when using HiJack this. You can screw up your computer if you delete the wrong things.

    I got this same virus while at work. I was reading cf.net but I was also downloading some music so I'll refrain from blaming clutchfans. The way I got rid of antivirus pro was to run combofix. That little program is amazing. It's always done a better job at deleting malware crap off my computer than other programs. The only thing is I had to run it immediately after start up before antivirus pro booted up. I hope this helps.
     
  11. TL

    TL Member

    Joined:
    Mar 27, 2001
    Messages:
    740
    Likes Received:
    26
    you guys rule.

    something is still wrong with the computer, because i can't connect to the internet, but i can now run malware (that i d/l from my personal laptop and transferred by memory stick) and can open programs. and what makes me really happy is that the d*mn antivirus pro warning hasn't showed up again.

    for the record, i did the msconfig thing.

    i'm not sure what the internet problem is, but if i can run excel and outlook, and acess files, i can be productive...and i'll let our IT guy identify the rest of it.

    seriously, thanks guys.
     
  12. Kyakko

    Kyakko Member

    Joined:
    Aug 15, 2002
    Messages:
    2,161
    Likes Received:
    39
    now, just do the system restore...you'll get the network back too. make sure you choose a time before the infection.
     
  13. Coach AI

    Coach AI Member

    Joined:
    Feb 15, 1999
    Messages:
    7,981
    Likes Received:
    840
    I've been seeing this crap for at least a year or two. 2009/Pro is just the latest iteration.

    The most 'impressive' (if you want to call it that) version of this I've come across had the Windows blue screen of death as a screensaver. So the user would think their system was blue screening all the time. :eek: It did a whole bunch of other crap too, and looked exactly like XP's Security Center.

    Nasty stuff.
     
  14. Joshfast

    Joshfast "We're all gonna die" - Billy Sole
    Supporting Member

    Joined:
    Dec 9, 2001
    Messages:
    6,516
    Likes Received:
    2,182
    Just a note for everyone in this thread with these problems - this is the best fix. :cool:
     
  15. Blake

    Blake Member

    Joined:
    Apr 7, 2003
    Messages:
    9,970
    Likes Received:
    3,005
    right click the desktop icon and hit "explore". now go into each folder and rename any file ending in .exe to a new name. EG "newfile.exe, file.exe, etc"

    this stops the virus from disabling it
     
  16. pirc1

    pirc1 Member

    Joined:
    Dec 9, 2002
    Messages:
    14,137
    Likes Received:
    1,882
    if you know where the file is located you can always use a window boot disk to go into the system reapair and remove the file. I have done this before to some other virus that keeps copying itself after it is deleted.
     
  17. stipendlax

    stipendlax Member

    Joined:
    Mar 3, 2008
    Messages:
    3,274
    Likes Received:
    136
    This **** has been going around at my job. It's also my job to get rid of it.

    It's a pain. If you try to just run a scan of Malwarebytes, don't bother. It won't work. These viruses/trojans have become more sophisticated with time.

    Some have been known to disable task manager and prevent your from running anti-malware software.

    Also, note. Just because you don't get the Antivirus Pro warning pop-up doesn't necessarily mean you're in the clear. If you're able, your best bet is to scan your hard drive externally.
     
  18. studogg

    studogg Member

    Joined:
    Jul 1, 2002
    Messages:
    6,056
    Likes Received:
    2,658
    I used those programs, hijackthis and downloaded a trial version of an antivirus program and it seems to have worked

    of course my antivirus programs of mcafee and symantec did nothing
     
  19. lpbman

    lpbman Member

    Joined:
    Dec 12, 2001
    Messages:
    4,238
    Likes Received:
    795
    It probably took your TCP/IP stack when you removed it. I would do nothing less than format and reinstall after you grab your data. If the pro's here say a restore is good enough then I wouldn't argue.


    Also, Microsoft Security Essentials is the best free anti-virus out there.
     
  20. No Worries

    No Worries Member

    Joined:
    Jun 30, 1999
    Messages:
    32,833
    Likes Received:
    20,619
    Does anybody have a recommendation for a firewall/virus/malware product that prevented this infection from d/l-ing in the first place?
     

Share This Page