Uber virus attack, HELP!

This topic is locked from further discussion.

Avatar image for Love_my_PS360
Love_my_PS360

337

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#1 Love_my_PS360
Member since 2009 • 337 Posts

you know those fake security programs that download a whole bunch of viral crap onto your computer to get you to buy the "full version"? well, i'm stuck with two of them, lucky me. they are anti-malware doctor and av security suite, how do i remove them, GS?

Avatar image for C_Rule
C_Rule

9816

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#2 C_Rule
Member since 2008 • 9816 Posts

Try these. (free version will do for both.)

http://www.malwarebytes.org/

http://www.superantispyware.com/index.html

Avatar image for Love_my_PS360
Love_my_PS360

337

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#3 Love_my_PS360
Member since 2009 • 337 Posts

Try these. (free version will do for both.)

http://www.malwarebytes.org/

http://www.superantispyware.com/index.html

C_Rule

i have malware bytes already, but even a full scan won't detect either infection, only the sub-infections it creates. it also doesn't allow me to download any files.

Avatar image for quijeros
quijeros

1728

Forum Posts

0

Wiki Points

0

Followers

Reviews: 3

User Lists: 0

#4 quijeros
Member since 2008 • 1728 Posts

MBAM should be able to remove these two programs.

If you need any more help, check out these tutorials for removal and prevention. The Geeks to Go! forums in general have helped me immensely with virus problems I've had with my old laptop, and I recommend posting there if anything else serious occurs.

EDIT: Fixed link.

Avatar image for wurd
wurd

634

Forum Posts

0

Wiki Points

0

Followers

Reviews: 19

User Lists: 0

#5 wurd
Member since 2003 • 634 Posts
use malwarebytes in safe mode along with their tools to turn off the working processes but if this doesn't work then the recommeded way is a windows wipe. The newer rogue AV are very very difficult to wipe fully.
Avatar image for C_Rule
C_Rule

9816

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#6 C_Rule
Member since 2008 • 9816 Posts

MBAM should be able to remove these two programs.

If you need any more help, check out these tutorials for removal and prevention. The Geeks to Go! forums in general have helped me immensely with virus problems I've had with my old laptop, and I recommend posting there if anything else serious occurs.

quijeros
404
Avatar image for Love_my_PS360
Love_my_PS360

337

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#7 Love_my_PS360
Member since 2009 • 337 Posts

I solved it! To anyone who has the same problem, here's what i did:

1. Check your System 32 folder for any folders modified on the day you got the virus(es)

2. I'm not sure about this, but it worked for me. Near those folders should be another folder called *something*UNINSTALL*something*, with *something* being random symbols.

3. This folder should also be in your Program Files folder.

4. Inside both folders there should a file named uninstall.exe or a varient, run both files, the one in System32 should disappear and the System32 folders last modified on the day of getting the virus(es) should now read last modified on the current day/time

5. restart your computer

6. the virus(es) should no longer disrupt your connection to the internet, so you can run an uptate on malwarebytes now.

7. restart your computer, this time, go into safe mode. to do this, during your computer's restart process, press the F8 key as many times as possible, a few menues should come up. if the menu has a option reffering to safe mode, choose that. if not, you have the wrong menu, so tell it to use the default settings and get back to jamming F8.

8. once you are in safe mode, run a quick scan in Malwarebytes. it should pick up 45 viruses, give or take, this is because the fake AV programs download loads of real viruses just so that they can report them. DO NOT INTERUPT THE SCAN EARLY!

9. after the scan is through, restart your computer, this time in regular mode, and voila, the viruses should be gone.

10. you may experience problems trying to connect to the internet, if so, go into firefox tools, advanced, network, settings, and set it to "no proxy" you should connect just fine now. this may also replace steps 1-5, but steps 1-5 are how i did it.

Avatar image for KLONE360
KLONE360

1119

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#8 KLONE360
Member since 2007 • 1119 Posts
Or do the best route. Boot up on a linux disc and run av stuff through that. Linux>>>>>> Windows
Avatar image for Love_my_PS360
Love_my_PS360

337

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#9 Love_my_PS360
Member since 2009 • 337 Posts

Or do the best route. Boot up on a linux disc and run av stuff through that. Linux>>>>>> Windows KLONE360

obvious troll is obvious

Avatar image for aura_enchanted
aura_enchanted

7942

Forum Posts

0

Wiki Points

0

Followers

Reviews: 14

User Lists: 0

#10 aura_enchanted
Member since 2006 • 7942 Posts

[QUOTE="KLONE360"]Or do the best route. Boot up on a linux disc and run av stuff through that. Linux>>>>>> Windows Love_my_PS360

obvious troll is obvious

bookmarked. but he does have a good point. linux is technically virus and spyware free. as is unix. you could do as he suggests and simply target the fate.ntfs files format disk partition :P and since it cant disguise itself in an open source environment. it would BURN!!!!:twisted:

Avatar image for We_never_die
We_never_die

223

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#11 We_never_die
Member since 2008 • 223 Posts

[QUOTE="KLONE360"]Or do the best route. Boot up on a linux disc and run av stuff through that. Linux>>>>>> Windows Love_my_PS360

obvious troll is obvious

He's not trolling... you can run ubuntu 10.4 from the CD without installing any files ( LiveCd ), it's by far the fastest and easiest way to heal windows from viruses since you can't run EXE and other windows files on lunix and run a virus scan/manual delete the junk

Avatar image for Sins-of-Mosin
Sins-of-Mosin

3855

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#12 Sins-of-Mosin
Member since 2008 • 3855 Posts
Unless you got too many files to back up, a quick format is always the best and safest way to make sure you got rid of any nasty things.
Avatar image for Daytona_178
Daytona_178

14962

Forum Posts

0

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

#13 Daytona_178
Member since 2005 • 14962 Posts

Its called a SmitFraud

Download smitfraudfix & ComboFix and run them in safe mode.

Avatar image for Daytona_178
Daytona_178

14962

Forum Posts

0

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

#14 Daytona_178
Member since 2005 • 14962 Posts
Unless you got too many files to back up, a quick format is always the best and safest way to make sure you got rid of any nasty things.Sins-of-Mosin
What if the original file that brought in the virus was in his documents? Then re-install all you want and it will just come back in a couple of days.
Avatar image for IvanElk
IvanElk

3798

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#15 IvanElk
Member since 2008 • 3798 Posts
Well I have seen the windows security center thing before, but I am not too stupid enough to download it.
Avatar image for Vax45
Vax45

4834

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#16 Vax45
Member since 2005 • 4834 Posts

Or do the best route. Boot up on a linux disc and run av stuff through that. Linux>>>>>> WindowsKLONE360

Or a more realistic approach is to boot into safe mode and run your antivirus that way. Also, as added protection, stop using IE, don't run yourself as administrator, turn on your firewall, and keep your system up to date.

Avatar image for Bigsteve3570
Bigsteve3570

975

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#17 Bigsteve3570
Member since 2009 • 975 Posts

you know those fake security programs that download a whole bunch of viral crap onto your computer to get you to buy the "full version"? well, i'm stuck with two of them, lucky me. they are anti-malware doctor and av security suite, how do i remove them, GS?

Love_my_PS360
You were tagged with a bunch of viruses when trying to get something that would protect you from them? Oh, the irony.
Avatar image for Love_my_PS360
Love_my_PS360

337

Forum Posts

0

Wiki Points

0

Followers

Reviews: 13

User Lists: 0

#18 Love_my_PS360
Member since 2009 • 337 Posts

[QUOTE="Love_my_PS360"]

you know those fake security programs that download a whole bunch of viral crap onto your computer to get you to buy the "full version"? well, i'm stuck with two of them, lucky me. they are anti-malware doctor and av security suite, how do i remove them, GS?

Bigsteve3570

You were tagged with a bunch of viruses when trying to get something that would protect you from them? Oh, the irony.

Actually, i was streaming online tv from shady sites. i don't think anyone's stupid enough to INTENTIONALLY download them.

Avatar image for KLONE360
KLONE360

1119

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#19 KLONE360
Member since 2007 • 1119 Posts

[QUOTE="KLONE360"]Or do the best route. Boot up on a linux disc and run av stuff through that. Linux>>>>>> WindowsVax45

Or a more realistic approach is to boot into safe mode and run your antivirus that way. Also, as added protection, stop using IE, don't run yourself as administrator, turn on your firewall, and keep your system up to date.

? Realistic? Viruses can still run in safe mode I have seen it. Its windows dude. Linux cant even run exe files so its impossible to run the windows virus. The only reason someone would call it unrealistic is because they dont know how to use any of the linux distros such as knoppix or ubuntu. By linux I meant a distro of it. Not the kernel. The rest of your comment is common sense that many ppl dont have. I always run as admin though. I demand the power!