OT: Virus question?

Voted Worlds #1 Most Loonatic Fanbase

Moderator: Andrew

OT: Virus question?

Postby Deb » Wed Dec 24, 2008 5:18 am

I figured there is some pretty knowledgable people here. My daughter accidently DL'd Antivirus 2009 on her laptop. She thought it was an update or something to her Avast. I googled it and it looks like it is a trojan or virus. I saw some different instructions on uninstalling/getting rid of it......some looked pretty technical. Does anybody know a way to uninstall this or should I take her laptop in to have it removed???
Deb
MP3
 
Posts: 14934
Joined: Sun Aug 06, 2006 11:23 am
Location: Gotta Love The Ride!

Postby Don » Wed Dec 24, 2008 5:47 am

Click start and click the run link, type msconfig in your run box and hit ok. go to the the startup tab and uncheck everything except Avast. Reboot and tick the little box so the config GUI doesn't keep popping up everytime you restart. Try to boot up in safe mode and see if Avast can remove it. When you're booting up hit the F8 key before it goes into the windows startup screen. Pick the safemode option with out network.

Try to download this program and run it also.

http://www.download.com/Spybot-Search-a ... 22137.html
Don
Super Audio CD
 
Posts: 24896
Joined: Sun Jul 22, 2007 3:01 pm

Postby Rip Rokken » Wed Dec 24, 2008 6:25 am

Hey, Deb. I predicted it was this before opening the thread - it's the #1 thing I see, and has more strains than Deano on the crapper. Some are lightweight, but many employ rootkits - stealth files that often are invisible and attach to vital system processes evn in Safe Mode, and I usually end up removing them with the help of a Linux boot disc where I can see everything on the drive outside of Windows. If your AV software can't remove it fully, the cheapest thing is to run a restore disc to take it back to factory defaults.

One very important thing - this is most often linked to ID theft, so don't get tricked into using your credit card to "purchase" the fake product.

Best of luck.
Last edited by Rip Rokken on Wed Dec 24, 2008 6:30 am, edited 1 time in total.
Image
User avatar
Rip Rokken
Digital Audio Tape
 
Posts: 9203
Joined: Mon Oct 01, 2007 5:43 pm
Location: Vadokken City

Postby Deb » Wed Dec 24, 2008 6:28 am

Gunbot wrote:Click start and click the run link, type msconfig in your run box and hit ok. go to the the startup tab and uncheck everything except Avast. Reboot and tick the little box so the config GUI doesn't keep popping up everytime you restart. Try to boot up in safe mode and see if Avast can remove it. When you're booting up hit the F8 key before it goes into the windows startup screen. Pick the safemode option with out network.

Try to download this program and run it also.

http://www.download.com/Spybot-Search-a ... 22137.html


Thanks Gbot. I'm at work, she's at home......LOL not even going to attempt to walk her through that. I'll give it a try tonight. Do I have to reset anything back after? Thanks again.

Oh and BTW she did run a scan on Avast, took forever....but she said it didn't come up with any infected? Mind you that wasn't in safe mode though? But there obviously is, cuz that antivirus 2009 box keeps popping up saying how many infected?
Deb
MP3
 
Posts: 14934
Joined: Sun Aug 06, 2006 11:23 am
Location: Gotta Love The Ride!

Postby bluejeangirl76 » Wed Dec 24, 2008 6:28 am

Rip Rokken wrote:and has more strains than Deano on the crapper.



LMAO! :lol:
User avatar
bluejeangirl76
MP3
 
Posts: 13346
Joined: Fri Oct 13, 2006 5:36 am

Postby Rip Rokken » Wed Dec 24, 2008 6:32 am

bluejeangirl76 wrote:
Rip Rokken wrote:and has more strains than Deano on the crapper.



LMAO! :lol:


I still got it! (Ralph Malph voice). :)
Image
User avatar
Rip Rokken
Digital Audio Tape
 
Posts: 9203
Joined: Mon Oct 01, 2007 5:43 pm
Location: Vadokken City

Postby Deb » Wed Dec 24, 2008 6:37 am

Rip Rokken wrote:Hey, Deb. I predicted it was this before opening the thread - it's the #1 thing I see, and has more strains than Deano on the crapper. Some are lightweight, but many employ rootkits - stealth files that often are invisible and attach to vital system processes evn in Safe Mode, and I usually end up removing them with the help of a Linux boot disc where I can see everything on the drive outside of Windows. If your AV software can't remove it fully, the cheapest thing is to run a restore disc to take it back to factory defaults.

One very important thing - this is most often linked to ID theft, so don't get tricked into using your credit card to "purchase" the fake product.

Best of luck.


Thanks Rip! No worries there, she doesn't have a cc yet. :lol: That's when she knew it wasn't an avast update when it popped up asking her to purchase such and such program to remove infected files......and phoned mommy. :lol: Her laptop would have come with a a restore disc, right?
Deb
MP3
 
Posts: 14934
Joined: Sun Aug 06, 2006 11:23 am
Location: Gotta Love The Ride!

Postby stevew2 » Wed Dec 24, 2008 7:45 am

I had to crash mine once and boot it up with the recovery CD,and reinstall my virus protection,there was no other way
User avatar
stevew2
MP3
 
Posts: 13073
Joined: Sat Dec 02, 2006 4:20 pm
Location: Maryland

Postby Rick » Wed Dec 24, 2008 8:06 am

Another thing to do is double click on the Avast icon on your desktop. Click on the doodad that looks like an eject button. Image In the resulting menu, move your mouse over Updating and then click on iAVS Update. Allow Avast to update itself, then click on the eject button thingy again, and then click on Schedule Boot-Time Scan. Restart the computer and Avast will scan it before Windows loads, and has a much better chance of cleaning the system. After that, go to www.download.com Search for then download Spybot Search & Destroy. Install it, update it and scan your computer with that. Allow it to fix all problems it finds.

I hope this helps.
Last edited by Rick on Wed Dec 24, 2008 8:07 am, edited 1 time in total.
I like to sit out on the front porch, where the birds can see me, eating a plate of scrambled eggs, just so they know what I'm capable of.
User avatar
Rick
Super Audio CD
 
Posts: 16726
Joined: Sat Dec 23, 2006 9:29 am
Location: Texas

Postby jrnyman28 » Wed Dec 24, 2008 8:07 am

I think I got that one as well. Just as my LiveCare Subscription expired!!! Really not looking forard to redoing it all....again.
jrnyman28
Compact Disc
 
Posts: 6742
Joined: Thu Sep 12, 2002 2:15 pm

Postby Deb » Wed Dec 24, 2008 8:18 am

Rick wrote:Another thing to do is double click on the Avast icon on your desktop. Click on the doodad that looks like an eject button. Image In the resulting menu, move your mouse over Updating and then click on iAVS Update. Allow Avast to update itself, then click on the eject button thingy again, and then click on Schedule Boot-Time Scan. Restart the computer and Avast will scan it before Windows loads, and has a much better chance of cleaning the system. After that, go to www.download.com Search for then download Spybot Search & Destroy. Install it, update it and scan your computer with that. Allow it to fix all problems it finds.

I hope this helps.


Thanks a bunch, you guys rock. Thanks for all your help. I'll try this too. Thing is, she said she ran an AVAST scan, it took forever, but she said nothing came up infected. But obviously it is if an Antivirus 2009 box is coming up saying there is infected files. Rip, could this be what you mean by a lightweight version, gawd I hope so. :lol:

You know what, let me have a look at it first later before I ask anymore questions, I'm getting this all second hand.....

Oh and Rick, you're slipping.......these instructions didn't come with scheduled coffee and potty breaks.....like your Nero to youtube instructions. :lol: :P
Deb
MP3
 
Posts: 14934
Joined: Sun Aug 06, 2006 11:23 am
Location: Gotta Love The Ride!

Re: OT: Virus question?

Postby epoy » Wed Dec 24, 2008 8:30 am

Deb wrote:I figured there is some pretty knowledgable people here. My daughter accidently DL'd Antivirus 2009 on her laptop. She thought it was an update or something to her Avast. I googled it and it looks like it is a trojan or virus. I saw some different instructions on uninstalling/getting rid of it......some looked pretty technical. Does anybody know a way to uninstall this or should I take her laptop in to have it removed???


It is not a virus that's why Avast didn't pick it up. It's malware. AntiVirus 2009 sent it and so it is "reporting" maliciously as a virus so you can purchase their software. It will take over your homepage, etc. You can try what the others have suggested but if it doesn't get rid of it, try http://www.malwarebytes.org/ - there's a free version and i have great success with it.

Here's more info about AntiVirus 2009:

Antivirus 2009 is a new rogue anti-spyware program from the same family as Antivirus 2008 and Doctor Antivirus . Antivirus 2009 is installed and advertised through the use of misleading web sites that attempt to make you think your computer is infected with a variety of malware. Once installed, Antivirus 2009 will scan your computer and list a variety of fake infections that can't be removed unless you first purchase the software. These infections are fake, though, and only being shown to scare you into purchasing the software.

When Antivirus 2009 is installed, a Internet Explorer browser helper object is also installed that displays fake messages when using Internet Explorer. These messages range from a line at the top of the browser stating an infection was found to adding a box to the Google homepage stating Google detected that your computer was infected. These tactics are just two more methods where Antivirus 2009 uses false information to scare you into purchasing their software.
Last edited by epoy on Wed Dec 24, 2008 8:39 am, edited 1 time in total.
"When you come to a fork in the road, take it." - Yogi Berra
"Sometimes i wonder, why is that frisbee getting bigger? Then it hit me..." - Anonymous
User avatar
epoy
Ol' 78
 
Posts: 153
Joined: Wed Aug 13, 2008 7:20 am
Location: Beehive State

Re: OT: Virus question?

Postby Deb » Wed Dec 24, 2008 8:36 am

epoy wrote:
Deb wrote:I figured there is some pretty knowledgable people here. My daughter accidently DL'd Antivirus 2009 on her laptop. She thought it was an update or something to her Avast. I googled it and it looks like it is a trojan or virus. I saw some different instructions on uninstalling/getting rid of it......some looked pretty technical. Does anybody know a way to uninstall this or should I take her laptop in to have it removed???


It is not a virus that's why Avast didn't pick it up. It's malware. AntiVirus 2009 sent it and so it is "reporting" maliciously as a virus so you can purchase their software. It will take over your homepage, etc. You can try what the others have suggested but if it doesn't get rid of it, try http://www.malwarebytes.org/ - there's a free version and i have great success with it.


Thank you very much, will try that. Was wondering why she kept telling me it wasn't showing up in AVAST scans?
Deb
MP3
 
Posts: 14934
Joined: Sun Aug 06, 2006 11:23 am
Location: Gotta Love The Ride!

Postby weatherman90 » Wed Dec 24, 2008 8:52 am

Using the Mozilla Firefox browser also helps to prevent that sort of thing from happening in the future. It is much more secure than Internet Explorer.
Matt
--------------------------------------
www.melodicrockconcerts.com
User avatar
weatherman90
Cassette Tape
 
Posts: 1565
Joined: Tue Aug 14, 2007 11:03 am
Location: Bismarck, ND

Postby Rip Rokken » Wed Dec 24, 2008 8:54 am

The lines between viruses/malware/spyware are really blurred these days, and most current products overlap their protection. I did read a recent article that said all the major security products only detect 25% of new botnet infections (the types that create networks of zombie PC's). After 30 days, that # increases to only 50%.

I quit relying on traditional scanning products myself a few years ago for virus removal, and do them all manually with a boot disk and a few utilities like Hijack This. There is no infection I've run across that I haven't been able to fully remove without wiping the drive unless it was by choice, but they are getting trickier all the time.

Deb, whether your laptop has a restore cd depends on the brand and model. Hope you get an easier variant to remove. SuperAntispware is also a great free scanner that does a good job.
Image
User avatar
Rip Rokken
Digital Audio Tape
 
Posts: 9203
Joined: Mon Oct 01, 2007 5:43 pm
Location: Vadokken City

Postby squirt1 » Wed Dec 24, 2008 11:08 am

Rip- I will laugh for the week. That was a good one !
squirt1
Cassette Tape
 
Posts: 1914
Joined: Thu Aug 03, 2006 10:47 am

Postby T-Bone » Wed Dec 24, 2008 11:26 am

Using the msconfig thingy doesn't get rid of a virus as they run hidden in the background and embed themselves in the registry. It'll take a specialized type program to assist you in getting rid of it, but if you don't know what the virus is, then it gets harder. HiJackThis V2 is a good one, but you have to be VERY CAREFUL on what you remove. Without seeing it, I can't help. Try having someone more knowledgable look at it in person before you do something that can't be undone
T-Bone
 

Postby pinkfloyd1973 » Wed Dec 24, 2008 12:31 pm

My boyfriend just got done wiping my computer totally out to rid us of this, now I have Norton (which I hear is very good) and Spy Sweeper to catch anymore trojans viruses and malware. I prolly should have read this thread before we went through all this, but i'm hoping it's rid of once and for all (and just so you know we had to re-download 98 updates) :evil:

Robin :?
"So this is how liberty dies, with thunderous applause."
User avatar
pinkfloyd1973
Cassette Tape
 
Posts: 1725
Joined: Thu Jul 13, 2006 11:15 am
Location: Sweet Home Chicago

Postby T-Bone » Wed Dec 24, 2008 7:55 pm

Actually, Norton is "ok", but it can be a system hog using your own system memory to run itself. I'd recommend Kaspersky or BitDefender

http://anti-virus-software-review.toptenreviews.com/


Spy Sweeper, if left running, can also be a system hog. It does the job ok, but I got annoyed with it bogging my system.


I run BitDefender on both my big rig and my backup and also run SpyBot Search And Destroy once a week. I usually have zero problems. And SpyBot only is running when I allow it to.



And wiping your system completely is sometimes the best thing to do. I redo my system at least once a year whether it needs it or not just to keep things in top form.
T-Bone
 

Postby Abitaman » Wed Dec 24, 2008 10:19 pm

I use AVG (the free version). It removes anything I have had problems with. Stuff Norton would not. You can get it at download.com when there type in AVG free. And it will take you to the download.
Eric, the Abitaman
Abitaman
Stereo LP
 
Posts: 4865
Joined: Fri Aug 13, 2004 8:06 pm
Location: NO LONGER in West TN, now in East TN's beautiful Smokey Mountains


Return to Journey

Who is online

Users browsing this forum: No registered users and 19 guests