Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


help me remove a badass Computer virus He beaten 10 of most popular antivirus
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

help me remove a badass Computer virus He beaten 10 of most popular antivirus

qwerty6666qwerty6666 Member
edited November 2012 in General

=============================================

Solved Thank !

Hi guys . I've just cough a really bad ass computer virus i never seen any virus survive to all the anti virus / malware i usualy use . This virus is really annoying it pop advertisement like this : http://screensnapr.com/e/aZEanc.jpg most of the time from xtendmedia but also some other ads company. Those ads are displayed on ALL site reddit , facebook all !!It also affect all browser My favorite browser is opera but i got the same problem with IE and firefox as well . it also record some information about my activity because when i go to porn tube they advertise some silly weird things . sometime it also redirect me on random page let say i click a reddit link it lead me to another crap

Here the antivirus/malware i've try up to now that have failed to eradicate this bastard ( all been updated before the scan ): - Malwarebytes
- panda

  • AVG

    • Avira
  • Spybot S&D

  • eset.com ( Online scan )

And some other that ive uninstall and cant remember i've try almost 10 .

I'm getting desperate it been multiple hour i try to fix it and search google for how to fix it but havnt found much related pages .

If you guys know this virus or got another apps to sugest me id be very gratefull

Im running window 7

«1

Comments

  • Did you bother to boot into safe mode before attempting to run any of the anti-virus? That's usually what you're supposed to do with the resilient ones as it usually prevents them from starting up for self-preservation, or even better yet pop the harddrive out and scan from a different machine (preferably non-windows).

  • try avast!
    Try microsoft spyware

  • AlexBarakovAlexBarakov Patron Provider, Veteran
    edited November 2012

    @qwerty6666 said: it also record some information about my activity because when i go to porn tube they advertise some silly weird things

    Start downloading porn the old-fashion way. Here, one problem solved.

  • @Alex_LiquidHost said: @qwerty6666 said: it also record some information about my activity because when i go to porn tube they advertise some silly weird things

    Start downloading porn the old-fashion way. Here, one problem solved.

    Sure It solved the problem yesterday but today i'm a bit tired of waiting for them to download and i'm getting annoyed by all those extra advertisement =)

  • :D Some people should keep two machines, their work/etc machine, and their STDs-I've-Earned computer.

  • By any chance you only using Internet Explorer? Also did you bother to run any of those scanners from safe mode or command prompt?

  • @qwerty6666 said: it also record some information about my activity because when i go to porn tube they advertise some silly weird things >

    See, just like real life. Unsafe sex leads to the plague potentially.

    Problem #1 --- Windows. Bye. Burn it and get another OS.

    Problem #2 ---- Hosts file block. Get a big current list and start blocking IPs and domains there.

    Problem #3 --- Javascript - the growing tumor of the web. Have 24 processors and 2TB of RAM but your computer is as slow as a 600Mhz Windows 98 model? Thank you Javascript. Now more abused and annoying than Flast. DISABLE IT.

    Even if you do just #2 and #3 your life gets much better.

  • Safemode, then run malwarebytes and superantispyware, also try avast.

    Unless you do it in safemode it will activly protect itself and kill any AV/malware scanner you try and run.

    Knowing what the virus is would be useful too, sounds like a browser hijack tho.

    Oh and its not usually a good idea to have more than 1 AV running at a time.

  • kbeeziekbeezie Member
    edited November 2012

    no.2 and no.3 won't be useful until after removing the culprit.

    Far as number 2 goes : Here's one of many http://winhelp2002.mvps.org/hosts.txt

    I personally run both OSX and Windows, OSX side is my main work horse, windows is mainly my streaming (hulu, netflix, etc) and backup side (currently running windows 8 on that).

  • problem is it's java!

  • Once you have it cleaned up, install XP mode for win 7 and do your porn browsing in a VM you can just delete when you screw it up.

  • @24khost you probably already know this, but Java != Javascript. Unless you meant Java specifically (Something that's disabled in the browser of both my OSX and Windows machine).

    @Deor I'm with you on any 'risky' tasks, a virtual machine with snapshots, you can just revert the snapshot back to a clean install once the deed been done.

  • @Deor said: Oh and its not usually a good idea to have more than 1 AV running at a time.

    Yup i uninstalled them all but malwarebyte after trying them

    see ya all in 5 min in 800*600 safe mode powa =)

  • Worst case scenario, command prompt mode :D (some antivirus do support that), and even worse-worst-case scenario hook up the drive to a OSX or Linux box and scan it over (though said tool would have to be able to alter/clean an NTFS partition).

  • @kbeezie said: @Deor I'm with you on any 'risky' tasks, a virtual machine with snapshots, you can just revert the snapshot back to a clean install once the deed been done.

    Easier to hide your browsing habits from your significant other too =)

  • @kbeezie yeah I know they don't equal each other. Most of these pop up's though are browser hijacks with java!

  • @Deor if not cough the law cough (lol), I know someone paranoid enough to run a torrent client in a win7 VM, that's been system-encrypted with trucrypt.

  • I think i found the cure if your using an old win98 box

    c:\windows\deltree /y

    That should solve your problems
    !lol!

  • @24khost thus why I responded with clarification, most people may read that and just assume javascript. Course now days the only Java-enabled app I bother with are VNC consoles for VPSes (though I just use an actual client for those now). I even go as far as using ClicktoFlash on Safari so that no flash/etc actually shows unless I click on the placeholder to load it.

    But you're right, turning off Java itself from the browser can solve a lot of those in-browser hi jacks. The other method is not to be stupid and just give any app UAC permission, like those porn videos that are somehow an .exe that needs your permission to open and extract :D

  • @qwerty6666 said: Here the antivirus/malware i've try up to now that have failed to eradicate this bastard ( all been updated before the scan ): - Malwarebytes

    • panda
    • AVG
    • Avira
    • Spybot S&D
    • eset.com ( Online scan )

    I hope you're not running them all at the same time :/

  • Personally I would say at this point if you got stuff backed up (maybe via safe mode), I would just nuke it, install clean and learn from your mistakes.

  • @kbeezie said: Personally I would say at this point if you got stuff backed up (maybe via safe mode), I would just nuke it, install clean and learn from your mistakes.

    yup this option is still in consideration . I dont go much on shady site i wonder where ive cough this . The browser hijack may be it this might be why antivirus dont found it .

    Also The crap ads still appeir in safe mode hehe =)

  • jarjar Patron Provider, Top Host, Veteran

    Format C:

  • @jarland :D I think on Windows 7+ it prevents "mistakes" from occurring by requesting the volume ID before it can actually perform the format.

  • @jarland said: Format C:

    +1

    @qwerty6666 May be its time you threwout windows and try Linux ?

  • jarjar Patron Provider, Top Host, Veteran

    @kbeezie said: I think on Windows 7+ it prevents "mistakes" from occurring by requesting the volume ID before it can actually perform the format.

    You can just exit back to DOS first right?

  • @gameon typical for someone to throw out the 'switch to linux' argument, if he's having problems with windows, what makes you think linux is going to cause less stress?

  • Boot into Safe Mode and run ComboFix.

  • @jarland lol, I don't think "exiting back to dos" has been an option since Windows 95, but at least command prompt is there as long as you can still load the windows bootloader, or the install disk. Just don't think I've actually seen "MS DOS" since 95.

  • kbeeziekbeezie Member
    edited November 2012

    @MrDos
    "From bleepingcomputer.com Rick- Click,Save As, ComboFix is FREE, DO NOT download ComboFix.exe from sites other than BleepingComputer.com"

    Yet it wants you to save the file from http://www.combofix.org/downloadlink.php :D (it's a redirect to http://www.bleepingcomputer.com/combofix/how-to-use-combofix but you can see the confusion to the confusion for some people already :D)

Sign In or Register to comment.