Hola ! Dont fight guy ! Stay calm…
His expertise, and knowledge at malware removal is unrivalled here.+1 The best rootkit killer essexboy
I will try that. Hopefully a USB will suffice, as my disc drive on my infected computer has not been working for almost a year now; has nothing to do with the recent virus though.
Well I mean, he wasn’t insulting you. Just didn’t agree.
I had the same problem a few weeks ago. My Avast also was unable to detect it.
And what I did was that I installed ESET NOD32 on it and it kicked the adware out of my PC .I advice u to do the same.
I am DAMMMM… sure if the nod32 is fully up to date, it is going to give a very good hit on the ass of the virus.
Best of luck!!!
Your virus must not have been that bad then.
I ran NOD32 and it seemed like it came close, at least. The virus wasn’t shutting it down, but NOD32 kept saying whenever it detected something that it needs to reboot to delete the infected file. However when I rebooted it, it didn’t do anything…it’s not like avast which will run a scan before you even log on with your account. I logged on and NOD32 did not even start up. However the one time it DID start up, it just said again that it needs to reboot to delete the file…obviously it’s getting owned by this piece of dog crap virus as well.
For the record, I don’t see what FF did or said to be criticized. All I saw was disagreement on his part.
The online world is doomed: http://oceania.digitalmedianet.com/articles/viewarticle.jsp?id=857595
Guess hell is for real then.
Congratulations Freewheeling Frank, I take my hat off to you. Due to your offensive, stupid remarks, you have just alienated, ( in my opinion ) the most talented person who visits this forum. His expertise, and knowledge at malware removal is unrivalled here. Not only that, he goes about his business, in a pleasant, calm, and very professional manner. Willing to help anyone, without question or judgement.A person who spends hours, analyzing logs,that no one else understands. His contribution to this forum and other forums, is invalueable.
Most people on this forum, myself included, have very little idea about removing serious malware. Many people who visit, seeking help, often leave, frustrated, due to the lack of expertise.
So to upset, one of the few people who has the expertise, is rank stupidity.
And Freewheeling Frank, loudmouth, what is your contribution ? How many people do you help ? I may be wrong, I don’t recall you, ever, giving, professional malware removal advice.
The one thing that surprises me, is the fact, that no one else, is, telling you, what a moron you are. It’s a bit cliquey here though isn’t it.
So once again F.F many congrats, I will expect, if Essexboy, no longer visits, this forum, you will, be filling his shoes, and, giving people, advice, on cleaning, their pc’s. I look forward to that ;D
Essexboy is being too much of a drama queen. Make an absolute statement of certainty around here about what constitutes essential computer security, and somebody is going to take issue.
Well I mean, he wasn’t insulting you. Just didn’t agree.
Thanks. In the post Essexboy objected to, that’s perfectly true.
Secunia is running a scan now...the past 20 tries I've tried with antimalware programs to scan and delete infected files, failed, as they just closed down due to a setting created by the virus, and every time I try to reopen the application it says files are missing. This is none other than the crappy virus being a B.I'm sorry, I hadn't realized that you were actually trying to deal with an active malware infection. (Yes, I know you said you got infected, I just hadn't realized it was happening "right now".) The Secunia scanner is not an antimalware application. It is purely a scanner/monitor, which gathers version data about your installed software, compares it to an extensive online database, and alerts you to out of date/vulnerable software. It is not intended it be used to assist with an active infection, and my recommendation to use it was/is based on the idea that having up to date software can very much reduce the chance of getting an infection, since those that the user doesn't install are generally installed via some software vulnerability. Should you be able to remove this thing, it would [i]then[/i] be a good tool to install to help keep you up to date. I apologize for not being expert enough to assist with the removal of this infection. The reported condition of your computer (or rather, what seems to have been disabled from your use of it) is beyond my experience to advise on.
FreewheelinFrank If it was me, I’d apologize, frankly. Telling someone that they are “too much up their paranoid rear” is hardly going to win friends. In that post, I thought you were being extremely rude. Calling someone a drama queen is not a heck of a lot better.
Your virus must not have been that bad then.I ran NOD32 and it seemed like it came close, at least. The virus wasn’t shutting it down, but NOD32 kept saying whenever it detected something that it needs to reboot to delete the infected file. However when I rebooted it, it didn’t do anything…it’s not like avast which will run a scan before you even log on with your account. I logged on and NOD32 did not even start up. However the one time it DID start up, it just said again that it needs to reboot to delete the file…obviously it’s getting owned by this piece of dog crap virus as well.
Strange!!
Did u try Malwarebytes antimalware
If yes,try SPYWARE DOCTOR or threatfire.
do not worry I will help u to remove that at any cost because I hate that virus more than anything
This is a link for the removal tool of av2010.
Hope it works!!
Or try
http://www.spywarevoid.com/antivirus-2010-removal-guide-remove-antivirus2010.html
If none works try AVIRA, I am 90% sure it will work though I never tried
And after u find the infected files , E-mail the to Avast.
Regards,
Shubham
Hi Shubham,
This is a rogue or fake AV program that has it’s ever-changing presence on the Internet to scare the **** out of unaware users to make them pay for a worthless fake program that is even inviting more **** onto their machines. The removal of these programs is best dealt through a qualified malware terminator like we have here essexboy and oldman, because they have the ever-evolving tools to do so and the expertise as a trained eliminator.
On the other hand it is true that a decent layered prevention and first and foremost a fully patched and updated Operational System and third party software (Secunia PSI scan) protects because the fake av tools are launched through a pack of known existing exploits and need the cooperation of the user that thinks his machine is infected.
A lot of people are not aware that not all pop-ups and messages are genuine MS messages and click to install malcode because they think it is a genuine Microsoft or computer message. So updating, patching and knowledge will keep the malware away, I would not advice spyware doctor…and it doesn’t let you clean the infections without paying, then they will be suspicious. Just my opinion!
polonus
Maybe Polonus is right, you should try once
The last option is System restore
Shubham,
I have sent you a message using the forum message feature. I don’t know whether you can reply or not. but please check.
nmb.
I have sent you a message using the forum message feature. I don't know whether you can reply or not. but please check.
I cant reply but I can e-mail if u tell me ur ID.
Make one more post, Shubham, and you should be able to reply to nmb’s message. It only takes 20 posts and you now have 19 posts.
you can message after number of posts is 20. i think its 19. one more to go.
charley you were fast.
nmb
I am just about to go on holiday but do the following it should clear the majority
Please save this file to your desktop
THEN
Click on Start->Run, and copy-paste the following command (the bolded text) into the “Open” box, and click OK.
“%userprofile%\desktop\win32kdiag.exe” -f -r
When it’s finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.
FINALLY
Download Combofix from any of the links below. You must rename it before saving rename it to Gotcha before saving it to your desktop.
==================================
Double click on the renamed ComboFix.exe & follow the prompts.
When finished, it will produce a report for you.
[*]Please post the C:\ComboFix.txt so we can continue cleaning the system.
Hi essexboy,
Very helpful posting there. We’ll refer to that. I like to wish nice holidays,
polonus
I would recommend using 2 free programs to remove any Malware infections. MalwareBytes AntiMalware and SuperAntiSpyware. They are both excellent and go about their businees in somewhat different ways. It is highly unlikely that anything could get past the scans of both of them. The free versions are just as powerful as the paid. The only thing you gain in the paid ones are realtime protection (which should not run in conjunction with an AV) and automatic updates (which aren’t needed if you just use them on demand, just run the updater before scanning).
As had been said, the lowlife malware authors change their “products” constantly to avoid detection by security software. You can be sure that they constantly test their products against the latest detection abilities of all of the security products so it’s a never ending battle to catch up. You can never be ahead of them unless you have some kind of a behavior blocker or HIPS system installed and even then, it’s not 100% sure they won’t find a way to get you.
Dch48,
The users (avastuser 1000 and Meteora) on the preceding pages of this thread did try the programs you mention. To varying degrees, they have seriously limited access to their systems, and in Meteora’s case, the only system utility than can be accessed is Regedit. We’re a bit beyond the use of antimalware scanners.
Those programs (especially MBAM, perhaps because it’s a smaller download) are often recommended at this forum. I agree, when they can be used, they’re darned good.
Hello Dch48,
If essexboy has posted, it means all the other scanners which we generally advise have not helped the person.
nmb