Annoying Virus & Complications

Praxis1452

Platinum Member
Jan 31, 2006
2,197
0
0
I've had a virus for sometime now, and it's been pretty difficult to remove. I'm using ad-aware, avira antivir, & Spybot S&D.

I first started noticing this when mozilla started randomly downloading pdf files. I manually removed them and scanned with ad-ware and avira. Ad-aware found nothing, and avira a trojan, which it quarantined/removed. It continued to do this from time to time and I kind of ignored it and manually removed the files right away as best I could.

A few days ago I got a popup for an antivirus, typical story I guess. Locked down my other programs, refused to let me open task manager, spybot, ad-aware, avira. Usually I always keep task manager running so I closed the process right away. It was random gibberish (.exe)

After running ad-aware and finding nothing, then running avira again, and finding nothing, I decided to use spybot and removed some malware. The problem was that after I removed it, I cannot get internet access with IE or Opera. Mozilla still works, but I'd like to be able to use my other browsers.

My response was to system restore, but that seemed to restore the malware again. After having it pop up on me again, I decided to make sure I removed all the pdf's and I had missed one. After I tried restoring it this time, system restore failed due to some missing files. I also installed a new version of avira, so that may be why as well.

IE states: "cannot display the webpage" and diagnosing states: "the remote device or resource won't accept the connection"

Opera states: Could not connect to proxy server. Access denied
Disabling proxy servers allows it to work. Is there a similar fix for IE?

The main reason I have three browsers is Mozilla has a huuuge memory leak, and crashes under heavy usage in only an hour. Opera works well, but I'm getting used to it. Youtube stopped working on it for a while. Ninjavideo doesn't work on Opera. IE I use sometimes when I don't want to deal with either.

BTW the antivirus program popup was called Antispywaresoft I think.

Anyone else have something similar? Maybe it's just cause I'm noob at this. I usually just expect Ad-Aware, Spybot S&D, and avira to catch everything quickly but this one I couldn't get for like a month.

edit: So I kinda forgot to mention my major issue. Ninjavideo won't work after I've removed the virus. Browsing websites will load, but trying to use the ninjavideo applet to play the vidoe just will not work. It will be connecting... forever. Once I system restore, it begins working again along with all the other browsers. Damnit! this sucks. Might have to just reinstall all my browsers, and if that doesn't work repair install windows, not sure what else is messed up.
 
Last edited:

Rubycon

Madame President
Aug 10, 2005
17,768
485
126
Ad Aware and Spybot are really yesterday's news!
Use Malwarebytes - www.malwarebytes.org to clean you system.

The malware runs on your system as a proxy mode so it changes your browser's settings to use a proxy server with 127.0.0.1 as the proxy address. This means pages are often changed to get you to download or do something to your PC which will worsen things I guarantee you!

In your browser settings under connections make sure any options to use a proxy server are left UNCHECKED. Since the exe (which is the fake proxy server) is not running your browser cannot find any sites because it's still looking at 127.0.0.1 - which is your machine itself.

Malwarebytes should clean it up. Run a quick scan first, remove and clean - rebooting if it says too. Then you can run the full scan which takes considerably longer as it scans the entire PC. Repeat the process with the quick scan if anything is found.
 

Praxis1452

Platinum Member
Jan 31, 2006
2,197
0
0
Ad Aware and Spybot are really yesterday's news!
Use Malwarebytes - www.malwarebytes.org to clean you system.

The malware runs on your system as a proxy mode so it changes your browser's settings to use a proxy server with 127.0.0.1 as the proxy address. This means pages are often changed to get you to download or do something to your PC which will worsen things I guarantee you!

In your browser settings under connections make sure any options to use a proxy server are left UNCHECKED. Since the exe (which is the fake proxy server) is not running your browser cannot find any sites because it's still looking at 127.0.0.1 - which is your machine itself.

Malwarebytes should clean it up. Run a quick scan first, remove and clean - rebooting if it says too. Then you can run the full scan which takes considerably longer as it scans the entire PC. Repeat the process with the quick scan if anything is found.
thanks a lot!

Too busy playing demon's souls to clean up my PC. Guess that's what I get for not keeping up with my security.

edit: still not sure what settings then virus changed, though it most certainly changed my browsers to use proxy servers, as I can now surf the web with all three browsers. Did a clean install of firefox, but ninjavideo still will not work. The malware fucked some settting on my end. Maybe I'll do a clean clean install, wiping out everything, and just use xmarks to resync my bookmarks etc. IE crashes everytime I try to enter a captcha on ninjavideo.

Malwarebytes only detected an old keygen, but that's been there for ages. I ran a quick + full scan and have had no luck. Unfortunately I noticed a new download on firefox today so I'm still infected. :(. hmmm
 
Last edited:

Pegun

Golden Member
Jan 18, 2004
1,334
0
71
My advice would be to do an offline scan of your computer, in other words find a scanner that can do a scan as the computer is starting up and there are few if no services running. I know Avast can do this, I'm not sure about Avira. Otherwise I would give the same advice I've given a hundred times, flush and fill. The complications that come with any virus are not worth the loss of your privacy, identity and personal information so you might be better off backing up your profile and saved games, reformatting and reinstalling your operating system. This of course only applies if you have a legit operating system, which all of us do here at Anand ;)
 

JEDIYoda

Lifer
Jul 13, 2005
33,982
3,318
126
My advice would be to do an offline scan of your computer, in other words find a scanner that can do a scan as the computer is starting up and there are few if no services running. I know Avast can do this, I'm not sure about Avira. Otherwise I would give the same advice I've given a hundred times, flush and fill. The complications that come with any virus are not worth the loss of your privacy, identity and personal information so you might be better off backing up your profile and saved games, reformatting and reinstalling your operating system. This of course only applies if you have a legit operating system, which all of us do here at Anand ;)

Just disconnect the computer from the internet any old way, including unplugging your modem....
 

stlcardinals

Senior member
Sep 15, 2005
729
0
76
Step 1: Download Malwarebytes from another computer onto a flash drive
Step 2: Turn Off System Restore
Step 3: Reboot into Safe Mode
Step 4: Install Malwarebytes and run it
Step 5: Reboot normally
Step 6: Turn System Restore back on

If that doesn't take care of the problem, it's time to reload your system.