Page 1 of 2

Virus?

Posted: 2009-04-11 10:54am
by Schuyler Colfax
I was just surfing sites when this AVG Antivirus, thing came up and said that my computer had been fucked up. It mirrored my "My Computer" window and showed what it looked like on a tab and had a blinking number saying the amount of viruses I had in each folder. It showed me what each did, and said to install it to fix it. A panicked and installed (not a good idea), and it said to update it to get virus protection, well the damn thing won't update. I have Norton on the computer (which I had forgotten), and when I pulled it up to detect any viruses, nothing came up, while every once in a while the AVG thing pops up showing me the viruses I supposedly have, and it asks me to register to update the program to get the ant-virus to work.

Any ideas on what the hell is going on?

I'm having Norton scan again.

Re: Virus?

Posted: 2009-04-11 11:05am
by Ariphaos
You had an unpatched version of Flash, Java, or perhaps something else installed, which overlaid itself over a dialog prompt asking you whether or not you wanted to allow something to fuck up your computer, which you promptly bent over for.

Naturally the only thing Norton is good for is sucking money out of your wallet + wasting CPU cycles.

http://www.internetinspiration.co.uk/roguefix.htm
http://www.malwarebytes.org/

Run these. If they don't work right off the bat (they sometimes can), then more convoluted stuff needs to be done.

Re: Virus?

Posted: 2009-04-11 12:01pm
by Schuyler Colfax
Tried malwarebytes, but once i restarted the same viruses came up, trying the other one.

Re: Virus?

Posted: 2009-04-11 12:12pm
by Schuyler Colfax
Image

This is what came up when I found out I my computer was infected. It looks legit, but its not letting me select any of the things it offers. I can't even register.

Re: Virus?

Posted: 2009-04-11 12:13pm
by Tolya
Roguefix is the shit. Saved my ass from a really nasty trojan (which apart from fucking up my computer and reducing accesibility also invited other trojans to join in the party). Be sure to follow the instructions on-screen!

Re: Virus?

Posted: 2009-04-11 12:15pm
by Tolya
Schuyler, don't buy into this ANG shit. It's just another Malware that disguises itself as a legit antivirus program. DO NOT DO ANYTHIN WITH IT! Most likely it will ask your for your money and then just download new trojans anyway.

How's the roguefix doing?

Re: Virus?

Posted: 2009-04-11 12:17pm
by phongn
Norton's newest AV program is actually good, but the older ones all suck. And, sorry Mr. Vice President, but you may well be screwed. Try the fixes Xeriar is linking to.

Re: Virus?

Posted: 2009-04-11 12:26pm
by Schuyler Colfax
I keep trying rogue, but this keeps coming up

http://www.internetinspiration.co.uk/do ... _2.242.bat

apparently, that's normal, but I don't know what to do next.

Re: Virus?

Posted: 2009-04-11 12:31pm
by Tolya
Download (right click + save as), put it into C: main directory and just run it. It is a batch file - essentially a set of commands that you could enter into your command line. It is humongous tho - its around 6 megabytes AFAIR.

Re: Virus?

Posted: 2009-04-11 12:48pm
by Schuyler Colfax
I'm not entirely sure on what its asking me to do (please be patient with me), I downloaded it, restarted the laptop in safe mode, and double-clicked the icon, and this note-pad thing came up.

Am I suppose to select that entire page and send all of that the stuff into the command box?

Re: Virus?

Posted: 2009-04-11 12:57pm
by Tolya
No. It should run, not display it's contents.

Instead of double clicking, try right clicking and selecting RUN (I have a polish OS, so the actual english command in the drop down menu may be a bit different).

Re: Virus?

Posted: 2009-04-11 01:03pm
by Schuyler Colfax
The icon itself is a notepad document, should I just select the entire thing and put it into cmd?

Re: Virus?

Posted: 2009-04-11 01:09pm
by JLTucker
Schuyler Colfax wrote:The icon itself is a notepad document, should I just select the entire thing and put it into cmd?
Open Folder Options, go to the View tab, and uncheck "Hide extensions for known filetypes". Then edit the extension of the batch file to remove ".txt".

Re: Virus?

Posted: 2009-04-11 01:09pm
by phongn
Do you have extensions hidden? Its file name should be something like foo.bat and not foo.bat.txt - which sometimes happen. Rename it; the icon should change to something with a gear on it.

Re: Virus?

Posted: 2009-04-11 01:11pm
by Schuyler Colfax
It reads roguefix_2.242.bat, but it does say it is a text document under properties.

Re: Virus?

Posted: 2009-04-11 01:30pm
by Tolya
Alrighty. In Explorer window click Tools -> Folder options. Then select the second tab from the left (View or something like this, again, a wild translation guess, sorry). Find the 8th check box from the top (it should read something of the sort: hide extensions of known types of files).

This way you will display all true extensions of all files. Then make sure that the roguefix file last three characters is .BAT and not .TXT

Good luck.

Re: Virus?

Posted: 2009-04-11 01:32pm
by Schuyler Colfax
Done and done.

Now we play the waiting game.

Re: Virus?

Posted: 2009-04-11 01:39pm
by Schuyler Colfax
I'm not really sure what happened. It came up and loaded or something, I think it scanned, but it took less than 5 seconds and asked me to reboot. I'm back on, and is something suppose to come up?

Re: Virus?

Posted: 2009-04-11 02:29pm
by Schuyler Colfax
I had 34 viruses and I'm am down to 5. I going to keeping running, the links you gave me, but is there anything else I can do?

Re: Virus?

Posted: 2009-04-11 02:56pm
by Tolya
Roguefix should get rid of the crap that is blocking access to your computer. Afterwards do a Malwarebytes scan.

However, your best bet to definitely get rid of that things is to backup your important stuff, nuke the system from the orbit (format) and reinstall it again. You can never be 100% sure you got rid of everything.

Re: Virus?

Posted: 2009-04-11 03:02pm
by Schuyler Colfax
According to ANG, I have 5 viruses left, Malware is doing its third scan, but so far it hasn't picked up anything. On its second scan it did pick up 5 though.

Re: Virus?

Posted: 2009-04-11 03:12pm
by Tolya
Don't either believe what ANG says nor even run that piece of crap. That is Malware (maybe not even a scanner) and by running it you are risking going back to step 1 - a computer full of strange shit.

Re: Virus?

Posted: 2009-04-11 03:20pm
by Schuyler Colfax
Tolya wrote:Don't either believe what ANG says nor even run that piece of crap. That is Malware (maybe not even a scanner) and by running it you are risking going back to step 1 - a computer full of strange shit.
Malwarebytes said that I still have 5 viruses. All of it is malware,

The funny part is

Image

ANG is actually listed.

Look I've been at this since 11, what's the worst that could happen if I were to turn off my laptop and pick this up later tonight or possibly tomorrow.

Re: Virus?

Posted: 2009-04-11 03:24pm
by Alyeska
Dude, how many times do we have to tell you? ANG IS THE VIRUS. Do no trust that popup and do not do anything with it at all.

Re: Virus?

Posted: 2009-04-11 03:25pm
by Tolya
Turning off is not the problem. Problem is turning it back on. If you leave something in there that is potentially dangerous, it may wreak havoc when the windows restarts.

A better thing to do is to disconnect your laptop from the internet and leave it back on.