Virus, Trojan Removal?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tomsmg, Jan 23, 2010.

  1. tomsmg

    tomsmg Private First Class

    Hello: I am here to find out how to remove lets say, the "Antivirus Live.exe"!
    My brother just had this Virus we live in different states
    No matter what you do to get rid of this virus, it does not work. First of all, all the advice for removal cannot be done because it simply takes over everything and even if you uncheck the Lan Proxy Server tip, it places the check right back in there.
    And then instructions say to download Malwarebytes etc. even though my brother has all this stuff, if cannot be run or downloaded because of the re-directing this virus does.

    Please dont mention any downloads, they are just not accessible.
    Even the Registry is closed off and the Run command

    Does any one know of a TRUE way to get rid of this kind of virus without formating the drive?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't want to bother trying our tools in safe boot or normal boot modes then I suggest that you do the below.
     
  3. tomsmg

    tomsmg Private First Class

    Ok, it windows xp Home (oem), the reason I said dont mention downloads is because he wasn't able to go to any sites other than Porn sites (redirected each time he tried)
    The pc would not accept any CD's either.
    You did give a great Idea when you said, take out the Harddrive and scan it on another pc, dont know if would work or not, but will keep it in mind next time
    However, We solved the problem, here is what happened, I tried to get him to run Malwarebytes from his desktop icon and it would not run.
    After hours of trying he figured out that the trojan had taken over his taskbar and thats why nothing worked from there.

    So to get Malwarebytes to run we had to click on the Malwarebytes Icon from the Desktop BEFORE the taskbar came up and Malwarebytes ran Great and caught 9 infections 7 real 2 False positives.
    Pc now runs good again.
    Sorry if I sounded a little strong on my post but all I saw on fix's thru out the internet were fix's that were impossible to perform, they just dont get it, when a machine is taken over, its taken over

    Im sure if it happened to you, you would understand exactly what I mean!

    Anyway, Thank You Very Much for your instructional reply, it is really appreciated.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you tried a USB flashdrive?

    Actually, there is typically a work around and some of our tools almost always run even when various scan tools do not. And this allows us to get started. But obviously you have to get the tools onto the PC first.

    You're welcome.
     
  5. tomsmg

    tomsmg Private First Class

    You said>>>
    Actually, there is typically a work around and some of our tools almost always run even when various scan tools do not. And this allows us to get started. But obviously you have to get the tools onto the PC first.

    I did not know you had these tools, but if nothing can be ran on the infected pc, how are your tools run, by Disk Offline?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Too many people make the assumption that NOTHING will run when they have not tried everything. Quite often commercial scanning tools may be blocked, but some steps of our cleaning process still will work. You have to try them to find out. Too many people quit before trying all steps and with out following instructions properly to try thing in safe boot mode, or safe boot mode with networking or from safe mode with command prompt as we request.

    In addition, those other tools mentioned will run. You just have to make the CDs.

    For people who truly cannot run anything and have really tried everything then that is why the last line says reinstall since that is the last option which comes after trying things like a repair/rebuild command.
     
  7. tomsmg

    tomsmg Private First Class

    Quote: Too many people quit before trying all steps and with out following instructions properly to try thing in safe boot mode, or safe boot mode with networking or from safe mode with command prompt as we request.

    In addition, those other tools mentioned will run. You just have to make the CDs. <<<

    Thats the point, Safe Mode dont work and CD's are not able to be played,

    Alot of people are well aware of what you can do if these things worked?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • And you don't have access to a flash drive or does that not work either?
    • What about a network connection to scan the drive from another computer?
    • Did the internet not work at all or do you have internet access? If there was access, had online scans been attempted? If using URLs was a problem, did you try using IP addresses rather than URLs? Had you flushed the DNS cache?
    • Had you tried other browsers if any are installed?
    • Had you tried disconnecting from the internet while running any scans available?
    • Had you tried using MSconfig or another startup controller to disable all startups and unnecessary services and then tried scans?
    The point is that there are many things to try. As you stated you were able to get Malwarebytes to run then the same would eventually be true for other tools especially MGtools which almost always runs even when others do not. It is a matter of figuring out what tricks are needed since the effects of each infection are not necessarily the same for each user even if the have the same name infection ( like Antivirus Live). Each user is quite often affected differently.
     
  9. tomsmg

    tomsmg Private First Class

    No, he had no flash drive available, put will let him know to keep one handy!

    Network connection was taken over via Lan proxy settings, but we just set a registry hack to lock the Lan settings from proxy's
    IP address's could not be used either, No access to command prompt or run.

    All attempts to run antivirus etc were stopped!

    Ms config would not come up at all.

    Believe me this virus was pretty complete, but as you said if Malwarebytes ran and the only reason it did was as mentioned he figured it out that the virus had control of the taskbar but not the desktop IF and Only IF he was able to click on something from the desktop BEFORE the taskbar came up.

    What tools from MG can we keep handy and should they be on a disk or flash drive? Thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The problem with this is that tools change all the time and you need to keep them updated. Also some things need to be installed ( like SUPERAntiSpyware & Malwarebytes ) and also updated. Having even an outdated copy to install from a CD or flash drive is better than nothing but you still have to be able to run the installer and the scanners. The best solution is actually to be proactive as is given by this: How to Protect yourself from malware!

    However, no tech should be with out the below CD. I always have it with me:

    UBCD4Win
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds