The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    virus detected but wont get removed. help!? **PICTURE**

    Discussion in 'Security and Anti-Virus Software' started by NateSlink, Jun 22, 2009.

  1. NateSlink

    NateSlink Notebook Geek

    Reputations:
    0
    Messages:
    95
    Likes Received:
    0
    Trophy Points:
    15
    avg finds it but wont remove it, and i tried to run Malwarebytes' Anti-Malware but windows wont let me run it (or maybe the virus wont let me run it)..
     

    Attached Files:

  2. DarkSilver

    DarkSilver MSI Afterburner

    Reputations:
    378
    Messages:
    2,249
    Likes Received:
    0
    Trophy Points:
    55
    Try run your computer in safe mode and use your MBAM to destroy it.

    2nd option, download SUPERAntispyware, it is a FREEWARE that have same function as MBAM.

    3rd option, uninstall your AVG. Download Avira Antivir Personal 9! It is free and its "POWER" is stronger than AVG.

    I have plenty of options haven't list out for you. Too much. LOL. Some are complicated.
     
  3. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Rename the mbam.exe in the Malwarebytes folder to ABC.exe and then try to run it.
    Make sure to update the definitions first.
    If this doesn't work, reboot into 'safe mode with networking' and then run MBAM.
    Cheers.
     
  4. DarkSilver

    DarkSilver MSI Afterburner

    Reputations:
    378
    Messages:
    2,249
    Likes Received:
    0
    Trophy Points:
    55
    Remaning of the MBAM is so funny. Actually, it is used to cheat the VIRUS itself rite? So, the virus can be remove without knowning MBAM is actually removing it.
     
  5. NateSlink

    NateSlink Notebook Geek

    Reputations:
    0
    Messages:
    95
    Likes Received:
    0
    Trophy Points:
    15
    this worked i am scanning in regular boot mode right now. but mbam still didnt let me update. but i d/l mbam yesterday so i should be up to date right? (will post results after its done scanning)..

    BTW - im running AVG pro (not free) should i seriously consider a different program?
     
  6. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    There are AV's with higher detection rates but then again, every AV will fail once in a while.
    Avira and Avast offer decent (free) AV, spending $ I'd also check out Norton and Kaspersky AV
    Maybe you can look into a HIPS or firewall with HIPS for an extra layer of protection. (Comodo, Online Armor)
    Mostly it depends on how the infection occurred.
    If you practice sensible habits and got hit by the trojan drive-by download du jour, there's not much you can do but visiting the dark side for instance, negates most security software (no offense).
    Securing your notebook also involves DIY steps like disabling autoplay for USB sticks so classmates/roommates/colleagues can't accidentally infect your precious.
    Also, take a look at 'sandboxing' your browser with Sandboxie. (check sig for links).
    Cheers.
     
  7. NateSlink

    NateSlink Notebook Geek

    Reputations:
    0
    Messages:
    95
    Likes Received:
    0
    Trophy Points:
    15
    ok hopefully that fixed it. AVG also picked up somethings when i 1st opened my browser after mbam scan in safe mode.. here are the results..

    edit - ok every time i open my browser avg pops up that same warning
     

    Attached Files:

  8. NateSlink

    NateSlink Notebook Geek

    Reputations:
    0
    Messages:
    95
    Likes Received:
    0
    Trophy Points:
    15
    uhhh nooo, i would like to remove the virus that is causing this pop-up. plz feel free to suggest maybe a more reliable better AV program
     
  9. DarkSilver

    DarkSilver MSI Afterburner

    Reputations:
    378
    Messages:
    2,249
    Likes Received:
    0
    Trophy Points:
    55
    I would suggest you to download AVIRA ANTIVIR PERSONAL 9!
    It is a FREE AV! In addition, it is better than AVG! I used to be AVG user for years. I thought AVG is the best FREE AV out there. But when I switch/try AVIRA, I know AVIRA is better than AVG! It used less resources, light system, high detection rate and large viruses date-based.
     
  10. gerryf19

    gerryf19 I am the walrus

    Reputations:
    2,275
    Messages:
    3,990
    Likes Received:
    0
    Trophy Points:
    105
    All anti-virus programs work on a principle of definitions. The antivirus needs to know about the virus to remove it. What you have is a morphing virus with a buddy watching it's back and recreating it after removal--the recreation is randomly named so killing it is particularly problematic.

    Malwarebytes is killing the randomly created portion, but the buddy watching it's back is getting missed.

    I can tell you that while a lot of smart people hang out here, the process of malware removal in this forum is not sophisticated enough to help you easily. Here, dozens of people are going to offer dozens of solutions and leave you running in circles.

    There are several internet forums that work differently and you should really go to one of them to get this addressed. You make a post, a helper is assigned to you and they walk you through it step by step.

    Try
    www.geekstogo.com
    and go to the malware/spyware forum, and follow the instructions in the first pinned thread and someone will take care of you.
     
  11. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Actually, it seems to be a nasty recent rootkit that even MBAM cannot kill atm.
    Another step is needed to crack the rootkit and clean it's remains with MBAM as 'showed' in this Norton forum page.
    Use the ForumGeeks route (or BleepingComputer) as adviced above.
    At least post a log in such a specialized forum to get assured your notebook is clean. Rootkits are a bit**.
     
  12. osomphane

    osomphane Notebook Evangelist

    Reputations:
    81
    Messages:
    426
    Likes Received:
    0
    Trophy Points:
    30
    reformat and re-OS is your simplest option... hope you had a backup