1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Antivirus system pro - lots of programs blocked.

Discussion in 'Malware and Virus Removal Archive' started by smithno13, 2009/10/29.

  1. 2009/10/29
    smithno13

    smithno13 Inactive Thread Starter

    Joined:
    2008/10/24
    Messages:
    63
    Likes Received:
    1
    [Inactive] Antivirus system pro - lots of programs blocked.

    Sup broni. Remember me?
    I dont know how I get myself into these messes.
    If I try to run DDS, I get the message "Application cannot be executed. The file cmd.exe is infected. Do you want to activate your antivirus software now? "
    I get the same message for taskmgr, among other things. Combofix was blocked, then I realized I shouldnt run it without your direction anyways, as it says xD
    Its an old version anyways.
     
  2. 2009/10/30
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,680
    Likes Received:
    104
    I do have an idea....


    I see you have P2P software ( Limewire, BitTorrent uTorrent etc… ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here, and here.

    I would strongly recommend that you uninstall them,

    Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at WindowsBBS Malware and Virus removal.
     

  3. to hide this advert.

  4. 2009/10/30
    smithno13

    smithno13 Inactive Thread Starter

    Joined:
    2008/10/24
    Messages:
    63
    Likes Received:
    1
    While I do understand that P2P programs can be very dangerous and lead to viruses, I believe I have never gotten on before... This virus came from a website I thought was trusted - Ninjakiwi.com. One of their ads had a virus embedded, and most of the virus alerts were targetting a .gif file in my temporary internet files. However, it could not delete it.

    However, I will take your advice and uninstall it... I hardly use it anymore.

    EDIT: I cannot access "Add or Remove Programs" from the control panel because rundll32.exe is blocked. I also cannot go through my harddrive and use the provided uninstaller because whenever I click on Program Files from the C: drive, explorer.exe freezes up.
     
    Last edited: 2009/10/30
  5. 2009/10/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Delete any Combofix file, you have.

    Download fresh copy from HERE

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE. If Combofix asks you to install Recovery Console, please allow it.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!


    Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackTHis log.
    Do NOT attempt to fix anything!

    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
     
  6. 2009/10/31
    smithno13

    smithno13 Inactive Thread Starter

    Joined:
    2008/10/24
    Messages:
    63
    Likes Received:
    1
    Actually broni, once I managed to clear my temporary internet files, Avast and Windows Defender knocked it out very nicely. If any problems arise, I'll go ahead and run combofix, but for now it seems clean. Thanks though!
     
  7. 2009/10/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Alrighty...
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.