TechSpot

Antivirus won't launch, redirected from antivirus website

By tonight1000
May 10, 2009
  1. Hi all,

    I am very new to this and i currently cant launch any antivirus software that i have downloaded from bit torrent site (note: i have been redirected or page showing error everytime i try to visit antivirus webiste)

    I am attaching a hjt log and your kind advice is appreciated.

    Thank You.

    tonight1000
     

    Attached Files:

  2. touch

    touch TS Rookie Posts: 978

    Hmm, it sound like you have downloaded piracy/cracked software -
    "cant launch any antivirus software that i have downloaded from bit torrent site"

    We do not support piracy, nor do we support P2P programs .

    Besides the hijackthis log have a large number of infections.
     
  3. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

    I use free Avira Antivirus I find it to be way better than most (if not all) free or paid versions :)
    Oh and I use this free Antivirus myself, I think you should consider that

    By the way, always go to the manufacture website to download stuff, most of it is free :)

    If you do decide to remove all the torrent stuff and anything else that's probably causing bad issues
    Have a look here: UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions
     
  4. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    As mentioned, your system is badly infected. One of the infections is the DNS Changer. which is a very serious.

    The use of the P2P programs is an invitation to malware: This may help you realize the danger:
    Credits to kritius

    Downloading a security program from a file sharing site is foolish. You need for these programs to be legitimate and with all the necessary features. Getting them from a file sharing site doesn't guarantee any of this.

    Please follow the 8 Steps in the link HERE:

    In addition to those programs, I'd like you to run Combofix. That will give us a better idea of the extent of the file sharing and if any piracy has been involved:
    [​IMG]Combofix
    Combofix instruction credits to Blind Dragon: Virus and Malware Removal: http://www.tech-101.com/virus-malware-removal/

    Please attach the 3 logs and the Combofix report to your next post. IF we determine that you are using pirated programs, our help will not be available.

    NOTE: In addition to the DNS Changer malware, you have the W32/Aimdes-C WORM which exploit AOL instant messenger and harvest email addresses. There is also RUNDLL88.EXE which is added as a Registry auto start to load Program on Boot up, xecuted from Temporary Folders, copied to multiple locations on the system and executed as a Process

    Something has also disabled doing a Registry Edit. You have numerous serious issues on the system.
     
  5. tonight1000

    tonight1000 TS Rookie Topic Starter

    Thanks for the kind replies.

    I have uninstalled bittorrent and bitcomet. i have also donwloaded the malwarebyte software , renamed it but an error message says ' the setup files are corrupted. please obtain a new copy of the program' .

    Does it mean the malware in my laptop is stopping me from installing malwarebyte and what else could i do ?

    Any kind advice is appreciated.

    Thanks.
     
  6. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

    Delete the downloaded corrupted MalwareBytes
    Run CCleaner
    Re-Download Malwarebytes again; Update it; then run a full scan (remove all found Malwares at the end of the scan)
     
  7. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Malwarebytes not running

    Please download and try running this: randmbam.exe

    It will try to create random names and shortcuts for Malwarebytes Anti Malware(MBAM) if you have it installed already.

    Once done, try running a scan again

    I think you will find this woks for you.
     
  8. tonight1000

    tonight1000 TS Rookie Topic Starter

    i think i am losing this battle against the malware in my laptop, i have run the latest ccleaner twice as told. then when i tried to click on the link you guys provided to download malwarebyte, the web browser will change back to homepage of techspot.com. how annoying.

    please help !
     
  9. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

  10. tonight1000

    tonight1000 TS Rookie Topic Starter

    thx kimsland, your link works and i managed to download malwarebyte, and run it after using randmbam.exe. i tried to update the malwarebyte and it says i don't have internet connection which is untrue because my internet connection is definately working.

    The scanning process hanged about 16% progress (managed to detect 16 malware so far) and and window saying 'google installer has encountered a problem and needs to close'.

    this window pop up everytime since my laptop is affected.

    after i have restarted the computer, the file generated by randmbam doesn't work anymore and give some error message.

    what should i do ?
     
  11. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

    Here is the manual update which should work: http://www.gt500.org/malwarebytes/mbam-rules.exe

    If not, then you might want to skip a step and run ComboFix:

    • Download [​IMG]Combofix to your desktop.
    • Double click ComboFix & follow the prompts.
    • A window will open with a warning.
    • When the scan completes it will open a text window.
    • Please save the log to be attached to a new reply

    Hopefully Malwarebytes will also scan now (updated first of course)
    If so, also save that log to be attached to the same new reply

    This was all to do with P2P !
     
  12. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    I had already instructed using Combofix.
     
  13. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

    Oh :confused:

    Where's the ComboFix log, tonight1000 ?
     
  14. tonight1000

    tonight1000 TS Rookie Topic Starter

    Dear Kimsland and Bobbye,

    Sorry for the late reply, i have managed to scan my laptop using malwarebyte,cleaned approx. 40 threats.

    but after that, i couldn't get on internet anymore, hence couldnt download the combofix software. and error message saying '

    i have tried to reformat my C drive using a windows xp installation cd but it the laptop keeps on shutting down during the process.

    is there any clever ways out there to help me out from this mess?

    thanks.
     
  15. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

  16. tonight1000

    tonight1000 TS Rookie Topic Starter

    Hi Kimsland,

    I have formatted my C drive and reinstalled windows, when i have download and run malwarebyte, it still found many trojans. Hence i have downloaded and run combofix and please see the attached log.

    Please advise.

    Thanks.
     

    Attached Files:

  17. kritius

    kritius TS Guru Posts: 2,084

    The reason you may be re infected is because there may be a DNS changer which can infect your router.

    1. Shut down your computer, and any other computer connected to your router.
    2. On the back of the router, there should be a small hole or button labelled RESET. Using a bent paper clip or similar item, hold that in continuously for twenty seconds. Unplug the router. Wait sixty seconds. Now holding again the reset button, plug it back in. Continue holding the reset button for twenty seconds. Unplug the router again.
    3. With the router unplugged, start your computer. Run MBAM again.
    4. Connect again to the router. The turn the router back on. When it stabilizes, reboot your workstation and try to aceess the internet. If you have any issues, access the Router configuration page and re-enter your authentication information.
    5. Attach the new offline MBAM scan results here.

    Run CFScript
    Open notepad and copy/paste the text in the code box below into it:
    NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
    Also ..

    Pay particular attention to this :-

    Make sure the word KillAll:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
    Code:
    KillAll::
    
    File::
    c:\windows\system32\drivers\wmzolan.sys
    c:\docume~1\Avin\LOCALS~1\Temp\ovfsthbdrtfqwgta.tmp
    c:\docume~1\Avin\LOCALS~1\Temp\ovfsthdstraetspj.tmp
    c:\docume~1\Avin\LOCALS~1\Temp\ovfsthmnrdvnnorx.tmp
    
    Folder::
    c:\docume~1\Avin\LOCALS~1\Temp\ovfsth000
    c:\docume~1\Avin\LOCALS~1\Temp\ovfsthx000
    
    Driver::
    jplbozx
    
    Rootkit::
    c:\windows\system32\ovfsthbgradybewteceviqtvbqdrdkfgtuupqj.dll
    c:\windows\system32\ovfsthcshqrcojcrqrgimapeonolhaohxhilgt.dat
    c:\windows\system32\ovfsthibpnkhxcgtwipwkbbebcbairurlspwwq.dll
    c:\windows\system32\ovfsthkkmfxfmfwmagbplbsuwkuhjmvshppwrt.dat
    c:\windows\system32\ovfsthujcublovqmdhrnbypiqltnttynqfqedd.dl
    c:\windows\system32\drivers\ovfsthlqvpxmobirviuamvxwbywslhyvbtuijx.sys
    
    Registry::
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthyqvdkmpmyqlvfboscprrothxrjnvdrwu]
    "imagepath"=-
    
    Save this as CFScript.txt

    Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.

    [​IMG]

    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.

    Please download ATF Cleaner by Atribune.

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.
    For Technical Support, double-click the e-mail address located at the bottom of each menu.
     
  18. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Thank you kritius. Your assistance is greatly appreciated.
     
  19. tonight1000

    tonight1000 TS Rookie Topic Starter

    hi kritius,

    I have followed your instructions to reset the router. but when i reconnect my router, i can't seemed to be able to connect to internet. My laptop could still detect both the LAN and wifi signal from the router but just no internet. i have tried logging into the admin page of the router and reset the settings to default and it still doesn't connect to internet.

    Could it be something has gone wrong when i was carrying out the physical reset procedures of the router ?

    thanks.
     
  20. kritius

    kritius TS Guru Posts: 2,084

    Go to start > run and then type cmd in the command prompt window type ipconfig /all.

    copy and paste the information back here.
     
  21. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

  22. tonight1000

    tonight1000 TS Rookie Topic Starter

    hi there,

    i am attaching a snapshot of ipconfig. please kindly advise.
     

    Attached Files:

  23. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

    Can you try that again, except this time with the "/all" switch

    Start > Run > cmd /c ipconfig /all >Desktop\Ipconfig.log > ok
    (Note: you can just copy that bold part to a run command)

    Then attach the "Ipconfig.log" on your Desktop to a new reply
     
  24. tonight1000

    tonight1000 TS Rookie Topic Starter

    hi all,

    i have attached the revised ipconfig log file.

    Thanks for your time.
     
  25. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

    Can you go back into your Router (http://192.168.1.1) and confirm:
    1. That you can get in through the browser (it looks like yes)
    2. Your Username and Password is set up correctly
    3. Firewall is disabled (we will turn this back on, if it was enabled, once a test is made)
    4. Save Settings (please search for this) and exit your Router


    Then: Start > Run the following commands, pressing OK after each one: (just copy and paste the command)
    netsh int ip set address name = "Local Area Connection" source = dhcp
    netsh int ip set dns name = "Local Area Connection" source = dhcp
    netsh int ip set wins name = "Local Area Connection" source = dhcp

    Then restart your computer, and any other computer attached to the network
    Test to see if you have Internet connection whilst wired to the Roouter
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...