Results 1 to 15 of 15

Thread: rouge antivirus?

  1. #1
    Join Date
    Jun 2006
    Location
    Falls Shity Oregon
    Posts
    585
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default rouge antivirus?

    i'm not sure how it got in but a Rouge AntiVirus named WinAntivirus2007 got into my system. and AdAware20007, Windows Defender, and Trend Micro PC Cillin were unable to even detect anything, PC Cillin doesnt work in safe mode and AdAware2007 didnt detect anything, i was told to get a hijack this log of my computer and i have tht and i was wondering if i should post it here?

  2. #2
    Join Date
    Jul 2005
    Posts
    17,038
    Thanks
    1
    Thanked 333 Times in 106 Posts
    EP Points
    890

    Default

    Go ahead, attach it.

  3. #3
    Join Date
    Jun 2006
    Location
    Falls Shity Oregon
    Posts
    585
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    (ten letters)
    Attached Files Attached Files

  4. #4
    Join Date
    Jul 2005
    Posts
    17,038
    Thanks
    1
    Thanked 333 Times in 106 Posts
    EP Points
    890

    Default

    Check and fix:
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\ugelpoxi.exe (file missing)


    Other than that, I see nothing special or that I don't like seeing.

    Get a screenshot of the pop up you get.



    EDIT:
    Quick google search yielded this:

    Malware Mike Worthington -- 22/07/06

    If malware authors are indeed so very very clever, how can we be sure that some of them are not posing as antivirus or antimalware providers?

    1.
    Rouge antivirus Anonymous -- 15/08/06

    Oh yes, they do so, they make programs that acts like a real antivirus or antipyware product. That's called rouge antivirus or rouge antispyware tools. Those will trick the user to pay some money by saying that the computer is infected or is in danger and if they would like to remove buy the upgrade blah blah blah. Some of them even displays a yellow bubble (as an urgent notofication in the same way as Microsoft displays when the firewall is not turned on or when a new update is available) so that it says that there is an infection on the computer and to remove click here. When you so you go to their website and you have to use your credit card to get rid of that message to keep popping up...
    Last edited by Evans; 19th-August-2007 at 02:51.

  5. #5
    Join Date
    Sep 2005
    Posts
    656
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    windows defender sucks IMO.

    also did you try just merely uninstalling it like you would any other program?

  6. #6
    Join Date
    Jun 2006
    Location
    Falls Shity Oregon
    Posts
    585
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    ok i tried the fix you just gave me if it keeps continueing i'll send pictures of hte popups i'm geting

  7. #7
    Join Date
    Jun 2006
    Location
    Falls Shity Oregon
    Posts
    585
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    when i try to go to the hijack this site, this kind of popup comes up, it doenst come up maximized or anyhting it pops up sized to the window that you were working in. as to completely cover the window you were working in.


    the other popup cmae up soon as i clicked uplaod for hte images
    Attached Images Attached Images

  8. #8
    Join Date
    Jul 2005
    Posts
    17,038
    Thanks
    1
    Thanked 333 Times in 106 Posts
    EP Points
    890

    Default

    Look, Corey told you to use different antivirus programs. Trash the ones you use now and try new ones. Kaspersky is free. Use it.

  9. #9
    Join Date
    Dec 2005
    Posts
    2,955
    Thanks
    3
    Thanked 23 Times in 22 Posts
    EP Points
    65

    Default

    Quote Originally Posted by Evans View Post
    Look, Corey told you to use different antivirus programs. Trash the ones you use now and try new ones. Kaspersky is free. Use it.
    I did?

  10. #10
    Join Date
    Jun 2006
    Location
    Falls Shity Oregon
    Posts
    585
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Kaspersky is not free and no corey did not say what you said he did

  11. #11
    Join Date
    Jul 2007
    Posts
    62
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    i use avg free and spy bot both free

  12. #12
    Join Date
    Oct 2003
    Location
    Inside of a Final Fantasy NES cartridge...
    Posts
    8,156
    Thanks
    0
    Thanked 18 Times in 8 Posts
    EP Points
    15

    Default

    Use FireFox or some other alternate browser instead of IE.
    That way you can get to the Hijack this site.

    I also recommend AVG free edition for anti-virus:
    http://free.grisoft.com/

    Although you already have Trend-Micro which isn't bad either, I guess.

    I see you have Lavasoft AdAware, but not Spybot S&D.

    Get it and scan your computer with both of them
    http://www.safer-networking.org/

    Make sure to fully update them both for you scan.

  13. #13
    Join Date
    Jan 2007
    Posts
    1,156
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    You need to use this program

    Download Links:
    Links are hidden from guests. Please register to be able to view these links.

  14. #14
    Join Date
    Jan 2005
    Location
    Vault 13
    Posts
    7,016
    Thanks
    1
    Thanked 37 Times in 15 Posts
    EP Points
    35

    Default

    Quote Originally Posted by Omega H4x View Post
    i'm not sure how it got in but a Rouge AntiVirus named WinAntivirus2007
    lol that thing sucks doesn't it? Maximum PC did an article about it as well, they contacted the company and they (the company) said there was no way the program would inject self installing apps onto people's computers and nag them to buy it. lol rite. Ok anyways:

    Use this tool - http://secured2k.home.comcast.net/to...undoBeGone.exe

    Maca's tool should work as well. This will remove all the adware/spyware, but not the program itself. Now go to add/Remove programs in the control panel, and remove WinAntiVirus manually. Then get a copy of ewido, know known as AVG anti-spyware, install/update/run.

    It should be completely now, if not then this post can help you more:

    http://www.bleepingcomputer.com/foru...10&hl=Winfixer

  15. #15
    Join Date
    Jun 2006
    Location
    Falls Shity Oregon
    Posts
    585
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    thank you all, this worked my compuiter is now completly clean, altho i had to delete my system restore because AdAware did a backup of the system wile the malicious softwre was still installed so then Windows was protecting bakcup copys of the bad software a tutorial on how to deal with stuff like this should be stickied.

Similar Threads

  1. Rouge Squadron problems
    By taintedcereal in forum Everything Emulation
    Replies: 1
    Last Post: 15th-June-2005, 11:00
  2. Replies: 21
    Last Post: 13th-August-2004, 04:15
  3. Antivirus
    By Foxhound in forum Computer Corner
    Replies: 8
    Last Post: 28th-January-2004, 21:48
  4. Need Advice on Antivirus Software and Firewall
    By Nightfall Z in forum Computer Corner
    Replies: 4
    Last Post: 11th-October-2003, 15:27
  5. Rouge spear
    By obsidian in forum Free 4 All
    Replies: 3
    Last Post: 9th-January-2002, 04:56

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
About Us

We are the oldest retro gaming forum on the internet. The goal of our community is the complete preservation of all retro video games. Started in 2001 as EmuParadise Forums, our community has grown over the past 18 years into one of the biggest gaming platforms on the internet.

Social