Author Topic: i have a virus that gose by the name of ''antivirus securty pro''.  (Read 6460 times)

0 Members and 1 Guest are viewing this topic.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #15 on: December 10, 2013, 11:49:37 PM »
1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
C:\Program Files (x86)\Pando Networks
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF Extension: Browse For Change - C:\Users\Chase Maxwell\AppData\Roaming\Mozilla\Firefox\Profiles\uqy4fjls.default-1369017205415\Extensions\browseforchange@browseforchange.com
C:\Users\Chase Maxwell\AppData\Roaming\Mozilla\Firefox\Profiles\uqy4fjls.default-1369017205415\Extensions\browseforchange@browseforchange.com
FF HKCU\...\Firefox\Extensions: [module@com.arcadesafari.firefox] - C:\Users\Chase Maxwell\AppData\Local\Arcadesafari\module@com.arcadesafari.firefox
FF Extension: Arcadesafari - C:\Users\Chase Maxwell\AppData\Local\Arcadesafari\module@com.arcadesafari.firefox
C:\Users\Chase Maxwell\AppData\Local\Arcadesafari\module@com.arcadesafari.firefox
CHR DefaultSearchKeyword: feed.helperbar.com
CHR DefaultSearchURL: http://feed.helperbar.com/?publisher={Publisher}&dpid={DownloadProvider}&co={CountryTwoLettersISO}&userid={InstallationHashID}&affid={affid}&searchtype=ds&babsrc=lnkry&q={searchTerms}&installDate={installDate}
C:\Users\Chase Maxwell\AppData\Local\Google\Desktop\Install
cmd: netsh winsock reset
cmd: ipconfig /flushdns

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

chase21

  • Guest
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #16 on: December 12, 2013, 12:00:17 AM »
Alright, I ran it from the desktop and it looks like everything worked out well. The fixlog is posted below.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #17 on: December 12, 2013, 10:26:53 AM »
Good, one final check:


Please download AdwCleaner by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
  • Click on the Scan button.
  • After the scan has finished click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Post logfile will also be saved in the C:\AdwCleaner folder.
Then...



Re-run FRST, press Scan and attach fresh report.



Then...



Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

chase21

  • Guest
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #18 on: December 12, 2013, 09:52:15 PM »
Alright, I ran the programs and have attached the logs below. I was unsure if I needed to add the other adwcleaner file, but I still can if you need it.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #19 on: December 12, 2013, 10:23:44 PM »
Please download ESET Services Repair tool, available here,  and save it to your Desktop. Right click on it and select Run As Administrator, follow the prompts. It should reboot when it finishes. If not reboot it yourself.
http://kb.eset.com/library/ESET/KB%20Team%20Only/Malware/ServicesRepair.exe
Post here fresh created logreports.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

chase21

  • Guest
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #20 on: December 12, 2013, 11:55:51 PM »
I believe I have the right log report posted below.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #21 on: December 12, 2013, 11:59:04 PM »
OK, system is now clean, tell me how are the things now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

chase21

  • Guest
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #22 on: December 14, 2013, 03:21:48 AM »
It's running better then it has in months. It even allows me to run a couple of games that were shutting down my pc. Dosen't seem to have the sluggish problem and overheating, thanks to too many programs running. Thank you!

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #23 on: December 14, 2013, 09:21:57 AM »
Good, then we're done here :)


Uninstall Adobe Reader and all Java versions from Control Panel, and download the latest versions. Keep all of your software updated.


Please download DelFix by "Xplode" to your Desktop.

Run the tool and check the following boxes below;
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

chase21

  • Guest
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #24 on: December 14, 2013, 11:15:12 PM »
Actually, I got on today and something is off. Everything looks pixelated and blown up about 3 times it's size. I went to use the program you suggested and it, and the browser just closed it self. I'm not sure what the problem is. it was running great yesterday, but now this.

chase21

  • Guest
Re: i have a virus that gose by the name of ''antivirus securty pro''.
« Reply #25 on: December 14, 2013, 11:25:14 PM »
Wait, I might have fixed it. It was the resolution, for some reason it was on the lowest setting.