Author Topic: Somebody help!! (please!)  (Read 4206 times)

0 Members and 1 Guest are viewing this topic.

deezgnutz

  • Guest
Somebody help!! (please!)
« on: February 27, 2010, 04:32:13 AM »
Im not sure what to do I have tried to do different things I have seen on here and other places and nothing seems to work... hopefully someone can help me.  My avast found a virus about a week ago ( JS:Prontexi-N[Trj] .. It says it was successfully moved to chest but i am still having problems.  If i go to maintenance and then the virus chest.. I dont see the JS:Prontexi there but there is another one that I dont really remember seeing it be detected.  This file says kav3[1].htm  and the file is temporary internet file\content.IE5\Z4PBVYPA.. I am unable to update ad-aware or malware ( i dont think any of them are able to update).. I have tried uninstalling and reinstalling malware and it didnt work..  And when i search for something especially on google when i click a link it will redirect me to a completely different website... I can click back and it will go back to google in the browser then usually redirect to the site i actually clicked on.. Sooooo i dont know what what to do.. any ideas..?!

deezgnutz

  • Guest
Re: Somebody help!! (please!)
« Reply #1 on: February 27, 2010, 04:36:25 AM »
Oh also Avast no longer detects any virus when I run a virus scan

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: Somebody help!! (please!)
« Reply #2 on: February 27, 2010, 04:44:11 AM »
The malware name by all accounts isn't displayed in the chest when the file is sent there, right click on the file you mentioned, kav3[1].htm and select scan, that I'm sure will be the file detected as JS:Prontexi-N[Trj].

The JS:Prontexi-N[Trj] is most likely to have been in you browser cache files as this is the JS (javascript) bit probably inside the .htm file.

I doubt this has anything to do with your problem updating adaware. Personally I wouldn't wast hard disk space on adaware, much less update it. So I believe there is something else on your system either hidden or undetected.

What program do you mean when you say "I have tried uninstalling and reinstalling malware and it didnt work." MalwareBytes AntiMalware perhaps ?

When you moved the file to the chest, I wouldn't have expected avast to detect it any more.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

deezgnutz

  • Guest
Re: Somebody help!! (please!)
« Reply #3 on: February 27, 2010, 04:51:37 AM »
It was Malwarebytes..  I dont really care about not being able to update Ad-aware.. I just want whatever is happening to be fixed.. Malwarebytes is unable to be updated as well..  The part where it redirects me to other webpages is the part that is annoying and im trying to find a solution for.  You are right about the JS:Prontexi that is the kav3 file when I scan it as you said above
« Last Edit: February 27, 2010, 04:53:44 AM by deezgnutz »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: Somebody help!! (please!)
« Reply #4 on: February 27, 2010, 05:48:24 PM »
What errors are you getting when trying to update MBAM ?
You could try downloading the latest version of MBAM from a different location, which you could try installing from safe mode. http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe][url]http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe[/url]

Are you able to update avast ?
As it could be that whatever it is could be blocking security sites. HOSTS file redirect a common malware tactic to block AV sites making it difficult to remove malware - 127.0.0.1 check your HOSTS file using notepad or a text editor of your choice, C:\WINDOWS\system32\drivers\etc\hosts or do a search for HOSTS to find it if not there.
 
Once open you are looking for entries with security based sites on the line, post the contents of the hosts file. http://en.wikipedia.org/wiki/Hosts_file
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Somebody help!! (please!)
« Reply #5 on: February 27, 2010, 05:55:44 PM »
Explanation of common Malwarebytes’ Anti-Malware error codes
http://forums.malwarebytes.org/index.php?s=&showtopic=10138&view=findpost&p=162096

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Somebody help!! (please!)
« Reply #6 on: February 27, 2010, 06:03:55 PM »
Hi there I have two programmes for you to download and run :

FIRST

Download TDSSKiller and save it to your Desktop.

  • Extract the file and run it.
  • Once completed it will create a log in your C:\ drive
  • Please post the contents of that log

THEN

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS  to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • Reg - Shell Spawning
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
    • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav


    • Now click the Run Scan button on the toolbar.
    • Let it run unhindered until it finishes.
    • When the scan is complete Notepad will open with the report file loaded in it.
    • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
    Please attach the log in your next post.

    To attach a file, do the following:
    • Click Add Reply
    • Under the reply panel is  Additional Options click this
    • Browse for the attachment file you want to upload