Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Viruss blocks all anti virus/malware programs


  • This topic is locked This topic is locked

#1
1mperator

1mperator

    New Member

  • Member
  • Pip
  • 2 posts

I already posted this thread over here, but I think this section is even better... sorry for the double post ... http://www.geekstogo...lware-programs/
I am redirected from Hackforums to this forum, because they were not able to help me out. I will try to give you guys an update as good as possible


Started with:
Does anyone have some advice to delete / clean a virus which blocks all virus scanners and malwarebytes? 

 

- Chamelon (version of Malwarebytes) does not work

- Malwarebytes does not work

- AVG 2013 does not work

 

Used an online scanner which used a loop to scan files which were not up to date / deleted.

 

Edit: scan online found "Win32/agent.rqd.gen trojan"


Windows security center:
Edit: Once I want to start, It says "couldn't start". 
Maybe a good detail: I did turn off the windows virus scanner earlier on because I do prefer AVG & Malwarebytes.
Edit2: Could it be because Im in safe modus?

I did run: Farbar Recovery Scan Tool
 

First it crashed, second as well. The program did make some files I just found out. 

Not sure if it's incomplete because of the crash.
 
FRST: 
 
Addition:
 
Gonna try that windows repair program
Edit: does not work. Same problem as other programs, crashes..

On these files I did get this advice:

 


1. Upload C:\Users\FRANK&~1\AppData\Local\Temp\mfe_rr.sys to http://virustotal.com and post the link here
2. Upload C:\Users\frank&jose\ghost.exe to http://virustotal.com and post the link here
3. Upload C:\Users\frank&jose\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WIKEWBEL\SwSaniNet_11 (1).exe to http://virustotal.com and post the link here
4. Remove the following service: COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
5. Disconnect from the internet, rename roguekiller.exe to something random (like 1328476safgwq.exe) and run it as administrator.
 
1.  Can 't find the file anymore , even when I am in the exact map and I do typ the exact name.
2. 0/56 detection rate (but I will still remove it).
3. Can't find this file as well, and I could only open the map while using the right mouse button (not with enter). 
4. I canonly find the dllhost.exe , not the processid. Scanned the dllhost.exe on virus total and it has a detection of 0/56.
 
I will do number 5. right now, will update when I do have more information
WHen I rename the file it does not show, when I open the map once again it does show the change.

all maps are visible, also the hidden and the system maps. 
 
Used roguekiller, changed the .exe name and still did not open.
Even without internet connection.
 
I hope you guys could help me out, Thanks for reading! 
 

 


  • 0

Advertisements


#2
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
Duplicate topic. This one will be closed.

Stick with the previous one, I am sure that somebody will pick up your thread soon.

Regards,
Naat
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP