Results 1 to 11 of 11
  1. #1
    E. Body
    Join Date
    Jul 2004
    Posts
    2,025
    BG Level
    7

    Virus/Worm is owning my computer

    So a couple days ago i got a trojan or a worm or something that was hijacking all my browsers prohibiting me from getting online. Anyone that I would open, the browser background would turn red and a message would pop up trying to sell my some bs antivirus, typical shit. So i ran two very long scans, one with malwarebytes and another, more successful one with emisoft, which found more items including a worm called worm.win32.VBNA!IK. I was able to remove the stuff so the browsers are no longer getting hijacked, but I can no longer get online with any of them despite being fully connected to my wireless network. What is going on? Any ideas?

  2. #2
    E. Body
    Join Date
    Jul 2004
    Posts
    2,025
    BG Level
    7

    And oddly, I can get AIM and stuff just no internet browser...

  3. #3
    Unique and/or Creative Phrase
    Join Date
    Aug 2006
    Posts
    1,432
    BG Level
    6
    FFXI Server
    Shiva

    Try deleting your browser and reinstalling it. Sounds like the virus deleted a part of it.

  4. #4
    F5 Like A Boss.
    Join Date
    Sep 2005
    Posts
    7,396
    BG Level
    8
    FFXIV Character
    Kuroki Kaze
    FFXIV Server
    Sargatanas
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Twisting Nether

    Also, it may be possible that you have a rootkit preventing you from using the browser. Use Safe Mode w/o Networking to run your scans.

    What Anti-Virus are you using? Try to get Kapersky if you can.

  5. #5
    The Dazzler
    Join Date
    Feb 2006
    Posts
    1,429
    BG Level
    6

    I'd also check your hosts file at C:\Windows\System32\drivers\etc and make sure there's nothing in there without a # at the start of the line

  6. #6
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    Hosts file is possible but I'd bank on it trying to use a blank proxy or something, check the proxy settings within IE/Firefox and turn them off if something's in there.

  7. #7
    Old Merits
    Join Date
    Nov 2007
    Posts
    1,002
    BG Level
    6
    FFXI Server
    Asura

    Sounds like a flavor of that Super Antispyware thing that people bring in to work now and then to get removed. I have to be able to load our web site to install the tools to remove it since they don't allow us to use USB flash drives or burned CDs to store our files, as they might spread something between the machines, and "don't look professional in a retail environment". I've been unable to get past it with those limitations the past two times I have seen it without heavy use of regedit to remove all references to it.

    One of the things it did was to link major search and antivirus sites to 127.0.0.1 in the registry and hosts file, which loops them back to your computer instead of their normal sites.

    My best recommendation would be, if you have another computer, to remove the drive from the infected one, attach it as a secondary or external drive to one that is up to date with a good antivirus, and scan it on the uninfected machine. Manually trying to remove it from the infected machine while booted to the infected OS is a pain.

  8. #8
    A. Body
    Join Date
    Nov 2005
    Posts
    4,315
    BG Level
    7
    FFXI Server
    Leviathan

    Go into device manager, delete your network device(s) and then have them get redetected/reinstalled (right click the root computer object and hit detect hardware). I've seen that fix similar problems. I think the basic issue is that the malware futzes with the settings, and by reinstalling the device you reset it all to defaults.

  9. #9
    Member since 2006 and still can't think of a title.
    Join Date
    Oct 2006
    Posts
    28,135
    BG Level
    10
    FFXIV Character
    Acanis Lindri
    FFXIV Server
    Midgardsormr
    FFXI Server
    Bismarck
    WoW Realm
    Kil'jaeden

    Make sure work offline is not checked in your browser. We've had a couple at work with that virus and somehow as a last fuck you checked tha box.

  10. #10
    :3
    Join Date
    Nov 2006
    Posts
    653
    BG Level
    5

    backup and reformat :D

  11. #11
    Relic Weapons
    Join Date
    Jun 2006
    Posts
    321
    BG Level
    4
    FFXI Server
    Leviathan

    Try this. Whatever your browser is, go to Options > Network > Proxy/LAN Settings. Uncheck any Proxy Server settings which most viruses w/ redirects do to redirect you to their sites so once they're gone your browser's still setup to connect to them. As soon as you're done, should be able to browse the web even w/o restarting your browser.

    Merry Christmas.

Similar Threads

  1. Replies: 22
    Last Post: 2008-12-06, 22:22
  2. Is my computer running to hot?
    By Donsalieri in forum Tech
    Replies: 2
    Last Post: 2008-01-05, 21:43