Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Varkas
Apr 16, 2003

If I post before 5pm PST, PM my boss and tell him I'm fired.
Has anyone gotten a virus that seems to block internet connections to specific known anti-virus/anti-spyware sites, and also seems to inhibit such installed programs from actually running?

I started noticing pop-ups this morning, so I ran AVG and picked up some stuff, rebooted. I wanted to follow up with Spybot, but now nothing happens when I try to start it up. If I go out and search for it on google, I seem to get redirected to bogus crap now. While I keep my important install executables on hand, reinstalling doesn't seem to help.

AVG still seems to be able to scan and pick up threats, but it's not able to connect for updates suddenly.

Edit - I'm going to try some of the other tools mentioned. Thankfully I've got my laptop and a thumb drive to get the apps over. Only concern though might be getting the updates.

Varkas fucked around with this message at 20:28 on Dec 20, 2008

Adbot
ADBOT LOVES YOU

Varkas
Apr 16, 2003

If I post before 5pm PST, PM my boss and tell him I'm fired.

Otacon posted:

Sounds like a rootkit, to be honest. The ones I've dealt with in the past wouldn't let me load up any cleaners, and changed some entries in HOSTS that redirected me to other sites when I tried to download fresh copies. I haven't tried it, but give that GMER a try, or RootkitRevealer, see what pops up.

Thanks for the help guys. I used Avira AntiVir(which interestingly enough wasn't targeted by the rootkit), GMER, and ComboFix primarily to clean everything up. Everything seems to be back to working order now.

  • Locked thread