SysChat is a free online computer support community. Ask questions, share resources, contribute knowledge and discuss technology. Join our growing community to access all features. Register Now!

SysChat » Software Support » Computer Security » Help to rid contra virus

Computer Security

Discuss Computer Security- Viruses, Adware, Spyware, etc...

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 06-01-2007, 01:36 AM
gerraldr gerraldr is offline
Junior Member
 
About:
Join Date: Jun 2007
Posts: 2
gerraldr is on a distinguished road

trouble Help to rid contra virus


Help, I am trying to rid my friends comp of some very evil malware know as "contra virus" also called "AddProtect" .
I have used "spybot search and destroy" and then "SuperantiSpyware" and the cursed thing just comes right back from the dead! This is on a xp home machine. Any luck out there getting fully rid of it?




Last edited by sysadmin; 06-01-2007 at 02:34 AM..
Reply With Quote
  #2 (permalink)  
Old 06-01-2007, 02:36 AM
mhookem's Avatar
mhookem mhookem is offline
Moderator
 
About:
Join Date: Dec 2006
Location: Chesterfield, UK
Posts: 387
mhookem will become famous soon enoughmhookem will become famous soon enough

Default


Hello gerraldr, can you give me a few more details about what the virus is doing, where you found it and any details your removal software is giving you.

Martin



Reply With Quote
  #3 (permalink)  
Old 06-01-2007, 05:20 AM
gerraldr gerraldr is offline
Junior Member
 
About:
Join Date: Jun 2007
Posts: 2
gerraldr is on a distinguished road

Default


Hello Martin,
The computer infected is a 9 month old Dell with windows xp. I am not sure what my friend was up to but he did admit to being on "the bad side of town" surfing the other night. He was surfing with firefox. To quote from "ContraVirus is a fake anti-spyware program that is often downloaded and installed without user knowledge or consent by a Trojan or through browser security holes. ContraVirus launches on Windows startup and may generate large numbers of popup adverts. ContraVirus will also display notifications of imaginary security risks in its attempts to get the user to purchase the full version. ContraVirus program can be extremely difficult to remove manually, and will continue to try to recreate itself. ContraVirus is thought to be related to VirusBlaster" This quote is quite accurate except that they could have added that it is hard to completely remove with spyware! Some small part of the cursed thing remains after even the most thorough cleaning, so that it can re-install itself on rebooting.
thanks, GR.



Reply With Quote
  #4 (permalink)  
Old 06-01-2007, 01:12 PM
mhookem's Avatar
mhookem mhookem is offline
Moderator
 
About:
Join Date: Dec 2006
Location: Chesterfield, UK
Posts: 387
mhookem will become famous soon enoughmhookem will become famous soon enough

Default


Hello, can you give me any other details your anti-spyware is giving you, like the location of the virus?
Also, any other filenames e.g. C:\Windows\System32\vcehaeb.dll

I got one myself about a year ago, that one was called 'VirusBurst'! It sounds like the same one.

Martin



Reply With Quote
  #5 (permalink)  
Old 06-06-2007, 02:25 PM
Karrie Karrie is offline
Junior Member
 
About:
Join Date: Jun 2007
Posts: 1
Karrie is on a distinguished road

Default I had the problem, too.


My computer just recently had that same problem, and I tried the same techniques you used. Then, my AVG anti-virus program got an update and said that there was a problem on my computer. I healed it and haven't had any problems since. However, at startup, a popup message now appears from contra virus saying "File config.ini doesn't exist. Please reinstall software." If your friend's computer doesn't have AVG, download the free version (that's what I have), and it should help.



Reply With Quote
  #6 (permalink)  
Old 06-11-2007, 01:20 PM
kathijj kathijj is offline
Junior Member
 
About:
Join Date: Jun 2007
Posts: 3
kathijj is on a distinguished road

Default contravirus


Hi,
I also had a contra virus infection.
It took me numerous tries to clean the thing from my system.

I used the search function to find this file and contravirus files. I had to go through this process numerous times before I got them all. It took me all day to get rid of this thing. The combination of this and the 411 spyware product finally got my computer clean again.




Last edited by Sami; 06-12-2007 at 11:37 AM.. Reason: to remove link
Reply With Quote
  #7 (permalink)  
Old 06-12-2007, 06:22 AM
kathijj kathijj is offline
Junior Member
 
About:
Join Date: Jun 2007
Posts: 3
kathijj is on a distinguished road

Default


Hi ,
I just did a bit more research and found that the software from the 411 site is a form of spyware.
My research lead me to download "Spybot - Search & Destroy" which found numerous other infections on my computer. This is a free program.
I ran this and cleaned up my computer and the difference is just remarkable.
My previous instructions did get rid of the contravirus (and unfortunately also installed additional sypware) but the computer was still running too slow for my liking. Hope this helps you.



Reply With Quote
  #8 (permalink)  
Old 06-12-2007, 06:36 AM
kathijj kathijj is offline
Junior Member
 
About:
Join Date: Jun 2007
Posts: 3
kathijj is on a distinguished road

Default


Check the listing on the following site of things that need cleaning
ContraVirus - from Wiki-Security, the free encyclopedia of computer security
Also check for the "XPuudate" process and files. On the 411 site there is also a mention of some other file names this uses.
After you clean your computer from "contravirus and xpuudate" run a search for both of these using the search files. (also search hidden files) These programs lodge themselves everywhere including in the backup.
Then clean the computer again using Spybot S&D



Reply With Quote
Reply





Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus, Worms and Torjan Horses: The difference among the three paula_cute Security 0 05-24-2007 02:54 AM
Anti Virus Help bopjazz General Tech Support 1 06-16-2006 12:52 PM
How Hackers and Virus Writers Attack E-mail Systems Sami News 0 03-14-2006 03:26 AM
First real virus for the Mac OS X discovered Sami News 0 02-16-2006 02:59 PM
Windows virus scheduled to delete files on infected computers February 3rd Sami Computer Security 2 02-02-2006 02:33 PM

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are on



» Ads



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54