Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash desktop dns driver drivers error ethernet excel freeze gaming graphics hard drive hardware hdmi internet laptop malware memory monitor motherboard network printer problem ram registry repair router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
Solved: Who's up for a challenge?

Reply  
Thread Tools
pimentointhesky's Avatar
Junior Member with 22 posts.
 
Join Date: Nov 2009
15-Nov-2009, 07:09 PM #1
Who's up for a challenge?
Okay, so there is one specific website that will not work for me: www.ninjavideo.net. I have probably gotten all errors possible from it and tried everything humanly possible to remedy this. I really need help! Here are the basic issues:
For a while, when I accessed the website, it would either:
-Redirect me to an unwanted page (porn, ad sites, etc.)
or
-Say it was loading for a really long time and then say "Done" in the left bottom corner when all it was showing me was a blank white page.

I then posted to this website on this forum and tried every remedy offered:
http://forums.techguy.org/web-email/...te-issues.html

After none of that worked, I got frustrated and Googled like hell. Somewhere it said that it could be a result of my antivirus, so I immediately uninstalled my trial version of avast! I was then able to access the website. Yay! I watched an episode of Glee and then the following happened:
I tried to click on a link to another TV show and was either
-Given a '404 not found' error
or
-Told that the connection was interrupted.

I then went and Googled those issues extensively and tried everything that was suggested (within what I could understand because I'm probably at the "Computers for Dummies" level).

I don't know what caused it, but I was able to watch another episode. Then, as soon as I was done watching it and went to click another link, I got 404s and "connection interrupted"s again. I decided the leave the site alone for awhile.

I tried again today and was re-directed to an ad website. Back to the drawing board!

Please help, this is more annoying than any other technology issue I've ever dealt with.

Thanks!
pimentointhesky's Avatar
Junior Member with 22 posts.
 
Join Date: Nov 2009
17-Nov-2009, 12:35 AM #2
updates.
I just got it to work again like an hour ago after installing AVG and wiping out all my bad cookies and such. Maybe that helped? Either way it worked for like an hour and then when I tried to open another video it kept loading and then spazzing... Like in the bottom left-hand corner where it says "Loading such and such" it was like "Loading, Waiting, Stopped" but over and over again really fast and ultimately nothing would happen on the page.

So I still need help! Please reply!
dotty999's Avatar
Computer Specs
Distinguished Member with 131,278 posts.
 
Join Date: Feb 2006
Location: UK
Experience: I'm learning all the time
17-Nov-2009, 12:44 AM #3
AVG isn't as reliable as Avast, rather than the trial version, you'd be better just using the free version, it's far more accurate than AVG.
I take it you've done malware scans? Malwarebytes is one of the best if you haven't already tried it, you should also run a virus scan, there are several online scans to choose from if you don't want to use Avast, I'd still recommend getting rid of AVG though
__________________
Always chase your dreams instead of running from your fears.
We make a living by what we get, but we make a life by what we give.
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
17-Nov-2009, 12:47 AM #4
Do you recognize these IP addresses?

O17 - HKLM\System\CCS\Services\Tcpip\..\{C966F92B-F884-40CE-8096-7E5FAFC26918}: NameServer = 85.255.112.211,85.255.112.149
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2BCF821-38A1-4B93-8A08-CC25C122FAC5}: NameServer = 85.255.112.211,85.255.112.149
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.211,85.255.112.149
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.211,85.255.112.149
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.211,85.255.112.149


Are you familiar with RIPE Network Coordination Centre?
__________________

• Our help is free 'cause we like what we do, so at least, please reply in a timely manner... Thank you.
• If we've solved your problem, please click on Mark Solved in the upper left corner of your thread.
How to Mark Your Own Thread as "Solved".
pimentointhesky's Avatar
Junior Member with 22 posts.
 
Join Date: Nov 2009
17-Nov-2009, 10:15 PM #5
ack...
Sorry, but I don't really know how to check whether or not I recognize those IPs or not? And no I'm not familiar with RIPE.

Sorry, I'm not hopeless, I promise, I've just never worked with IPs before.
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
17-Nov-2009, 10:24 PM #6
I don't trust those 017 entries as the IP addresses point to RIPE in Amsterdam. This could have been added by malware to redirect you to another server.

I would click on the Report button and kindly ask for a malware removal expert's advice.
pimentointhesky's Avatar
Junior Member with 22 posts.
 
Join Date: Nov 2009
22-Nov-2009, 04:25 PM #7
it says that that function isn't supposed to be used for help with technical issues. i did it anyway, but that probably hinders my chances of getting a response.
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,223 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
22-Nov-2009, 05:03 PM #8
Download to Desktop: DDS by sUBs from one of these locations:

http://download.bleepingcomputer.com/sUBs/dds.com
http://download.bleepingcomputer.com/sUBs/dds.scr
http://www.forospyware.com/sUBs/dds

double click DDS.scr to run

When complete, DDS.txt will open.

Click Yes for Optional Scan.
Save both reports to your desktop.
DDS.txt
Attach.txt

Attach the contents of both logs back here.

=====
GMER:
=====

Download GMER Rootkit Scanner from here or here.

Ensure you have uninstalled any CD Emulation programs before you run GMER as outlined here
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe.
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..


    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save it where you can easily find it, such as your desktop

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
pimentointhesky's Avatar
Junior Member with 22 posts.
 
Join Date: Nov 2009
22-Nov-2009, 06:02 PM #9
Whenever I open DDS, the window shows up for like 5 seconds and then closes itself.
pimentointhesky's Avatar
Junior Member with 22 posts.
 
Join Date: Nov 2009
22-Nov-2009, 06:29 PM #10
I did the rootkit thing though.
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,223 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
22-Nov-2009, 06:38 PM #11
post the rootkit report then
pimentointhesky's Avatar
Junior Member with 22 posts.
 
Join Date: Nov 2009
22-Nov-2009, 07:20 PM #12
Whenever I try to save my results, it says it is saved successfully. I then look for it on my Desktop (where I saved it) and it is not there. I then click the Windows icon and search the file name and it does not come up. What is wrong with my computer?
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,223 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
23-Nov-2009, 03:19 AM #13
without logs I can't do much but try this


Please download Malwarebytes' Anti-Malware to your desktop
from HERE or HERE

Double-click mbam-setup.exe and follow the prompts to install the program. At the end, be sure a checkmark is placed next to the following:

Update Malwarebytes' Anti-Malware. Launch Malwarebytes' Anti-Malware. Then click Finish.

If an update is found, it will download and install the latest version. Press Update to make sure the latest database is loaded.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad.
Please include this log in your next reply.

It might ask you to reboot to finish cleaning. Please do so. ( Press YES on the alert)
If you receive an (Error Loading xxxxxxxxxx .dll) error on reboot please reboot a second time . It is normal for this error to occur once and does not need to be reported unless it continues on every boot
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
pimentointhesky's Avatar
Junior Member with 22 posts.
 
Join Date: Nov 2009
23-Nov-2009, 04:46 PM #14
Yay! This one worked!

Quote:
Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 6.0.6001 Service Pack 1

11/23/2009 3:45:04 PM
mbam-log-2009-11-23 (15-45-04).txt

Scan type: Quick Scan
Objects scanned: 94443
Time elapsed: 8 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 9
Folders Infected: 3
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\gxvxc (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Conv ert2Play (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gxvxcserv.sys (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameS erver (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Inter faces\{c966f92b-f884-40ce-8096-7e5fafc26918}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Inter faces\{e2bcf821-38a1-4b93-8a08-cc25c122fac5}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServe r (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interface s\{c966f92b-f884-40ce-8096-7e5fafc26918}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interface s\{e2bcf821-38a1-4b93-8a08-cc25c122fac5}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServe r (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interface s\{c966f92b-f884-40ce-8096-7e5fafc26918}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interface s\{e2bcf821-38a1-4b93-8a08-cc25c122fac5}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.211,85.255.112.149 -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Convert2Play (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Users\Lena (is awesome)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convert2Play (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Users\Lena (is awesome)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\totalvid (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Convert2Play\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Windows\System32\gxvxccounter (Trojan.DNSChanger) -> Quarantined and deleted successfully.
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,223 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
24-Nov-2009, 07:48 AM #15
now try dds & gmer so we can see what else is there
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 08:03 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.