Off-topic MT4/mql4 questions. - page 32

 

It's better to replace the whole thing. Don't skimp on the main thing.

 

Hi all!

Just thought I'd check my computer early this morning with the so called "free" Kaspersky utility. Kaspersky's "free" utility. Went and downloaded it from native site (from native Kaspersky site).

I ran it and checked all the boxes I had checked. Instead of free scan I get what I have got:

I mashingly somehow entered my number (Megafon) and got an SMS - where I was offered to confirm request for code "back" - word YES. I sent "YES", but of course I didn't get any fucking code. Moreover - in the window there was a countdown for 30 seconds - during which I must enter the allegedly received code.

I wanted to repeat the procedure. But I looked at the balance of my account just in case. It turned out that Megaphone charged me 117 rubles for the callback!

Like this .... No money, no free virus scan....

Looks like a scam by MegaFon and Kaspersky - another scam?

 
leonid553:

Hi all!

Just thought I'd check my computer early this morning with the so called "free" Kaspersky utility. Kaspersky's "free" utility. Went in, downloaded from native site (from native Kaspersky site).


Try ESET's free online scanner. Tested - completely free.
 
leonid553:

Hi all!

Just thought I'd check my computer early this morning with the so called "free" Kaspersky utility. Kaspersky's "free" utility. Went and downloaded it from native site (from native Kaspersky site).

I ran it and checked all the boxes I had checked. Instead of free scan I get what I get:

Kaspersky doesn't do that... :-))) I've been using it since 98...

Either your computer is infested with link hijacker (i.e. native site, but all download links are substituted on the fly...),

or the Trojan intercepts the license agreement request from the native distribution...

Here's a direct link to the program - http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/avptool11/setup_11.0.1.1245.x01_2013_08_24_08_30.exe (check yours)

Just tried it - works like clockwork... :-)))

 

Thank you all for your feedback.

I actually have the following problem. The "big" computer is blocking browser access (Opera, IE, Musilla) to anti-virus sites. And the loading of some other addresses slows down.

I downloaded Dr.Web at first but it found nothing. In general, it's been some kind of "useless" since they neutered it about two or three months ago. I've wasted so much time on it a couple of times already.

Maybe there is some special utility for this particular virus, so that I don't have to spend hours on general anti-virus scanning?

(host file - checked, normal)

 
leonid553:
Scroll through a few pagesfrom here.
 

Silent, thank you! I'd forgotten all about these pages, although I was here myself in 2010 - when Rita was performing the techniques described by Abzatz!

In the morning, nevertheless, I started Kaspersky's utility, and several hours later it found several viruses. But apparently not the ones that blocked the antivirus sites. Sites still wouldn't open!

I started to repeat steps I described on page 4. I repeat all my actions, maybe someone can help:

1. Ctrl+R Regedit
Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\PersistentRoutes -
found the same virus file as at Rita.

2. type Win +R
there cmd
there route -f
Enter
reboot - may be required
- yes had to reboot because internet was lost.

3. Then - this is what you try to do
"Open a command prompt. Press Start and select Run and write there cmd and press Enter. In the window that appears, write:
ping ftp.drweb.com
This will most likely say that the host could not be found.
= Yes, a message appears saying that the nodes are unavailable.

Here, at this point in time, Rita's sites started to open. But furthermore, unlike those events - I still had no antivirus sites open.

4. Press Start and select Run and type cmd and press Enter. In the window that appears write
nslookup ftp.drweb.com
A table will appear
Unofficial answer:
Name: rr.drweb.com
Addresses: there will be a bunch of IP addresses written in commas: 81.176.67.171, 81.176.67.173, etc.
We will type one of these addresses into a web browser: Internet Explorer, Opera, Mazilla, etc.
FTP files will appear.

This fourth method did not work. None of the multiple IP addresses would open in the browsers. A virus wouldn't let it, I guess. And I - finally - invoked the last recommendation from Abzatz:

5.Check what else
Win+R
msconfig
Autoloader
tab - and there in Autoloader window some file (with strange name) was found, which was not visible in task manager! It seemed to be the virus I was looking for.


I unchecked it and rebooted the computer! After that, everything worked fine! Antivirus sites are loaded!

But the virus must be still sitting somewhere, waiting! And Dr.Web and Kasper utilities couldn't get it out. Now I have to try all above recommended utilities. Until they catch this virus!

 
Search for _uninst_36992148 on the drive and in the registry
 

Charged in a search. Found these files:

Can it (the bottom file) be deleted manually? Or should both be deleted?

 

Yes. Both.

Install Reg Organizer and clean up your system.

PS If you haven't deleted it yet, try to open it with Notepad (right-click - open with) and show the contents.

Or "Edit", also notepad will open.

Reason: