Staredit Network > Forums > Technology & Computers > Topic: Anti-malware Doctor
Anti-malware Doctor
Sep 30 2010, 4:48 am
By: payne  

Sep 30 2010, 4:48 am payne Post #1

:payne:

Well, "Antimalware Doctor" decided to auto-install itself on my computer and now I'm stuck with this fucking virus.
I've downloaded Malware's Byte, ran a Full Scan, he found exactly 100 virus. I asked him to delete everything. He did it and confirmed it.
I reboot my CPU, and guess what, this fucking Antimalware Doctor virus is still there! :flamer:
I run a Complete Scan once again, but this time, Byte finds nothing.

Help! :(



None.

Sep 30 2010, 5:20 am rockz Post #2

ᴄʜᴇᴇsᴇ ɪᴛ!

sounds about right.

You have 2 options:

The best option is to backup, reformat, reinstall. Works every time. The reason for this is that no matter the antivirus, no matter the methods you take to undo the virus, you can never be certain that a previously compromised system is no longer compromised. Never.

The second option is to download a linux based virus scanner. Clamwin should have a linux version. I was impressed with Avira Antivir's bootdisc antivirus, though it's detection is somewhat lacking. Try out MSSE, perhaps it will have something. Finally, you can google for how to get rid of it, but they'll probably tell you what I did.



"Parliamentary inquiry, Mr. Chairman - do we have to call the Gentleman a gentleman if he's not one?"

Sep 30 2010, 10:57 am NudeRaider Post #3

We can't explain the universe, just describe it; and we don't know whether our theories are true, we just know they're not wrong. >Harald Lesch

combofix usually gets rid of these persistent viruses.




Oct 1 2010, 2:39 am Falkoner Post #4



If you're on XP, I highly recommend ComboFix, if you're not, I recommend finding the startup entry for the virus in msconfig, it'll usually be some randomly generated jumble of letters, using RunDLL to load the DLL into a system process. Find that entry, find the file path to the DLL it's loading, then boot into something like Hiren's Boot CD or UBCD4Win, and delete that file from your computer using either one, it should be gone on startup.



None.

Oct 5 2010, 9:14 pm Twitch Post #5



http://www.bleepingcomputer.com/virus-removal/remove-antimalware-doctor GO down to the bottom to find every file it is attached to. Start up in safe move and remove each of those one by one. After that restart and it should be gone.



None.

Oct 9 2010, 11:49 pm CecilSunkure Post #6



If you run through this, and don't screw it up, then you'll be malware free almost for sure. If not, you can post your logs onto the website, and they'll help you.

http://forums.majorgeeks.com/showthread.php?t=35407



None.

Oct 10 2010, 12:50 am rockz Post #7

ᴄʜᴇᴇsᴇ ɪᴛ!

>then you'll be malware free almost for sure

Once your system has been compromised there is no way to tell with 100% certainty that the system is malware free.



"Parliamentary inquiry, Mr. Chairman - do we have to call the Gentleman a gentleman if he's not one?"

Oct 10 2010, 12:51 am Centreri Post #8

Relatively ancient and inactive

Hence the almost, no?



None.

Oct 10 2010, 1:01 am CecilSunkure Post #9



Yeah, you can always reinstall your OS to be sure. Although, running through that link has worked pretty darn well, and most people don't care if they're still infected if it's not even doing any damage, or if it's even noticeable.



None.

Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[01:19 pm]
Vrael -- IM GONNA MANUFACTURE SOME SPORTBALL EQUIPMENT WHERE THE SUN DONT SHINE BOY
[01:35 am]
Ultraviolet -- Vrael
Vrael shouted: NEED SOME SPORTBALL> WE GOT YOUR SPORTBALL EQUIPMENT MANUFACTURING
Gonna put deez sportballs in your mouth
[2024-5-01. : 1:24 pm]
Vrael -- NEED SOME SPORTBALL> WE GOT YOUR SPORTBALL EQUIPMENT MANUFACTURING
[2024-4-30. : 5:08 pm]
Oh_Man -- https://youtu.be/lGxUOgfmUCQ
[2024-4-30. : 7:43 am]
NudeRaider -- Vrael
Vrael shouted: if you're gonna link that shit at least link some quality shit: https://www.youtube.com/watch?v=uUV3KvnvT-w
Yeah I'm not a big fan of Westernhagen either, Fanta vier much better! But they didn't drop the lyrics that fit the situation. Farty: Ich bin wieder hier; nobody: in meinem Revier; Me: war nie wirklich weg
[2024-4-29. : 6:36 pm]
RIVE -- Nah, I'm still on Orange Box.
[2024-4-29. : 4:36 pm]
Oh_Man -- anyone play Outside the Box yet? it was a fun time
[2024-4-29. : 12:52 pm]
Vrael -- if you're gonna link that shit at least link some quality shit: https://www.youtube.com/watch?v=uUV3KvnvT-w
[2024-4-29. : 11:17 am]
Zycorax -- :wob:
[2024-4-27. : 9:38 pm]
NudeRaider -- Ultraviolet
Ultraviolet shouted: NudeRaider sing it brother
trust me, you don't wanna hear that. I defer that to the pros.
Please log in to shout.


Members Online: Roy