Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Cannot access any Anti-virus websites, live updates etc.

Posted on 2004-03-29
9
Medium Priority
?
7,017 Views
Last Modified: 2013-12-04
Recently My computer encountered a problem with the internet. When I went to specific sites such as google, utoronto.ca and download.com, I'd be able to browse the sites but when I did a google search or download, I got a redirected page of "Search the Web" - which was spyware. Apropos to be exact. So after some difficulty Ad-aware got rid of it. Unfortunately, after we got rid of it my internet just stopped working.

We took a number of steps to fix this:
1) Checked file/drive consistency
2) Rollback to a week ago Restore Point
3) Debated corrupted sock5 file
4) Unplugged and plugged router etc.

Then we made a drastic move and just reinstalled windows again to renew any corrupted files. I know it isn’t a problem with the internet itself because my roommate runs off the same router and her internet was fine. After reinstalling windows, the internet was still down.

So my friend guessed maybe my IP address was blocked somehow so he changed the IP and internet worked fine. However, when I downloaded Norton off a cd, I could not do a Live Update.

I could neither access any anti-virus websites. After using an online anti-virus scanner – Microworld – I discovered the agrobot virus. It got rid of it and right after I was finally able to update my virus definitions. However when I rebooted the virus was back and I could not access live update or any ant-virus websites (Grisoft AVG, Symantec Norton, Mc Afee).

Any ideas to what I may have or how I may fix it?

Thanks,

Jenni
0
Comment
Question by:jenniwilliams
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 14

Accepted Solution

by:
JohnK813 earned 500 total points
ID: 10704299
Many of the viruses/worms today are attacking your "hosts" file so you can't access antivirus sites.

With Notepad, open up the file

c:\windows\system32\drivers\etc\hosts

If you see lines like this:

0.0.0.0    www.symantec.com
0.0.0.0    www.norton.com

or any other site mapped to 0.0.0.0, delete those lines.  Also, if you see any common sites you recognize (such as Google) mapped to another number (IP address), delete those lines.

Your browser checks this hosts file first when you type a web address into your browser.  So, when it sees a site listed, it automatically uses that IP address.

Hopefully, deleting these lines from your hosts file will allow you to update your AV.  And, hopefully that updated AV will get rid of your virus problem.
0
 
LVL 12

Expert Comment

by:trywaredk
ID: 10704336
A search on http://www.mwti.net/virusnews/virusalert.asp?action=search did'nt find any agrobot virus.

hat's the correct name of the virus?

Many Regards
Jorgen Malmgren
IT-Supervisor
Denmark

:o) Your brain is like a parachute. It works best when it's open


0
 
LVL 12

Expert Comment

by:trywaredk
ID: 10704351
Debugging IIS Deadlocks and Blockings - e.g. if you have a dllhost.exe that consumes 100% CPU.
http://www.windowswebsolutions.com/Articles/Index.cfm?ArticleID=22276

0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:jenniwilliams
ID: 10705042
The correct name of the virus is agobot, not agrobot, sorry for the error. This is an example of a virus search log for the virus:

File C:\WINDOWS\System32\regsvc32.exe infected by "Backdoor.Agobot.jn" Virus. Action Taken: File Renamed.

****

I followed JohnK813's advice and found these--

127.0.0.1      update.symantec.com
127.0.0.1      updates.symantec.com
127.0.0.1      liveupdate.symantec.com
127.0.0.1      customer.symantec.com
127.0.0.1      rads.mcafee.com
127.0.0.1      trendmicro.com
127.0.0.1      www.trendmicro.com
127.0.0.1      www.grisoft.com

There were more lines top of that but those are just to name a few. Since JohnK813 had said to look for 0.0.0.0 I wasn't sure if I should delete any of the lines. Still I experimented and deleted "127.0.0.1  mcafee.com" and was finally able to access the site. Perhaps because I am on a network that is shared the IP 0.0.0.0 would not be the same but -- 127.0.0.1.

I have finally updated my Virus Definitions properly and am running a Virus Scan right now and I sincerely want to give my thanks. I was considering bringing my computer in to a shop so I'm grateful that I got a response that worked.

trywaredk - Thanks as well, but I checked my task manager and it seemed my CPU usage was normal. I checked out the site for more information - it's good to know all possibilities.

Thanks again,

Jenni
0
 
LVL 12

Expert Comment

by:trywaredk
ID: 10705105
:o) Your welcome

BTW: The hosts file is used for redirecting an url, and the ip-number in front of an url, means to redirect the use of the url to the ip-number instead.

127.0.0.1 is your own computer. Thus typing www.trendmicro.com in your browser, you are not getting www.trendmicro.com, but your own computer, so "nothing happens"
0
 

Expert Comment

by:The_HAD
ID: 11257094
i have the same problem.
i fixed the file hosts as sugested, but the problem wasn't fixed. i still can't access antivirus websites
0
 
LVL 14

Expert Comment

by:JohnK813
ID: 11263533
HAD -

Piggybacking a question like this isn't liked too well around here, unfortunately.  If you'd like, you can ask your own question (check the left column, under Page Options), and I'm sure there are tons of experts who would be glad to help with your situation.  In fact, if you post a link to your new question here, I'll take a look and try to help you myself.

Cheers,
John
0
 

Expert Comment

by:The_HAD
ID: 11277531
Dear Mr johnK813

Sorry if my post wasn't up to your level. I myself am an IT manager and was trying to share with you the problem i was facing.

after cleaning the file hosts, and restarting the computer, the line i deleted are rewritten.
I updated the virus definitions and scan my PC. nothing was found.
i got the Gaobot removal tool. nothing was found.
does any one have suggestion ??
0
 
LVL 14

Expert Comment

by:JohnK813
ID: 11280070
HAD -

I didn't mean to insult you or your question in any way.  It's a very good question and a very common and annoying situation.  I was just trying to be helpful and inform you of the way things are done around here before someone tries to accuse you of cheating the system (see here for more information: http://www.experts-exchange.com/Community_Support/help.jsp#hi107).

If you open a new question, there will be many experts offering many suggestions to try to help you.  But, by posting here, you only have the attention of me, trywaredk, and jenniwilliams.  And, since Jenni's problem is solved, she may be getting annoyed by receiving an email each time one of us posts a comment to this thread.  So, it's really in your best interest to open a new question.

As for your situation, I'd suggest checking your system restore points and using a few of the spy/adware removal tools listed here: http:Q_20975384.html  But, as I said before, open a new question, and you'll receive many more suggestions and help by people who may know more about your problem than I do.
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question