Solved

Cannot access any Anti-virus websites, live updates etc.

Posted on 2004-03-29
9
6,987 Views
Last Modified: 2013-12-04
Recently My computer encountered a problem with the internet. When I went to specific sites such as google, utoronto.ca and download.com, I'd be able to browse the sites but when I did a google search or download, I got a redirected page of "Search the Web" - which was spyware. Apropos to be exact. So after some difficulty Ad-aware got rid of it. Unfortunately, after we got rid of it my internet just stopped working.

We took a number of steps to fix this:
1) Checked file/drive consistency
2) Rollback to a week ago Restore Point
3) Debated corrupted sock5 file
4) Unplugged and plugged router etc.

Then we made a drastic move and just reinstalled windows again to renew any corrupted files. I know it isn’t a problem with the internet itself because my roommate runs off the same router and her internet was fine. After reinstalling windows, the internet was still down.

So my friend guessed maybe my IP address was blocked somehow so he changed the IP and internet worked fine. However, when I downloaded Norton off a cd, I could not do a Live Update.

I could neither access any anti-virus websites. After using an online anti-virus scanner – Microworld – I discovered the agrobot virus. It got rid of it and right after I was finally able to update my virus definitions. However when I rebooted the virus was back and I could not access live update or any ant-virus websites (Grisoft AVG, Symantec Norton, Mc Afee).

Any ideas to what I may have or how I may fix it?

Thanks,

Jenni
0
Comment
Question by:jenniwilliams
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 14

Accepted Solution

by:
JohnK813 earned 125 total points
ID: 10704299
Many of the viruses/worms today are attacking your "hosts" file so you can't access antivirus sites.

With Notepad, open up the file

c:\windows\system32\drivers\etc\hosts

If you see lines like this:

0.0.0.0    www.symantec.com
0.0.0.0    www.norton.com

or any other site mapped to 0.0.0.0, delete those lines.  Also, if you see any common sites you recognize (such as Google) mapped to another number (IP address), delete those lines.

Your browser checks this hosts file first when you type a web address into your browser.  So, when it sees a site listed, it automatically uses that IP address.

Hopefully, deleting these lines from your hosts file will allow you to update your AV.  And, hopefully that updated AV will get rid of your virus problem.
0
 
LVL 12

Expert Comment

by:trywaredk
ID: 10704336
A search on http://www.mwti.net/virusnews/virusalert.asp?action=search did'nt find any agrobot virus.

hat's the correct name of the virus?

Many Regards
Jorgen Malmgren
IT-Supervisor
Denmark

:o) Your brain is like a parachute. It works best when it's open


0
 
LVL 12

Expert Comment

by:trywaredk
ID: 10704351
Debugging IIS Deadlocks and Blockings - e.g. if you have a dllhost.exe that consumes 100% CPU.
http://www.windowswebsolutions.com/Articles/Index.cfm?ArticleID=22276

0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 

Author Comment

by:jenniwilliams
ID: 10705042
The correct name of the virus is agobot, not agrobot, sorry for the error. This is an example of a virus search log for the virus:

File C:\WINDOWS\System32\regsvc32.exe infected by "Backdoor.Agobot.jn" Virus. Action Taken: File Renamed.

****

I followed JohnK813's advice and found these--

127.0.0.1      update.symantec.com
127.0.0.1      updates.symantec.com
127.0.0.1      liveupdate.symantec.com
127.0.0.1      customer.symantec.com
127.0.0.1      rads.mcafee.com
127.0.0.1      trendmicro.com
127.0.0.1      www.trendmicro.com
127.0.0.1      www.grisoft.com

There were more lines top of that but those are just to name a few. Since JohnK813 had said to look for 0.0.0.0 I wasn't sure if I should delete any of the lines. Still I experimented and deleted "127.0.0.1  mcafee.com" and was finally able to access the site. Perhaps because I am on a network that is shared the IP 0.0.0.0 would not be the same but -- 127.0.0.1.

I have finally updated my Virus Definitions properly and am running a Virus Scan right now and I sincerely want to give my thanks. I was considering bringing my computer in to a shop so I'm grateful that I got a response that worked.

trywaredk - Thanks as well, but I checked my task manager and it seemed my CPU usage was normal. I checked out the site for more information - it's good to know all possibilities.

Thanks again,

Jenni
0
 
LVL 12

Expert Comment

by:trywaredk
ID: 10705105
:o) Your welcome

BTW: The hosts file is used for redirecting an url, and the ip-number in front of an url, means to redirect the use of the url to the ip-number instead.

127.0.0.1 is your own computer. Thus typing www.trendmicro.com in your browser, you are not getting www.trendmicro.com, but your own computer, so "nothing happens"
0
 

Expert Comment

by:The_HAD
ID: 11257094
i have the same problem.
i fixed the file hosts as sugested, but the problem wasn't fixed. i still can't access antivirus websites
0
 
LVL 14

Expert Comment

by:JohnK813
ID: 11263533
HAD -

Piggybacking a question like this isn't liked too well around here, unfortunately.  If you'd like, you can ask your own question (check the left column, under Page Options), and I'm sure there are tons of experts who would be glad to help with your situation.  In fact, if you post a link to your new question here, I'll take a look and try to help you myself.

Cheers,
John
0
 

Expert Comment

by:The_HAD
ID: 11277531
Dear Mr johnK813

Sorry if my post wasn't up to your level. I myself am an IT manager and was trying to share with you the problem i was facing.

after cleaning the file hosts, and restarting the computer, the line i deleted are rewritten.
I updated the virus definitions and scan my PC. nothing was found.
i got the Gaobot removal tool. nothing was found.
does any one have suggestion ??
0
 
LVL 14

Expert Comment

by:JohnK813
ID: 11280070
HAD -

I didn't mean to insult you or your question in any way.  It's a very good question and a very common and annoying situation.  I was just trying to be helpful and inform you of the way things are done around here before someone tries to accuse you of cheating the system (see here for more information: http://www.experts-exchange.com/Community_Support/help.jsp#hi107).

If you open a new question, there will be many experts offering many suggestions to try to help you.  But, by posting here, you only have the attention of me, trywaredk, and jenniwilliams.  And, since Jenni's problem is solved, she may be getting annoyed by receiving an email each time one of us posts a comment to this thread.  So, it's really in your best interest to open a new question.

As for your situation, I'd suggest checking your system restore points and using a few of the spy/adware removal tools listed here: http:Q_20975384.html  But, as I said before, open a new question, and you'll receive many more suggestions and help by people who may know more about your problem than I do.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Excel files protected mode 4 50
recent accessed documents on windows 7 computers 2 154
Windows Event 56 TermDD. Am I getting hacked? 4 262
is this a virus? 3 59
In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question