antivirus 2009 is taking over the world, but my computer first...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dcor, Dec 22, 2008.

  1. dcor

    dcor Private E-2

    Well lets see, where to begin. I want to premise that I have followed the malware removal instructions sticky on the top of this forum. Secondly, I allowed a script to run last night that I thought was legitimate. Obviously it wasn't. Shortly after I allowed the script to run, I got a popup from what looked like windows security panel telling me "you have a security problem." At that point I knew I had done something wrong....My first plan of action was to use avg to scan it. When I scanned it with avg, somehow I think it changed the path of avg to use antivirus 2009.....so when I would click on avg, av2009 began to scan....awesome! Well, I uninstalled av2009....but still kept getting popups saying I had a security problem and a popup asking if I wanted 64.128.whatever (random ip addresses) to allow access on port etc. etc....This isn't actually my computer, it is my roomates to make things better....my next idea was to google for an answer....the icons and jpeg etc. files were being blocked but the engine actually did work. When I would see the results displayed and click on a link, it would take me to some random search engine or some pharmaceutical website with blogs on it.......so I thought I would try to go to majorgeeks.com and found out that you guys had called it quits...(or so I thought at the time.) But after playing with this thing for some time, I realized that everytime I tried to go to a legitimate site that might be able to help, it blocked it as if I had no connection to the internet or the site did not exist. The next course of action was to try and see what processes were running, and keeping in mind that it wasnt my computer, I killed most of the ones running under his name that I wasnt familliar with as well as reset his internet settings. That didn't stop the "you have a security problem," and assumed it was still recalling the functions from the registry or whatever....so i ran ccleaner which i had installed on his computer some while ago and deleted the "bad" registry files.....once that didnt work and I could not get spybot, adaware, or malaware to install or even navigate to pages that had them I realized that I might have to get on my computer to actually find legitimate support. I actually decided to download them from my computer, import them with a flash drive onto his and try to run them from there.....i got them actually onto his desktop, but when i try to install, it just sits......with spybot s&d, it tries to access the update server but it does this at 127.0.0.1!! wtf? This thing is mean!!! I went to major geeks (which I have used for years....just never had to post here guys.) and saw the remove malware sticky and followed the instructions....since then, I have reinstalled java....and when I went to the boot in normal mode in windows.....I ran into some issues.....it freezes up now and sends me to a blue screen which talks about having "adequate disk space. If a driver is identified in the stop message, disable the driver or check with the manufacturer for driver updates. Try changing video adapters"...then it gives me a bunch of hex digits 0x0000008E, 0xB0F9DB75,0XADE6B7E8, 0X00000000...I tried to boot in safe mode and run system restore....but after i find a date and hit next to launch system restore, the button goes dead and doesnt function.....so at this point im at a loss for words....I have no clue what to do besides contemplate a factory restore.....if you need any more information than what I'm about to provide let me know plz.....thanks in advance...

    Win xp sp3
    dell inspirion 1501
    amd turion 64 x2 mobile
    1.60 ghz
    1.37 gb ram
     
  2. dcor

    dcor Private E-2

    ok an update....i actually got malwarebytes on the infected computer to run by disabling one of the non plug and play drivers thckk.sys or something like that....renamed the installer file to something else and got it to run....it removed antivirus 2009 but would not update....the popup is completely gone...but the internet still has the same issues of not allowing antimalware websites to load.....i could not get spybot to load on that computer since it requires an update to install.......so i went ahead and tried to restore the computer to a previous date again and I can't get a system restore to go through.....any ideas on how i can get my browser back?
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds