Explorer Crashes/Restarts

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ArmyOps, Jul 22, 2008.

  1. ArmyOps

    ArmyOps Private E-2

    Ack!
    Ive never been one to be duped into the Whole "Click me to fix blahblah" Routine, but seeing as my roomate has just woken me up, and my computer is showing ALL the WONDERFUL signs of some pretty heavy infection, im gonna need help.
    I THINK Ive already gotten rid of winspywareprotect, cause it was popping up left and right, which in addition to explorer blinking at me, makes it a bit hard to get into my C drive and see whats there that doesnt belong.

    -PnkbstrA And B, if they show, are from a game i play, theyre harmless anti-cheat programs.

    Hijackthis Logfile:
     
    Last edited by a moderator: Jul 22, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. ArmyOps

    ArmyOps Private E-2

    If i activate Normal startup, ill be taking a giant leap back from where i have progressed.
    Normal startup includes several of the files i know to be cauising the problem, and if i were to boot them, i would not be able to:
    Acess any control panel or administrative tools, connect to the internet, etc.
    Explorer is STILL crashing and rebooting in safe mode, and networking will not work.

    I've also tried using combofix, but it says CFSscript is misspelled or some pile of booshie.
    Lol, ive tried all the normal ways around this, and wouldnt really be posting unless it was over my head, which it is.
    Things tried--

    Safe mode- No networking/Explorer crashes and restarts EVEN MORE frequently along with
    the "Your computer is running in safe mode" Text box popup. I can barely get to Start>My computer before it goes out.

    -Control panel Add/remove Programs- Everything seems fine here, though due to the number of gamers in the household, im not sure.

    Hijackthis+Combofix- Renaming the Hijackthis Logfile to Combofix-Do Is not working for some ungodly reason, though i sorely wish it would, because if i remember correctly, we had this problem before.
    -Lavasoft Ad-Aware+Trend Norton+Spy Sweeper
    Only things these programs are finding is tracking cookies, which, just to be on the safe side, i got rid of as well.
    Windows Explorer Is NOT Crashing while combofix runs, but resumes its antics immediately thereafter.

    When this started, i had Winspywareprotect, And 3 or 4 other
    "We found 238974 infectious files on your computer(That we put there)! Buy our fake program now so we can infect you farther!" - programs and managed to get rid of those mostly, as the frequent popups are gone, as are the running processes, unless im failing to see them.
    They disabled my taskmanager, whcih i got around by editing the registry through the winkey+r method, and also removed all but "Set program access and defaults" And "Shut Down" From my start menu. I could not access ANYTHING and when i went to run system restore, cause i didnt want to mess with it, ALL my restore points were gone, and a new one had been created, handily enough, it was created while the files were on my computer, so i cant just skip past this. -_-
    *pulls hair out*
     

    Attached Files:

    Last edited: Jul 22, 2008
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't worry about resetting to normal startup just yet.....

    Did you rename combofix to combo-fix? Is it on your desktop? (You need to disable your anti-virus software before you run it).

    SAS and MWB's scans should run in either safe or normal mode ....and can be downloaded to a diff. computer and then transfered to the infected one.

    Why are you trying to rename hijackthis to combofix?
    I need the logs from running:
    SuperAnti-spyware
    MalwareBytes
    MGLogs.zip ---> from running the MGTools.exe
     
  5. ArmyOps

    ArmyOps Private E-2

    I was told to rename the hijackthis logfile to Combofix-DO and drag and dfrop onto combofix at one point. I dont remember where, but i MIGHT have picked that up here.
    Lol ill get right on those other logfiles, hunting links now :p
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It certainly was not someone here that told you to do that ....and the HJT log that you attached does not show anything of use ...mainly because it was not properly installed. It will be when you do the MGTools. :)

    I gave you the link to the Read and RUn First, which has all the links you need.
     
  7. ArmyOps

    ArmyOps Private E-2

    Scanning with SAS now, then MWB and ill download MGtools.
    Sorry if my frustration shows through my posts, but i dont know too much about all this, and my idiotic Boyfriend and his friends, aka my roomates, have even less of a clue as to what to do in case of a serious infection. Lol.
     
  8. ArmyOps

    ArmyOps Private E-2

    AAAAAAAAllrighty.
    After running All three, i restarted, as prompted by SAS, and have spent the last 30 mins(Well, you know. Not 30 mins. xD) trying to get my machine to boot xD
    It would flash the critical OS error screen and restart, so i finally just went to last know good config and it seems to be working fine.
    Thats on normal startup as well, mind you, so im 90% sure its fixed.Here is the hijackthis log from the MGtools folder, in case your curious to see it.
    But now im having another problem. xD
    Instead of opening destination(clicked or opened folders) in the same window, its popping a new one up every time i click anything.
    Simple i know, but point me in the correct area of the website to visit so i can fix this (slightly) less annoying problem?
     

    Attached Files:

    Last edited: Jul 22, 2008
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs....not individual logs from the MGLogs.zip.

    I need to see all of them. You are rather infected and I cannot get you clean with just a HJT log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds