Hello, I desperately need help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by strngdwrvnl, Aug 6, 2010.

  1. strngdwrvnl

    strngdwrvnl Private E-2

    dear forum,

    i come crawling to you humbly in need of assistance. i apologize for my ignorance and inexperience and hope ive managed not to break any forum rules...yet.

    i have read READ ME FIRST thread, but have not been able to get very far.
    i cannot find the AntiVir quarantine folder or anything like that in either Explorer or AntiVir.
    i ran CCleaner, but nothing seems to have happened.
    i cannot see if my windows xp home is 16 or 32 bit

    my problem:
    i started my pc today and AntiVir went mad. i have about 5 pop-ups from AV open permanently now. if i click okay/action it comes right back. i seem to have the following malwares:
    W32/Infector.Gen2
    HTML/Crypted.Gen

    my browser (firefox, chrome even netscape) keeps crashing, as well as windows explorer. i have already been getting error messages like this for a few days, but thought nothing of it: "dwwin.exe ... 0x00172058 refers to 0x08a50014 ... something couldnt be executed ... click okay to cancel application." im german american, living in germany, so half my pc's stuff is in german, making the matter even more difficult to solve.

    dear forum, thank you so much for reading this and thank you for considering a reply. im afraid i can only offer warmest thank yous and some help in the german language in exchange. ...and good kharma.

    thanks again
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    As stated at the beginning of the instructions, you need keep going until you have tried running all steps and all scans. You should not be stopping unless you don't understand an instruction and need to ask for help.
     
  3. strngdwrvnl

    strngdwrvnl Private E-2

    hello and thank you for your time,

    it seems that in my panic i overlooked the last step. i have now followed all the steps listed in Windows XP Cleaning Procedure except for the very last, since it lists Vista programs.

    as instructed, i downloaded the tools and performed scans. i started with Spyware Doctor, which froze my computer completely at 3%. i had to shut it down by turning off the power. after rebooting, it seems to be functioning like AntiVir, popping up malware messages, but when i tried to perform another system scan, it froze again.

    next, i tried ComboFix, which complained about AntiVir still running, which i cant seem to be able to turn off. it seemed to start, but froze. it was displaying the following status (this is a literal translation from german): "attempting to create system restore point." as everything froze along with it again, i had to pull the plug again.

    MalwareBytes: i couldnt rename it because this time i couldnt open Explorer anymore. my browsers also werent functioning (im surprisd and glad they are now). like with the others, my stuff froze completely and inspite of restarting two or three times, i couldnt use any application on my pc last night anymore.

    this morning, i ran RootsRepeal, which to my delight was short and successful. since everything else failed, im assuming there are no other logs for me to attach. the only other log i could find was an AntiVir update-fail, but i attached it nonetheless. (i looked thru the folders of the app's, but there seem to be no log-files in either the main folder or log folder)

    since my stuff seems to be working somewhat right now, should i try running all the programs again?

    thank you so much
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Huh??? The Windows XP Cleaning Procedure is all for Windows XP!!!

    Spyware Doctor is not part of our cleaning procedure and we definitely would not even want you to install it or run it. If this is not your own paid for copy, uninstall it immediately.

    The first scan you were suppose to run is SUPERAntiSpyware.

    This is not the order requested. You needed to run Malwarebytes after SUPERAntiSpyware.

    You don't need to rename it. That is only a trick used when a program seems to have problems running. Sometimes a simple rename allows it to bypass trivial malware that is only checking for the program name.

    You need to run SUPERAntiSpyware and you made no mention whatsoever about running MGtools.

    Also try running Malwarebytes again.

    We do not need a log from AntiVir that just shows its update process.
     
  5. strngdwrvnl

    strngdwrvnl Private E-2

    hello again,

    thank you for your time and patience. nothing works.
    -SUPER-Anti-Spyware freezes at setup and when i try to run it nonetheless, it stops after its first detection. it seems to freeze, make no progress, though the "Elapsed Time" keeps running.
    -sorry, i did run MGTools before and eventually my sh*t froze. it seems that, depending on what programs i use, my pc runs 5-10 mins before it completely freezes.

    i'll try everything again, but its very frustrating and time-consuming. i am, however, expecting the worst, so i have these basic questions:
    -if i burn files on dvd, will they be infected?
    -if i move stuff to an external hard drive, will that become infected and ruin the other stuff thats already on there?
    -is completely re-installing windows an option?
    -i have heard of stories where aggressive viruses damaged the hardware beyond repair. does this actually happen and, if yes, may that happen in my case?

    thanks again
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you tried to run the scans in safe boot mode? If not please do so. Try each of the below:
    • SUPERAntiSpyware
    • Malwarebytes
    And then run MGtools as follows

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the logs from SUPERAntiSpyware and Malwarebytes if they ran
    • C:\MGlogs.zip

    Without really knowing exactly what infections you have, it is not possibly to answer this with any certainty; however if you only backup your personal data, pictures, etc and no executable files (like download of programs etc) it is less likely.

    Same answer as above.
    Yes it is always an option, but not always necessary since there is usually a way to get started.
    Yes this can happen, but again, without seeing some logs or looking at your PC first hand ( which we cannot do ) it is not easy to answer.

    We have not run out of possible things to try yet. First check to see what happens in safe boot mode. If that does not work, see if you can make one of the below CDs and boot from it to run scans and see what happens. Make the CD using another PC if that is necessary.

    Kaspersky Rescue Disk

    http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html

    http://trinityhome.org/Home/index.php?wpid=1&front_id=12
     
  7. strngdwrvnl

    strngdwrvnl Private E-2

    hello again,

    i tried rebooting in safe mode, but that failed. ever since, my computer doesnt start windows at all anymore. i am getting this error message: "...cannot be started because \windows\system32\config\system is missing or damaged."

    i insert the windows cd, attempting to first repair, then reinstall, but i get another error message that goes something like this:
    "BAD_POOL_CALLER
    . . .
    Technical Data:
    *** STOP: 0x000000c2 (0x00000043, ..."

    since i had already begun downloading kaspersky rescue disk, i burned it and stuck it in my pc and im happy to see my pc doing something again, but i dunno if its any use any more. i also dont really know what im doing. im trying to do researcg, but as an inexperienced layman, sh*t takes time.

    so its scanning right now and it wont be done before i go to work. if it fails and i cant repair my computer, i suppose ill try the other two cd's youve suggested and see how much people would want for coming here and personally inspecting the machine.

    thanks again for all your support. i hope next time i post, i will have something positive to announce.

    cheers
     
  8. strngdwrvnl

    strngdwrvnl Private E-2

    hello again and sorry for bumping,

    i ran kasperski and then tried to reboot. now im getting this again: "...cannot be started because \windows\system32\config\system is missing or damaged."

    i tried repairing/reinstalling windows off the cd, i get a blue screen that says Windows Setup, but otherwise remains blue.

    when i boot off of the kasperski cd, i get a linux desktop, where i can go online from, but i cant access any of my drives or find anything regarding repairing windows.

    yeah...any suggestions left?

    thank you for reading
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you have your Windows CD, the below should be your next step as it appears that your registry has been corrupted:

    http://support.microsoft.com/kb/307545
     
  10. strngdwrvnl

    strngdwrvnl Private E-2

    okay, okay, look, im really sorry for being daft, but i cant seem to do snap in linux. i downloaded the .exe file from the page you kindly provided me with, but how will i run that file in linux? i am prompted to "open with" and "open selected file with," but ive no idea with what, how and where i would find that file or application.

    i cant do the manual repair because whenever i do make it to a seemingly functioning repair menue, i am asked for numbers and cant type in entire commands.

    dude, thank you. seriously.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exe file are you referring too? I did not ask you to download and run any exe file under linux. Linux is not Windows. I gave you a list of some potential CDs to try an help you work around the inability to boot and that is all. They have built in scanners and other tools that can be useful.

    The last link I gave you in my last message is what you should be trying to do. This is the link to repair a corrupted registry using your Windows boot CD to get to the Recovery Console.

    I don't know what you mean by being asked for numbers? Nor do I know what commands you are referring to nor why you cannot type them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds