Scared to surf bot naked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by esszeeeye, Jan 31, 2009.

  1. esszeeeye

    esszeeeye Private E-2

    While running thro' your wonderful guide to sort my PC,got stuck.

    Attempting to turn off AVG 8.0 Build 224 (free) in order to run "Combofix".
    -Combofix told me it was running,needed to be shut down.

    (The link may need updating-current program runs to end of 08-only a reduced version downloads)

    I could not turn off all the features,IE Anti-virus component,Anti-Spyware,from the advanced menu.
    -So I decided to try uninstalling,and getting a new version after the Combo scan...no dice,I got this-

    Local machine: installation failed
    Installation:
    Error: Action failed for registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: creating registry key....
    Error 0x80070005

    -So I got my AVG up again..virtual viagra and ginseng coffee.:hyper

    So now I'm scared to death I'll end up naked (Virtually speaking),and wonder
    what my next step is ? Go on with the list ? Next item is MGtools .
     
  2. esszeeeye

    esszeeeye Private E-2

    Ok,all the steps except the Combofix (explanation above) have been done.

    It all started when posting to my home photo forums,a pop-up window,from Windows asked for my Email address to continue.I closed the thing and got VERY nervous.I'll attach a pic of it.

    I contacted an admin,who said it was probably my computer,not their site,so I've been alternatively scanning/freaking out,all day.

    In my perambulations all over my computer,did find 5 exceptions to pop-ups
    in Firefox 3,which I unchecked,my problem is obviously teenagers ( I have 2)
    as well as Malware,as they were gaming sites.......time for a new password,
    methinks.
     

    Attached Files:

  3. esszeeeye

    esszeeeye Private E-2

    Spybot found nothing,run it every few days,also keep my AVG updated.

    Pic of pop-up added.

    Ok,the pic is a no-show,because its already here,in my hello post-

    http://forums.majorgeeks.com/showthread.php?t=181082

    Thanks in advance-I've already learned a lot,today.:cool
     
    Last edited: Jan 31, 2009
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean, though we can do some minor clean up:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  5. esszeeeye

    esszeeeye Private E-2

    Thanks so much,TimW,
    -great to hear I have nothing bad going on.

    AND I really appreciate all of the info and free programs,like CCleaner,as I was too chicken to try this stuff out before.:-o

    I will complete the suggestions you make,and keep SUPERAntiSpyware and Malwarebytes Anti-Malware,-felt rather bare out there with just AVG.;)
    and cannot use Totalscan,my old backup,with Firefox 3.

    My computer is HP Pavilion,DV5000 ,
    XP Professional,5.1.2600 service Pack 2 Build 2600

    Repartitioned by local shop (Guy who works on all the family’s PCs and band recording gear) on Friday, August 29, 2008.


    -Ran the MSTools,no problems.Fixed.:-D

    Not so successful with the file…What did I do wrong, here ?:confused

    Registry editor,

    "? Are you sure you want to add the information in
    C:\Documentsand Settings \HP\Desktop\ fixME.reg
    to the register ?"

    I click "Yes" and get-

    X

    "Cannot import C:\Documentsand Settings \HP\Desktop\ fixME.reg The specified file is not a registry script. You can only import binary registry files from within the registry editor."
    --------------------------------------------------------
    File contents=

    *
    REGEDIT4

    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

    *


    File name fixME.reg

    Save as type All files

    Encoding ANSI

    (Also can chose Unicode,Unicode big endian,UTF-8)

    Thanks again.:major
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ah..you copied all of the box which ( my mistake) had a space above Regedit4.

    I have corrected it..

     
  7. esszeeeye

    esszeeeye Private E-2

    Did the whole thing-success-message reads the registry entry was accepted !
    -can't say how relieved and really psyched I am to know it can be done by a beginner-Tweeted a coupla times how much I loved this site.
    The guys all laugh at me,trying to learn to do this on my own,well-for once,think I gained a little respect,just for that,huge thank you.
    I guess you will be seeing me around,as I learn to update my drivers,improve on the Windows defragger,etc,-totally get educated about Malware protection,etc.
    Cannot say thank you enough !

    :major
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds