Several problems like lost of control panel

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Carlos Martins, Nov 5, 2011.

Thread Status:
Not open for further replies.
  1. Carlos Martins

    Carlos Martins Private E-2

    I think i was invaded by something (hijacker) that controlled my computer despite my malware bytes (everyday scans) and real time control from Avira.
    It seems that all this happened after my instalation of a free version of Avast and the new version of Avira (they said that this new version was not compatible with Avast). I had no time to do all the changes needed and computer was working well despite my mouse usually crsossing the screen when i typed something.
    I did an hijackthis and i am asking all the help possible for this. I have so many problems: now even my computer lost boot.ini and other boot configs and it is booting from c:windows only. However is lost almost everything from the system files and even do not let me enter with a recovery console (do not let floppy or dvd work). Frankly i need you rhelp.
    When i try to do something to recover those files mssg is always this: "
    The log file of Hijack this: "This operation has been cancelled due to restrictions in effet on this computer. Please contact your sistem administrator". However the administrator was usually myself, no more is working on this computer and have no more users.

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 14:23:59, on 05-11-2011
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal


    Edit by chaslang: Inline HJT log removed. READ & RUN ME FIRST. Malware Removal Guide sticky not followed.
     
    Last edited by a moderator: Nov 5, 2011
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should never install more than one antivirus at any given time. You have both Avast and Avira installed. You need uninstall both of them immediately. Then reboot your PC. After reboot, reinstall ONLY one antivirus program. Then continue on with the below.


    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Carlos Martins

    Carlos Martins Private E-2

    i really thank you and will follow religiously your indications and sugestions. However just one thing: how to uninstall the two anti-virus if one of this (Avast) only accept uninstallation through Safe Mode and my Safe Mode don´run anymore, no matter the way you try it (F8, msconfig, etc.).

    Please let me know if i can keep the Avast (the problemtic anti-virus) and unistal the Avira and then follow the remaininf of you rinstructions.?

    Kind regards
     
  4. Carlos Martins

    Carlos Martins Private E-2

    My Avast is still on my my computer as a stone statue. I know you have here a good recomendation to remove software without needing safe mode. However it is not free and i have not enough money to buy it. Is call Best Removela Tool and is eactly what i need to remove some software that don´t leave without leaing remainings everywhere.
    Can you sugest me another ooption when safe mode is KO?

    Thanks and Kind Regards
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can use the below program to uninstall it:

    Revo Uninstaller
     
  6. Carlos Martins

    Carlos Martins Private E-2

    Thank with your suggestion about Revo Uninstaller but it even do not recongnize all the files into the folder Avast5. Every files reply whith acess denied when i clicked to uninstall. As Avast only uninstall with FaceMode and i even can´t run Face Mode (nor with MSConfig or F8), i stll remain with Avast files includinbg the one that is detected on Registry (avastsvc.exe). I also try running autoruns and disable it from there but still very hard.
    I think that something is avoiding i use my privileges as Administrator and do not let me uninstall avast. For now at least i denied acess to Firewall (Avira with Firewall) and in the processes. It is not running but think that is controling the system or be controled by a malware.

    Do i must to run some anti-spyware before any action now?

    Ihave the logs of combofix, rootkitreveal and others and can place here according your instructions.

    According your rules i also tried to delete the quarantine files on Avira and they simply were not fixed, i mean Avira do not denied, repaired or delete it. I am telling you that the virus it founds there (for several tries to repair) is called TR/Cript.xpack.gen

    I couldn´t send any log files because i couldn´t accomplish the first instructions you send me.
    What do i have to do now?

    Best regards
    Carlos
    P.S. Sorry if any interruption of your Sunday and hope you have a good day.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you are talking about.. What is Face Mode? Also Avast is not installed/uninstall via MSconfig.

    Did you download and install illegal copies of Avast and Avira?

    You were supposed to uninstall all of Avira.


    Just attach run all of the READ & RUN ME FIRST and attach logs from the below programs:
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    • RootRepeal
    • MGtools
     
  8. Carlos Martins

    Carlos Martins Private E-2

    Yes, sorry i meant Safe Mode but typing is also wrong (sorry to let you know that i am a writer and have some books on libraries includind USA).
    What i meant is that i tried to boot with safe mode by MSConfig (as you know it is possible)but i couldn´t even when click the F8 Safe Mode never came.

    Now i am reovering most of the sistem files (system restore, control panel, tsk manager but unfrotunately not with your help). It seems you are worried with the questions i made even when your instructions do not revover my system.

    Instead i used another programs and that´s why i am almost recovering everying.
    It seemes to me that you are very pretensious and arrogant what i never noticed you before.

    Bye and will not return here.

    In the mewanwhile let me thamk you for the time you spend with me )some seconds indeed).

    Happy day to you
    Carlos
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but you never completed any of my instructions so that we could attempt to help you.

    Since you don't want or need our help, this thread is closed.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds