Something is attacking my computer!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by osupaman, Jun 6, 2010.

  1. osupaman

    osupaman Private E-2

    First hello, and thank you in advanced.

    I'd like to start this off by explaining the problems i have been having. One day i guess i downloaded something or who knows.. and my computer suddenly and drastically slowed down. i also noticed my google redirecting and pop-up ads as soon as my mouse went near a link. Also i ran Antivirus scans (which i uninstall for some reason) a lot of my .Dll files came into error. So i came upon this site and did the Windows XP Cleaning Procedures. I ran SUPERAntiSpyware and Malwarebytes Anti-Malware fine and have the logs. ComboFix would first as me "Which user account do you want to use to run this program?" and my option would be current user(name of my account) and an option to "protect my computer and data from unauthorized program activity" which has a under description : This option can prevent computer viruses from harming your computer or personal data, but selecting it might cause the program to function improperly. SO i tried both and they both end up saying "some files could not be created. Please close all applications, reboot Windows and restart this installation" which of course i did.. and did not work.
    i would also like to add the constant "freezing" of the computer. When i play a game it takes forever to load then freezes when i ALT+TAB. And EVERY program i open is extremely delayed. (normal 1 second now about 20-30 seconds)
    starting a new paragraph so you're eyes don't strain..

    just to ensure i followed the procedure, i couldnt save combofix directly to desktop, but i did move it. (hope thats not a biggie.. no option to save as to desktop)

    Going on to rootrepeal, as soon as i double click the exe (also couldnt save but i moved it to desktop) the program pops up as well as an error. (error - invalid PE image found!). I hit ok and do the scan and save the log.

    MGtools I downloaded the same way and moved to desktop. I open the .exe and quickly and error pops up as well (Failed to ensure dir exists: /MGtools) i read the how to use Mgtools forum and nothing about this problem was posted. I googled another site and it told me to go to run /cmd and type "cd /mgtools" which didn't work so i couldnt finish the rest of the processes it told me to go.

    Well thats my story and if i forgot something im terribly sorry. I do have HiJackthis logs if that would help. This computer has been stressing me out for a while! i hope you can help!

    * i found an old ComboFix log from a month or two ago.. just gonna throw that in. OLD log!!!

    ** so after typing all this i realized my computer froze on the superantispyware scan .. so it didnt save the log though it did complete it. im gonna post this and add the scan log in an hour or 2 when it finishes scanning. i hope this wont affect much! sorry for the inconvenience.

    ***i havent tried the whole Procedure in Safe-mode. please let me know if i should try that too. (felt like another long use of 3 hours scanning)

    **** added an updated hijackthis.log


    Microsoft Windows XP
    Professional
    version 2002
    SP3

    Dell XPS 630i
    Intel Core 2 quad cpu
    q6600 @ 2.4ghz
    1.5ghz, 3.25 gb of ram
     

    Attached Files:

    Last edited: Jun 6, 2010
  2. osupaman

    osupaman Private E-2

    I've re-read the rules for this forum and i know I'm breaking them all in this post. Unfortunately i couldn't sit here and feel like i wont get a reply cause I posted my HJT post.. so I'm just going to add my updated SUPERantiSpyware scan log and hope for the best. My deepest apology geeks and specialist. I know you don't want to deal with people who didn't read rules first so here's my apology.

    Forgot to add the fact that I tried to copy/move MGtools to C:\ but

    Error Copy File or Folder
    Cannot copy MGtools: Access is denied
    Make sure the disk is not full or write-protected
    and that the file is not currently in use.

    It's not in use.(checked task manager) and tried on a fresh restart.

    Thank you once again.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you using for anti-virus protection? Did you disable or uninstall it before trying to run MGTools.exe? You need to take ComboFix out of the folder it is in and slide it onto your desktop.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  4. osupaman

    osupaman Private E-2

    i was using Avira Antivir, i uninstalled it previous to all the scans and attempts of using the procedure.

    I have redownloaded and moved combo fix onto the desktop and the same problem occured. If its any difference if i tell you that the combofix load bar lingers after crashing? And it also still runs in the taskmanager.

    As for MGtools i did as you said about the MGtools and after typing CD /MGtools, it says the system cannot find the path specified.
    MGtools is on my desktop and in my MYDOCUMENTS, unable to move into the Root C drive.
     
  5. osupaman

    osupaman Private E-2

    I just figured out i have Helpassistant user virus. And i believe thats why i cant run anything onto C folder or most of these antivirus stuff is not working. :cry

    i will read up onto other post on this forum. will repost i guess if i cant fix it.

    Fixing this causes me to use Combofix, which doesn't run.. Any other suggestions?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you try running MGTools from your desktop? Did it create the C:\MGTools folder? There are other methods to use when Combo will not run, but I need to see these logs in order to help.

    Since you have Combo on the desktop, do this:

    Go to Start > Run > then paste in:
    "%userprofile%\desktop\Combobatch.bat" /stepdel

    Tell me if it then runs.
     
  7. osupaman

    osupaman Private E-2

    MGtools is on my desktop when i run it..

    Error - Failed to ensure dir exists: \MGtools

    *oh and it did not create the C:\MGTools folder.

    typing ""%userprofile%\desktop\Combobatch.bat" /stepdel" in run program yet another error occurs..

    Windows cannot find 'C:\Documents and settings\XPS\desktop\Combobatch.bat'. Make sure you typed the name correctly, and then try again. to search a file, click start button and then click search.


    I think i gave up on trying to "cure" this computer. Ive tried to reformat and start recovery console about 10 times each, each time "bluescreening" when it gets near starting up. Reformatting would be best right now just to start fresh, but it boots up the Windows XP cd, loads and then once it gets to the "installing windows" part, it bluescreens. tried this multiple times.

    As for anti-virus scans. i scanned Malwarebytes and superantispyware, 3 times or so, clean as a whistle.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Trying to reinstall and getting a BSOD sounds like a possible hardware issue. However, I did make a mistake in not telling you to rename ComboFix.exe to Combobatch.bat before trying to do the run script.

    Are you saving your data and personal info and then wanting to do a reformat and clean install?
     
  9. osupaman

    osupaman Private E-2

    I changed the name of the file to Combobatch, and same problem, same error message.

    This computer only about 3 years old, so from previous ownership i know to store most of my stuff on externals, so reformatting wont be a huge issue on terms of losing information. The pros over weigh the cons right now.

    If i need help reformatting shall i start a new thread on the Software or Hardware side?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you should post in the software forum for issues related to reinstalling. The thing is, hardware issues can mimic malware issues. But I would hope that you can at the least get the hard drive reformated so a clean install can be done.
     
  11. osupaman

    osupaman Private E-2

    Thanks for your time and help! Though we couldn't figure it out. i learned a lot :)
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....hope that it all works out. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds