Used Malwarebytes now programs won't open/Alternative to avpfind.bat?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by adnara, Dec 14, 2011.

  1. adnara

    adnara Private E-2

    I found this forum and the post by IcemanGER "programs wont start after using malwarebytes" so I decided to follow those instructions (maybe wasn't the best idea?)

    Number 3, Rkill.scr worked for me. I then tried to use the avpfind.bat link which I supposedly should have used immediately, and it doesn't work. What do I do now? Is my computer still safe?

    I'm doing this all in safe mode.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, you should never follow advice tailored especially for another user/computer.

    Are you saying that you are not able to run ANY of the below in either normal OR safe mode?

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. adnara

    adnara Private E-2

    I came here after I already ran malwarebytes and the Win7 popup was gone so I didn't take any of the steps before Step 5.

    Before I used the rogue killer, I ran a full scan with Super anti spyware on my computer, then restarted in safemode only to see that Win7 was still there, so I ran Malwarebytes. This got rid of it but I am unable to use programs on my computer (like Windows Media Player, the volume control is muted, etc)

    I just rebooted my computer after following these steps from READ & RUN me first

    -Fixing Google Redirection/hijacking (up to step 3, but I still got redirected to a random website when I opened firefox to post here)
    -didn't do step 2 because I only have Norton, I am also unable to adjust firewall settings at this time
    -I mistakenly typed sun java into my program search so I didn't uninstall it, I guess I thought it was a different version =/
    -have a 32-bit operating system
    -enable viewing of hidden files
    -set MSconfig to Normal startup
    -already used a malware program...
    -disabled disk emulation with gooredfix

    Should I proceed to Step 7? Or go to step 4 in Fixing Google Redirection/hijacking?

    here's what I got in the Gooredfix notepad:
    GooredFix by jpshortstuff (03.07.10.1)
    Log created at 16:19 on 14/12/2011 (My Name)
    Firefox version 8.0 (en-US)

    ========== GooredScan ==========

    (none)

    ========== GooredLog ==========

    C:\Program Files (x86)\Mozilla Firefox\extensions\
    websitelogon@truesuite.com [07:20 18/07/2011]
    {972ce4c6-7e08-4474-a285-3208198ce6fd} [19:05 17/07/2011]

    C:\Users\MyName\Application Data\Mozilla\Firefox\Profiles\uxhyb9zz.default\extensions\
    (none)

    [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
    "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\IPSFFPlgn\" [12:22 15/07/2011]
    "{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\coFFPlgn_2011_7_3_6" [05:28 14/12/2011]

    -=E.O.F=-
     
  4. adnara

    adnara Private E-2

    Alright, huge problem



    I was browsing the web and all of a sudden my internet windows (firefox) closed, and I got a message "unable to read system" or something...I forgot what it said because I panicked and it popped up like fifty times.

    A few of my icons (Firefox, Malwarebytes, Superantispyware_ have disappeared)

    I was just about to post that my internet windows close down like that and that my computer randomly closes my programs and reboots itself. I saved all of my pics and documents yesterday so at this point I'm okay with starting all over.


    I'll do anything to fix this...I can't afford to take this to take my comp to anyone right now


    I'm using a Windows 7

    Im going to quick reply and add more info continuously in case it shuts down again sorry
     
  5. adnara

    adnara Private E-2

    Also Last night before I used Superantispyware and Malwarebytes I thought that the Win 7 virus was a legitimate warning from Windows 7 so I put in an order for a Win 7 home security package with my mom's bank card but called the bank and cancelled the card once I realized the stupid mistake. After that I made a worse one and called a hotline I found on a google search on my phone, called myphonesupport.com/Microsoft, and over the phone the tech told me to visit logmein123.com where he had access to my computer and looked at the Win 7 and told me to let him "fix it fast" or else. Well I became skeptical because of his pushiness and my friend told me she read it was a scam so I didn't go through with it.

    Also when I got the pop-ups and turned off my computer, when I turned it back on it went straight to Safe mode without pressing f8. Is this because I just pressed the off button without shutting down, or did I screw up my computer? (I'll try to find out by shutting it off normally when I'm done with this post)

    The only online scanners I have left are Whitesmoke and Spybot search and destroy, I still have Defogger, all my docs and pics are gone, a lot of games and other things are gone.

    please let all this info show so that it prevents anyone else from making these dumb mistakes

    Sorry for all the added info, I really don't mind waiting a while for a response so long as I get one. I won't sign back in til tomorrow from the library to check for a response, I don't think I'm helping the situation by using the computer.
     
    Last edited: Dec 14, 2011
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But this is classed as "Bumping" and that will delay your helper from giving you a response, pushing you to the back of the queue. Your post also ended up in moderation as something in it tripped the spam filter. More than likely the website for the logmein.

    If he had access to your computer then you need to change all of your online passwords from a known clean computer. hen you need to contact your bank and all credit card accounts and just alert them to the fact that your personal info may have been compromised.

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Did that help?

    You mention that you were able to run certain programs such as Malware Bytes and SUPERantispyware, so please look again at my link, following all of the other instructions in it and start attaching logs for me to review. Not only do I want to see logs from Malware Bytes and SUPERantispyware but also from Combofix and MGTools if you were able to run them.
     
    Last edited: Dec 14, 2011

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds