Windows vista still not operating correctly

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Countrybunker, Dec 13, 2012.

  1. Countrybunker

    Countrybunker Private E-2

    Hello,

    My computer has been acting up for a few months now. Im not exactly sure when/how it happened. :confused

    the Google website started acting wierd. Every link I clicked on went straight to an add. Also on forums I frequent, the txt's would be highlighted, and when the pointer was over them a pop up would appear. It kept getting worse and worse.

    A month or so ago I downloaded a free version of AVIRA. This seemed to help stop, and block the virus('s) As I don't notice the pop up's/and adds as much anymore. Yet occasionlly I still do. However I get a notice every 30 seconds it seems from AVIRA that says,

    Security alert
    Access to file C;/windows/installer/
    blocked
    Unwanted program
    'TR/ATRAPS.gen2' was blocked.


    I went threw the steps in the READ & RUN ME guide here, and here are the logs I collected. After doing everything, nothing has changed, or went away.

    The TDSSKiller program seemed to be blocked, as after scanning it said it found one malware object, but would not cure it. After hitting cure, it just came back to the normal screen.

    Also don't think the MGlogs are correct. However I'm not %100 sure.

    Hope someone can help.

    thanks in advance!
    zac
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the file/folder tab and locate these 5 detections:

    • [ZeroAccess][FILE] @ : C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@ --> FOUND
    • [ZeroAccess][FOLDER] U : C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U --> FOUND
    • [ZeroAccess][FOLDER] L : C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\L --> FOUND
    • [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> FOUND
    • [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Re run Hitman and have it delete all items under the heading "Malware" EXCEPT this entry: C:\Windows\system32\services.exe With this one I want you to let Hitman REPLACE.

    You can now also have it delete "Malware remnants" and "Potential Unwanted Programs".

    Now rerun TDSSkiller, just a scan and attach log. Same for RogueKiller please.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds