I Need Help Fast!!!!!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by swoops456, Jun 8, 2008.

  1. swoops456

    swoops456 Private E-2

    hi, ive been experiencing slow internet process, and pop-ups are exploding out of nowhere. im pretty much new to having viruses or whatnot on my computer, so i dont know what to do... I tried running my antivirus and it says that i had a virtumonde virus, and it quickly disinfected it (I run my antivirus and spyware in Safe Mode). Ive tried running my spyware and it detects nothing.So basically my antivirus and my spyware are saying my computer is fine. But so many popups are popping up asking me to download an antivirus and there are also many add popups. It also resets my cookie privacy to allow all cookies everytime i ask it to be on medium high. I dont know whats going on. My keyboard also is being affected...I DONT KNOW WHATS GOING ON PLEAZE HELP ME WITH MY SICK COMPUTER BEFORE I LOSE MY MIND!!!!!:cry:cry:cry
     
  2. swoops456

    swoops456 Private E-2

    Here is my hjt log ( i didnt know if you wanted it or not) and my mg log...im scanning the SUPERantispyware and the Malwarebytes antimalware now...
     

    Attached Files:

  3. swoops456

    swoops456 Private E-2

    Here are some of the other scan logs...there is one more i reckon
     

    Attached Files:

  4. swoops456

    swoops456 Private E-2

    this is the malware scan part 2...thats what ive scanned...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Next time please be more careful when following instructions. You did not DOWNLOAD and save MGtools.exe to your PC and then run it as requested. You ran it directly from the website using Open or Run. The below shows this in your log:

    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\MXI8TZ5K\MGtools[1].exe

    Not following instructions can lead to problems. You are lucky that it ran properly.

    Uninstall the below below non-recommended software:
    SpyHunter
    SpyZooka

    Also uninstall Norton 360 since you are using Panda!

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - rsion - (no file)
    O2 - BHO: (no name) - {C4E3F692-0A2C-42BF-9E2B-B4407042457D} - C:\WINDOWS\system32\mlJYrrss.dll
    O2 - BHO: {02fd2afc-85cd-e4aa-4dc4-d54fc770b10e} - {e01b077c-f45d-4cd4-aa4e-dc58cfa2df20} - C:\WINDOWS\system32\mopgaoqd.dll
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. swoops456

    swoops456 Private E-2

    i dont know what i did but my computer is working great now...fast too..but ill do what you just told me as soon as i get home tomorrow...
    i have another question...i want to change my antivirus, because my panda software is outdated, and im afraid that if i dont get a new antivirus soon that my computer will be vulnerable to viruses...do you know of a good...free...antivirus software?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. swoops456

    swoops456 Private E-2

    Ok so i did what you told me to do in the previous post...I also deleted my panda! antivirus and switched over to avast...do you think that was a good decision? I have another question...when looking at my ComboFixLog.txt...i saw: WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!...
    what does this mean...is it bad?
     

    Attached Files:

  9. abri

    abri MajorGeek

    Hi swoops456,

    If you are interested in installing the recovery console, it takes a very short time as long as you have the cd for your operating system. It can be useful in some more serious crises. You can read the instructions for it here:

    How to install and use the Windows XP Recovery Console

    abri
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should not be making any changes to your software unless we ask you to do so. You now have Avast installed and did not have a proper cleanup of Panda before installing Avast. Also I still see Norton 360 in your logs. Did you look for it in Add/Remove programs to uninstall? Does it show?

    Also you attached MGlogs.zip after running in Safe Boot mode. You need to be in normal boot mode. Please do the below:

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Panda Process Protection Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastePavPrSrv into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds