big computer problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jeansl, Sep 18, 2007.

  1. jeansl

    jeansl Private E-2

    I had someone use my computer and they disabled my firewall and God knows what all but now I have a useless computer. I have tried running the read and run this first. After two days of constant work I am about to give up. It took me a whole day just to get to step 5. I can't get the scans in step 6 to run. I have got messages like "DrWatson Postmortem Debugger has encountered a problem and needs to close", this happened while trying to get into safe mode. My computer freezes and constantly shuts down. Am I screwed or does anyone have any ideas. :cry
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you boot into safe mode and from there run a system restore?
    Can you do it in normal mode?
     
  3. jeansl

    jeansl Private E-2

    No such luck. It says that my computer could not be restored to.......... what ever date I choose. I tried several. Any other ideas?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see if you can somehow run the procedure in the below link:

    Using MGtools

    If you can, then attach the MGlogs.zip file that it creates in the root folder of your Windows boot drive (this is normally C:\MGlogs.zip )
     
  5. jeansl

    jeansl Private E-2

    That was easy enough. Here it is.
    jeansl
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your ZIP file seems to be missing one log that should have been automatically run and put into the ZIP file. This log is a HijackThis log. Did you see HijackThis popup after a minute or so after running the MGTools.exe file? HijackThis and a log from it should have popped up and the log should have been put into the MGlogs.zip file.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also on Sept 9th someone installed a load of stuff (most looks related to Realplayer) directly into your C:\Program Files folder instead of into a folder for Realplayer itself. While this should not really cause crashes, it is a very bad idea to do this and now it is almost impossible to properly clean it up since it is very hard to distinguish which folders belong to the Realplayer (or RealAcade) software and what belongs to something else. Do you need this Realplayer stuff for any reason? I would doubt it is really needed. If not, I suggest that you uninstall Realplayer and RealArcade in an attempt to hopefully cleanup some of what it did to your C:\Program Files folder.

    Also I see signs of AntiVir, Norton/Symantec and also CounterSpy but they don't appear to be truly installed. Can you explain this? Also can you explain not having an working antivirus on installed?
     
  8. jeansl

    jeansl Private E-2

    I do not need real player or any arcade games. I do not know why my AVG is not working. I had to download CounterSpy last spring while running the read and run this. It was hard to get off after the trial ended but I thought I uninstalled it. Norton was uninstalled long ago, after my original subscription expired. After I got my computer cleaned I had sygate firewall installed and AntiVir in my attempt to keep my computer malware free. Norton was installed when I bought the laptop. I uninstalled AntiVir and reinstalled AVG while trying to "read and run this", this week. In the midst of all the warning pop ups and blue screens it must not have installed correctly.
    Everything was working well until my brother got on my computer and disabled the firewall and I don't know what all he did.
    So, now I will attempt to uninstall Real player and RealArcade and get my antivirus on correctly. Hopefully that will work.
    Thank you for helping me out.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You installed AVG Anti-Spyware 7.5 while running the READ ME, not AVG Antivirus. You do not have any active antivirus protect installed at this time which is very dangerous.

    Uninstall the RealPlayer and RealAcade stuff and then attach new logs from ShowNew and HijackThis. I will then try to workup a cleanup procedure to remove othe miscellaneous stuff left hanging around from RealPlayer and from all of your old protection software.

    At some point we will probably be uninstalling your firewall and then reinstalling but let's hold off on that until cleaning up other things.
     
  10. jeansl

    jeansl Private E-2

    Sorry this has taken awhile. My computer got to where I could not do anything without it giving me the blue screen and shutting down. I also had to leave town for a couple of days. Now I am using a USB 2.0 Universal Drive Adapter to access the problem lap top with my husbands computer. Thanks so much.
    L.Jeans
     

    Attached Files:

  11. jeansl

    jeansl Private E-2

    I don't think running the ShowNew will work this way, as it scans my husbands C drive instead of my problem laptop.
    Is this a lost cause?
    L.Jeans
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and the HijackThis log is not for your laptop either.

    Well you are outside the realm of malware. And your logs back from messsage # 5 did not show any malware either. You have problems with your OS and may need to try a repair install or may need to do a complete reinstall. You would be better off discussing this in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds