Unbeatable?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by NezKydn, Dec 25, 2008.

  1. NezKydn

    NezKydn Private E-2

    erm.. my pc infected by many kind of virus.. i think :( i dono how to remove it... my kaspersky is been conquer by the virus..
    hope anyone in this forum can help me.. :(
     

    Attached Files:

  2. NezKydn

    NezKydn Private E-2

    anyone can help me?? i used combofix on my other infected pc... my pc having blue screen... cant even loading welcome screen...:-D
     
  3. NezKydn

    NezKydn Private E-2

    can anyone help me?? two of my laptop been infected... help me plz... i used combofix.. still got the virus
     
  4. NezKydn

    NezKydn Private E-2

    still no ppl willing to help?? any intrustion i need to do first?? download wat ? wat logs?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should have just read the sticky threads in the forum which tell you everything you need to know including that fact that constantly posting is bumping and that will cause delays in getting an answer. See the below sticky:

    Don't Bump! It Only Hurts You!!!


    Now please follow the instructions in the below link (also a sticky which appears on all pages in the forum) and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  6. NezKydn

    NezKydn Private E-2

    i cant open ccleaner and seach and destroy.. double click them and nothing happen... i cant run my pc in safe mode.. blue screen.. search use Malwarebytes' Anti-Malware and superantispware get no result..
     

    Attached Files:

  7. NezKydn

    NezKydn Private E-2

    here is the sas log.. from sas.. i cant run my laptop on safe mode..
     

    Attached Files:

  8. NezKydn

    NezKydn Private E-2

    halo?:-o
     
  9. NezKydn

    NezKydn Private E-2

    should i bump?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you totally ignore the below line that I posted in my first message????????? Does the font need to be larger??

    Don't Bump! It Only Hurts You!!!

    Message # 5 cost you 3 to 4 days. And this last bump cost you 4 or 5 more.

    Why did you ignore the first Important Notes in the READ & RUN ME that stated you must only have one antivirus installed. You have both McAfee and Avast installed. You must uninstall one of them immediately before continuing.

    You are way out of date with Malwarebytes. You should run the program and Update it first and then run a new scan just to be safe and then attach the new log.

    See step 1 of the READ & RUN ME and put your PC into Normal Startup mode with MSconfig as we requested.


    You really need to read what we post and follow instructions since you appear to be skipping things.

    Goto Add/Remove Programs and uninstall PPSÍøÂçµçÊÓ which I assume is PPS Accelerator in english.

    You can try to repair your Safe Boot mode function by using the tools in SUPERAntiSpyware. Run it and click Preferences and goto the Repairs tab. Scroll down to the Repair broken SafeBoot key and select it and then click Perform Repair.


    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Is your copy of Spyware Doctor a paid version that actually fixes problems? If not, uninstall it immediately.

    Did you knowingly install Autorun Eater?

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work. Continue no matter what happens.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 13, 2009
  11. NezKydn

    NezKydn Private E-2

    my laptop is very serious last time... keep getting blue screen.. so i save all my data and format the c: .. stupid me, using the infected pendrive..the common thing that keep pop out is reader_s.exe ... after reader_s.exe then following alot more random name exe... i cant run ccleaner.. double click and then in a flash .. the ccleaner close by itself.. the fixreg wont work... coz the regedit been disable.. after i open the regedit .. i tried to edit the disable registry tool.. but the value keep change to 1 after i change to 0... dono wat make it auto changing the value ... my task manager also been disable.. i cant remove all the files in Local Settings\temp .. coz been used by other process.. i ran sas and show some virus.. after remove it .. it keep coming back.. so does mbam... i cant run my search and destroy... same like the ccleaner .. auto closed by itself.. could someone help me?? :cry:cry:cry my pc is very lagging... hope to get fast reply for u... thx...
     
  12. NezKydn

    NezKydn Private E-2

    this all happen after i download "adobe photoshop cs4 with working crack" after finish download it.. i install it but other thing came out .. the setup installing total secure 2008.. if i remember it correctly.. after that keep got pop out whenever i try to open folder or my drive.. say my pc is infected .. click okay and direct me to a website.. after i left the laptop afk for whole nite.. the next morning i see.. my pc is very lagging and many process is running ...
     
  13. NezKydn

    NezKydn Private E-2

    i just formated my laptop... and my laptop ald infected.. :cry:cry:cry:cry here is the new log... i cant run my mgtools.. blue screen?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot follow your messages. Are we talking about a second PC now? If so, you need to post in a new thread.

    A newly formatted PC will not be infected! Therefore you are reinstalling the infections youself by continuing to use illegal cracked software and or keygens. Please read our policies. Warning about Keygens, Cracks, and other Illegal Software

    I suggest the you start over again with a format and reinstall. And do not reinstall any illegal software. Also do not reinstall any backed up programs since they may be infected as well.
     
  15. NezKydn

    NezKydn Private E-2

    i reformat my pc and i didnt install other else... just the drivers ... i didnt format my D drive.. so i ll get infected?
     
  16. NezKydn

    NezKydn Private E-2

    :-D:-D:-D:-D:-D:-D:-D i knw my problem ald.. thx guys... i been infected by win32/virut.ae using avg and remove it.. im so DAMN happy now... :cool:cool:cool
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  18. NezKydn

    NezKydn Private E-2

    thx... :D no wonder i keep format and the virus keep coming... the virus infected my exe files.. thats y everytimes i play my game .. the virus keep coming back....
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes that is what Virut infections and quite a few others do. They spread to every executable type file on your PC and that does not just mean EXE files. If means anything that could be considered and executable (like .com, .dll, .mp3, .scr, .jpg, ..... and more)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds