My youtube loving kid has screwd up my computer!

Discussion in 'Malware Help (A Specialist Will Reply)' started by spadesmamma61, May 28, 2008.

  1. spadesmamma61

    spadesmamma61 Private E-2

    Bought a new computer, ran fine untiol 2 days ago then all of a sudden Im getting all these popups from dating sites etc. I also keep getting something running that says Windows.Security.InternetExplorer blah blah.

    Ive run all the neccessary things in RUN ME FIRST and WindowsXP Cleaning Logs are attached. Please help asap as I use this cvomputer for work and Im screwed for tomorrow if I cant get it running right.


    Thanks so much you guys have always been such a help!
     

    Attached Files:

  2. spadesmamma61

    spadesmamma61 Private E-2

    Here are the final logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good...are you still having issues?
     
  4. spadesmamma61

    spadesmamma61 Private E-2

    Actually no I havent since last night. Im hoping that those steps fixed the problem. :)

    I'll let you know if there's a further issue..
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In the meantime....If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  6. spadesmamma61

    spadesmamma61 Private E-2

    I may have spoke too soon. This is showing up in my fireway whqat the heck? I didnt allow this stuff? Ive started blocking but as you can see there are many and they are all from the same IP addey. Is there a way to just block the addey? Or is this a problem? I honestly dont know what to make of it.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is showing up in your firewall? Something trying to get in or get out? That is what your firewall is supposed to do...but you need to tell me exactly what is happening.
     
  8. spadesmamma61

    spadesmamma61 Private E-2

    I dunno the bloody screencap didnt attach. Im not worried about that anymore.

    My original problem is back! :cry

    Please see attached SSD log, Ive also noticed an extreme number of Internet Explorer needs to close error messages along with a few WINDOWS Explorer needs to close messages. :( I didnt have SSD fix anything yet. I wanted to get your input first. I am however ready to disown my child for freaking up my new computer!!!!


    SOS! :confused
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Was there something in that log that concerns you? Perhaps you should do a new MalwareBytes scan and also run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  10. spadesmamma61

    spadesmamma61 Private E-2

    The stuff in the quote box below is the thing that started all my problems to begin with. It was gone and now its back. I''ll have to re-download the MGTools thing since I deleted it as instructed. I'll do that and the other scan and reattach those logs.

     
  11. spadesmamma61

    spadesmamma61 Private E-2

    Ok ran the scans. The first one located a Trojan in my Restore files.

    And while running the MGlogs program I got a yellow box at the bottom right something about my C drive and it didnt look good. Im going to attach the screencap of that as well. :(

    Thanks so much for your help with this.
     

    Attached Files:

  12. spadesmamma61

    spadesmamma61 Private E-2

    Oh no its worse. I went ahead and ran the checkdisk on a reboot and it froze. This came up:

    I went ahead and rebooted again and skipped the checkdisk this time.

    Eeeep Help!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The file in your system restore folder will be removed when you toggle system restore.

    The cmd.exe being corrupted is not good.....please go to start / run / type "sfc /scannow" without quotes and note the space...have your xp cd ready. Run it twice. Let me know what happens.

    You say this is a new computer? I would like you to run chkdsk again.....right click the c drive and click properites / tools / error checking....check both boxes and reboot...watch the screen and tell me if it finds errors and what they are.
     
  14. spadesmamma61

    spadesmamma61 Private E-2

    Alrighty then.

    I toggled the recovery off.
    I ran the scannow twice and both times I had to insert my XP disk. It said it was missing a DLL file I believe.

    Checkdisk took a lifetime to run.

    As best as I could write this is what happened as far as unusual things:


    then after it restarted I toggled the recovery back on.

    Whats next? As of this moment it appears to be running ok but it did that before. Am I in the clear now or do I need to run that scannow again?


    Check that - I just ran SDD again and that Windows.Security thing is back again, apparently its just going to move around my system. :(

    Wasnt sure if you need new MGLog so I ran that again as well.
     

    Attached Files:

    Last edited: Jun 1, 2008
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't tell me how old the computer is...I wouldn't expect errors showing on a chkdsk scan.

    As to your spybot issue:
    See if this is checked: "Allow active content to run in files on My Computer".
    Uncheck it if it is, then reboot and scan again.
     
  16. spadesmamma61

    spadesmamma61 Private E-2


    The above is not checked in my settings. Also, I dont have any toolbars installed on my computer.

    And the computer is 4 months old.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is fine.....and you are ok. It is just an update for security purposes. Not a problem.

    I think it strange that you would have those errors...though the malware could have caused them.....just keep your virus and firewall software up to date and you should be fine. :)
     
  18. spadesmamma61

    spadesmamma61 Private E-2

    OK thanks, one more question. After this infection, my computer quit automatically opening up programs the way it had in the past. Mainly the one where when I attach my Digital Camera a little Wizard would open up and start running or at the very least the Windows prompt that would ask you what you wanted open the file with. Thats gone now. Any way to make this work again?
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That would be a question to ask in the software section.....but let me ask, when you plug in the camera, and open my computer...does it show as a drive/device?
     
  20. spadesmamma61

    spadesmamma61 Private E-2


    Yes, I can access it that way but I dont get the little windows wizard, the one that pops-up like if you put in a CD, if you know what I mean. It will say what program do you want to open this file with blah blah...
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This should be addressed in the software section...it may require a reg. key change.
     
  22. spadesmamma61

    spadesmamma61 Private E-2

    Oki doki thanks for everything :)
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds