com infected, programs cant run

Discussion in 'Malware Help (A Specialist Will Reply)' started by bearx, Jun 22, 2008.

  1. bearx

    bearx Private E-2

    hi, i tried to install a theme for windows and my computer suddenly went crazy. i can't launch any program. not even ie or firefox. it will pop up an error window and avg will show warning of the program that i try to open.

    when i try to restart, windows doesn't load at all. then i went into safe mode, and did a system restore. but it freeze for a long time when it was halfway through. restarted again and this time windows took a very long time to load. system restore didn't complete.

    can anyone help? i'll post hjt and avg logs.
     

    Attached Files:

    Last edited by a moderator: Jun 22, 2008
  2. abri

    abri MajorGeek

    Hi bearx,
    Welcome to Major Geeks!


    It looks like your computer has a lot of malware. Please go through the instructions in the READ & RUN ME FIRST and attach the requested logs. You should see some improvement from the symptoms as you work through the instructions. If you find you can't do something, please make a note of what happened and then continue on until you've done or tried to do everything. When you finish, please use the Manage Attachments button to attach any logs you were able to get and tell us how your computer is working. I've moved your inline logs to attachments as we don't use inline logs here.

    abri
     
  3. bearx

    bearx Private E-2

    done the scans. posting my logs.
    sometimes when my computer screen flashes to black for a second for a few times when i start-up or restart. is it caused by virus or hardware?
     

    Attached Files:

  4. bearx

    bearx Private E-2

    1 more log. thanks. :)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually this can be quite normal. As various applications load ( or unload ) they hook (or unhook ) themselves into Windows Explorer and this can cause the effect you are seeing since they must momentarily kill the explorer.exe process to create (remove) the hooks.

    You appear to have some left overs from Symantec running, but AVG8 is your current antivirus program. We need to get Symantec removed. Please uninstall the below:
    LiveUpdate 3.2 (Symantec Corporation)
    LiveUpdate Notice (Symantec Corporation)

    Now run thisNorton Removal Tool (SymNRT) then reboot your PC and run it one more time.

    Now you MUST put your PC into Normal Startup mode with MSconfig as was requested in step 1 of the READ & RUN ME. You must remain in this mode. After doing this, continue on with the below.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    What are drives G and H? You need to make sure the below files are deleted from them:
    G:\EXPLORER.EXE
    H:\EXPLORER.EXE


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 4, 2008
  6. bearx

    bearx Private E-2

    I can't remove LiveUpdate Notice (Symantec Corporation).
    It shows an error You are attempting to uninstall a program that is required for other Symantec products to run on your PC. You are unable to remove this program at this time.
    So I didn't complete the rest of the steps with Norton Removal Tool (SymNRT).


    fixme.reg
    was successful.

    Drives G and H are my external devices. PSP, iPod eg.
    I just need to delete EXPLORER.EXE the normal way?

    Thanks.
     

    Attached Files:

  7. bearx

    bearx Private E-2

    Can't find the edit button...

    Another question.

    I have Live Messenger on my system start up and it takes very long to load. The volume and Safely Remove Hardware icon appears on the system tray almost immediately, followed by Live Messenger icon.
    But Live Messenger takes around 1 minute to pop up the main window. After Live Messenger is ready, then Local Area Connection and Wireless Network Connection icons appear.

    When I removed Live Messenger from start up, Local Area Connection and Wireless Network Connection also takes about 1 minute to appear.
    May I know what is the problem?
    Thanks.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you should have not run the others either because I needed those other logs after Symantec is removed. Please runt the Norton Removal Tool as requested and thenrun the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the new C:\MGlogs.zip log

    Yes those explorer.exe files from the external devices should be deleted the normal way.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What problem? You said either way it takes a minute. What external hardware do you have plugged in that is causing the Safely Remove Hardware icon to be present. Bootup your PC with this disconnected and see if there is any change.
     
  10. bearx

    bearx Private E-2

    Okay, no more problems now. :)
    Posting new log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean but you really should follow the instructions in step 1 about not using MSconfig like you are using it now.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. bearx

    bearx Private E-2

    My computer seems to have a problem again...
    My brother used LimeWire and experienced the screen flickering, going black.
    It happened for 20 minutes before he manually switched it off.

    Didn't open LimeWire anymore. But sometimes my computer will automatically restart when it boots up to the desktop. The screen will also flicker for a while on start up.

    Can you help? Thanks.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See step 10 of the How to protect yourself link from malware. We advise against using P2P programs.

    It really sound more like you have Windows Operation System or file system problems. We can do a quick check for new problems (this is not a comprehensive check). Run Malawarebytes (make sure you have the new version) and also get the new version of MGtools and run it. Attach the logs from these.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds