removed antivirus trigger, but my progams seem corrupted now

Discussion in 'Malware Help (A Specialist Will Reply)' started by klondike_bar, Dec 26, 2008.

  1. klondike_bar

    klondike_bar Private E-2

    well, on the morning of the 24th, i began getting irritating "your computer is open for attack", "our computer may be infected", "click here to virus scan", etc garbage popups while internet browsing.

    I ignored this cuz i had better things to do on chrismas then virusscannings (stupid move), and within 12 hours, it had progressed to more popups, and then suddenly I found an installation of antivirus trigger and another, seemingly unremovable icon in the system tray.

    my internet would redirect all search site links to popup ad pages, and every 1/4 sites i visited would be blocked because "i was infected". I finally found a site of what registry entries and programs to remove, and followed it after disabling my wireless connection.

    the instructions matched 50% of the files i had, and about 25% matched similar folders and programs. (avirtrig vs avtrg for example). I also renamed/removed 2 dll files that would respawn immidiately if ended in he task manager. (jelediyo.dll and another starting with b)

    upon reboot, the computer would freeze up and not reach the login/finger swipe page unless external power was disconnected(even then, a 30% chance only). No antivirus trigger or other symptos appeared at startup though, and i was able to remove 3 more files with f-secure and clen up the registry a bit with CCleaner.

    another reboot, and the problems appear gone. however, windows media player freezes within 2 seconds of opening (but will finish playing the mp3 you opened (time elapse bar doesnt move) (same with video files). msn wont run when clicked, utorrent will become a process, but not run/open, and internet explorer locks up before it can load the little grey status bar at the bottom of the page/window (with the phishing filters/zooms/etc).

    It is a school (university) loned laptop, wih many of thier own software preinstalled. for this reason, resetting to factor settings is my last resort, even if i can save most of my files first. (school it support takes from 2 days to 2 weeks sometimes)

    any ideas? the laptop appears to work fine, but on closer inpection is almost useless.:cry
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It would have been much easier if you had just come here before doing anything on your own and followed our cleaning procedures. Now we have no idea of exactly what changes you made to your file system or registry on your own. Thus all we can do at this point is suggest that you still run our cleaning procedure to see if any malware remains. After doing that, you may have to work in the Software Forum to address issues with Windows related problems that may remain.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does
     
  3. klondike_bar

    klondike_bar Private E-2

    well, I appeared to remove all of the virus, but within 5 mnutes of trying to reconnect internet, it was back on again.

    when the antivirus trigger is installed, my computer works as normal, except for the virus' effects. when the virus is ESSENTIALLY removed, many programs become lagged, inoperable, or prone to crashing the entire system.

    i removed the program once more, but could not remove the irritating icon in my system tray. A cleanup of MSconfig removed a few startup issues, with no improvement. finally, I disabled all but 3 seemingly essential startup programs and numerous services, with no effect still.

    unfortunately, i am unaware as to my own password (i fingerswipe to logon), and my secondary account appears to not be valid for logging onto safemode. because of XP profesional, i cannot simple bypass like with my MCE or home systems.

    at this point, I am considering a complete abortion of the system, and merely restoring the factory settings from the bios. Ive tested a usb drive (plgged in blank, copied a few megabytes, and let sit for 10 minutes, with no sign of the virus transferring to the drive)

    I think im just gonna backup my essential files and program data before wiping. (due to frequent backups [of documents and media] on a 500gb at my residence, this should be a managable 7-15GB)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless you attach the logs we requested, we cannot help you. You may not have been clean.

    If you are going to restore to factory settings anyway then the logs no longer matter and you should just work thru the below after a reinstall:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds