Safeshield virus/sytem restore/safe mode problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ricey, Nov 14, 2009.

  1. Ricey

    Ricey Private E-2

    Hello.
    It has been a while since I needed your help... had to re-register :)

    Firstly, i have been having probs with my comp for a while. Slow performance, slow to boot ETC.
    I use NOD32 and it found a virus but could not delete it. My comp was contiuallly being attacked but NOD managed to block it all. I have been thinking of returning my comp to its manufactures settings becuase I dont really have too much data too loose that will cause me any grief. My comp is 3 years old now and there is so much rubbish on it, I dont know what I need and what I dont..... Bloody kids :)

    Anyway, I boot my comp this morning and up pops an activation page for safeshield antivirus and a red cross on the tray saying my comp has been infected. The activation page pops up every cople of minutes. I had a problem like this b4 and u guys sorted me out (Thanks :) )
    My NOD32 icon is missing from the desktop and it does not seem to have loaded. I go to all programmes/ESSET and it tells me NOD cant comunicate with the kernal.
    I run anti-malaware and it finds 4 objects but freezes when I hit remove them. I look around the net and learn that I should be able to remove this by starting in safe mode and running anti-malaware. I reboot my comp and hit the f8 key but i dont get an option to reboot in safe mode :confused
    I get three options of drives with which to boot,,, 1)floppy, 2) dvd rw or 3)hdd and some numbers (Can give more acurate info later if needed).

    I then think B******S to it and decide to restore my comp to original state which hopefully will improve its performnce and solve my problem. So i go to system restore and the bloody thing wont run.
    I get the message "System restore cannot protect your comp.... please restart and try again"

    So here I am once more, with begging cap on, can you help?

    NOTE: Im not very computer literate so it'll have to be in "Computer Dummies" language.

    TY in advance
    Ricey.



    PS .... these are the 4 items found by malaware.
    Trojan.agent File c:\windows\msacm32.drv
    Adwarwe.playmp3z Registry key hk_current_user\software\medi....
    Fake.Beep.Sys File c:\windows\system32\drivers\beep.sys
    Malaware.Trace Registry Value key_local_machine\software\micro ...Value: UID
     
  2. Ricey

    Ricey Private E-2


    UPDATE .. Itried deleting these one at a time.... It deleted 3 but freezes when i try deleting the last one ... Malaware.Trace Registry Value hkey_local_machine\software\micro ...Value: UID

    NOD32 still not opening -(
     
  3. evilfantasy

    evilfantasy Malware Fighter

  4. Ricey

    Ricey Private E-2

    Thank you for the welcome and your response.

    Since my original post, I have attempted to clean my comp a little, but it was not untill today that I could get the malaware programmes to delete the items they found. They both froze when deleting the items. However, I continued my efforts and they eventually worked.
    I have attached the logs for Super anti spyware and malaware. My comp now seems free of malaware but NOD32 is still not operating correctly.
    I uninstalled it and re-installed it and I have chosen the "repair" option too. But on the protection status page it says.....
    Analysis of application protocols will not function
    An error occured while starting services. Analysis of application protocols (POP3, HTTP) will not function.

    (NOD32 is still updating though).

    After running super anti spyware and malaware sucessfully, I went to the next step of running combofix. However, it reboots my computer when it reaches "Complting stage 50" and there is no log. A pop up announces that the system recovered from a serious error.
    I decided to post for your advice before running RootRepea and MGTools, although it wont take me long to do this if you need me too.

    TY in advance.
     

    Attached Files:

  5. evilfantasy

    evilfantasy Malware Fighter

    Without all of the logs from the READ ME (that you can get to run) we can't help. We need the logs...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds