maleware or virus blocking ALL security functions

Discussion in 'Malware Help (A Specialist Will Reply)' started by crimsonarc, Nov 11, 2009.

  1. crimsonarc

    crimsonarc Private E-2

    I have been hit with something that has taken over all my ability to open or access any anti-virus or security system. I understand about reading and following the basics for house cleaning and READ AND RUN me first ( I did return my MSconfig to normal start-up mode ) but my problem is that I cant even ACCESS my SUPERAnti spyware or highjackThis to post a log ( I am able to download the trial version of malewarebytes for scanning but I'm not in a position to make the purchase for anything beyond that ). and I cant even OPEN windows security center after having closed it for something I was doing. I was using SUPERAnti spyware for an analysis and removal and it found 23 objects ( trojans and more stuff ) and it said at the end they were successfully removed. when I tried to re-enter the SUPERAnti spyware program it said - windows cannot access the specified device, path or file...you may not have the appropriate permission to access these files - so I'm assuming its a virus or maleware or a problem with having left the MSconfig to run start-up and then uninstall a program and as the basics said ' leaving behind faults, errors or malicious material ' . do I need to cover more basics or is this a genuine problem I need help with?

    my specifics : dell inspiron 1525 laptop / 32 bit system / LAN ( no wireless used ) / logged on as administrator / windows vista home basic / downloaded most recent critical updates from microsoft security ( yesterday ) / windows firewall ( on ) / novice computer user.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We don't want or ask for a HijackThis log anyway since it is not going to help you.


    Let's see if we can get some info so that we can determine which system file has been corrupted. That way we can try to replace it. Please work thru all steps below and report back later. DO NOT stop if any particular step does not work.

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post)


    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools

    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • c:\avplog.txt
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. crimsonarc

    crimsonarc Private E-2

    AVPFind.bat - blocked or stopped running cant find anywhere on my system

    malewarebytes anti-maleware downloaded but instantly stopped scanning when started, when try to re-access it from desktop I get the same - windows cannot access the specified file, device or etc. - message.

    MGtools was also instantly stopped when it appeared. its on my system but I cant access it.

    did get one file report, couldnt find it to upload so I copy/pasted it :

    {\rtf1\ansi\ansicpg1252\deff0\deflang4105{\fonttbl{\f0\fswiss\fcharset0 Arial;}}
    {\*\generator Msftedit 5.41.21.2509;}\viewkind4\uc1\pard\f0\fs20 exeHelper by Raktor\par
    Build 20091021\par
    Run at 08:22:45 on 11/14/09\par
    Now searching...\par
    Checking for numerical processes...\par
    Checking for bad processes...\par
    Checking for bad files...\par
    Checking for bad registry entries...\par
    Resetting filetype association for .exe\par
    Resetting filetype association for .com\par
    Resetting userinit and shell values...\par
    Resetting policies...\par
    --Finished--\par
    \par
    }

    also I'm getting a ( supposed ) microsoft security update everytime I connect to the internet now ( 15 so far ), kind of strange it could be malicious because it has the same code everytime. here it is :
    windows malicious software removal tool -November 2009 (KB890830 )
     
  4. crimsonarc

    crimsonarc Private E-2

    I was able to get the perflogs attachments after all hope their here. if not I'll try again.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    log.txt should be wherever you ran exeHelper.com from.


    It is probably valid. You probably are not able to properly get the updates installed.


    I have no idea what you are referring too.

    What version of Windows (including Service Pack) are you using?
     
  6. crimsonarc

    crimsonarc Private E-2

    windows vista - service pack 2. I'm also a little concerned about the windows security update downloading everytime I connect to the internet, does that put the 9 mb its rated as on my system everytime and accumulate over time bogging down my OS? the point I'm trying to make is that everything I tried you asked me to do was more or less cut off by ' something ' directly interfering with a security related scan. so is this something that is not normally able to be addressed by normal means or do you need more info or can we go in another direction? or should I just do a system restore?

    I cant find what your asking me to find. tell me where to look ( for example : start - computer - etc. / start - control panel - etc. ) ( which is what I'm saying - it may not be there at all ) all I could find other than the paste/copy of the last reply is exe.helperlog 2 that I hope I got on attachments, if not here it is :

    exeHelper by Raktor
    Build 20091021
    Run at 08:22:45 on 11/14/09
    Now searching...
    Checking for numerical processes...
    Checking for bad processes...
    Checking for bad files...
    Checking for bad registry entries...
    Resetting filetype association for .exe
    Resetting filetype association for .com
    Resetting userinit and shell values...
    Resetting policies...
    --Finished--
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No.

    There are dozens of forms of this particular type infection and what we are doing is trying to determine exactly which particular problem so that we can attempt to fix. The malware constantly evolves and learns how we fix it and then changes to block what we run. You could try using system restore but some forms of this malware block system restore. In addition, if system restore runs, it will not fix all the problems caused by the malware. If may only mask some of them and you may think things are okay when they may not be. Give it a try and report back. If it does run, it could help us to start making some progress.

    Also in preparation for what we may be doing next, please do the below.

    • Disable or uninstall your antivirus program which will get in the way of performing the fixes.
    • Download the below files and make sure that you save them to the C:\Windows folder. They must be save here or steps I may need to give next will not work as I need to know EXACTLY where they are saved.
    cngaudit

    netlogon

    scecli
     
  8. crimsonarc

    crimsonarc Private E-2

    I downloaded the three files you wanted me to to : Computer - OS (C:) - windows -

    ( it says those three files are there but I cant find the titles on the windows list ! ) saved as DLLMG type file help? I saved them to : genxie - documents
    as well in case you couldnt find them.

    and I did try a system restore but it seemed to only DO a system restore for the day I did it, I'm not sure what I'm supposed to do after that or how to use it. I would have liked to go back 20 days or so when my computer wasnt infected, but I was only given 4 or 5 days back as options unless I didnt see a scroll there ...
    ( looked hard - nothing ).
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter cmd into the box and click OK. This should open a command prompt window. Copy the below bold black print commands into the run box and hit enter after each one. The bold purple part is just informational for you.


    cd C:\windows <= there is a space after the cd. The prompt in the window should change to C:\WINDOWS>

    dir > C:\flist.txt <= there is a space after the dir

    dir /s C:\mgtools >> C:\flist.txt <= there is a space after the dir , and after the /s and before the >> And yes the >> is correct.


    Now you can close the command prompt window.

    Attach the C:\flist.txt file to your next message.
     
  10. crimsonarc

    crimsonarc Private E-2

    response is - access is denied - for what you asked me to copy or watch for ( and for the last one as well )
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the first command succeed or is it denied?
     
  12. crimsonarc

    crimsonarc Private E-2

    I'm sorry, yes the first one does succeed, it does change to what your looking for.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's try changing the second two to the below.


    dir > flist.txt <= there is a space after the dir

    dir /s C:\mgtools >> flist.txt <= there is a space after the dir , and after the /s and before the >> And yes the >> is correct.


    If this works the log file will be located at C:\Windows\flist.txt
     
  14. crimsonarc

    crimsonarc Private E-2

    access is still denied on the last two.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if it is denying using the dir command or creating the file.
    Just type dir at the command prompt and hit enter. Does it show a directory listing or is it denied?
     
  16. crimsonarc

    crimsonarc Private E-2

    the directory is listed.
    do you want to see it? how do I get it to the forum reply, I cant copy and paste it.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you can but it will probably be very long. If you right click in the command prompt window you will see that you can Mark, Copy, and you can Paste. But after marking, you will have to right click on the top bar of the window and use the Editing commands to copy.

    When you first open a command prompt window (open another one) what is the exact word for work prompt you see? It should be something like below. Where username is the user account name being used.

    C:\Documents and Settings\username>
     
  18. crimsonarc

    crimsonarc Private E-2

    after the ' copyright - microsoft etc. - all rights reserved etc. - the next line below is

    C:\ Users\Carin>_ ( with that last symbol the flashing cursor )

    the name Carin is the previous owner, I tried to ask dell to convert the warranty but they wouldnt without having the full name and the store where I bought it second hand wouldnt release the full name for customer privacy. buts its never been an issue for the last, what 10 months now and the warranty just expired last month anyway. the guy at the store said my new user name would be the admin and that has been my experience, when I did a test that someone suggested to determine if I did have admin rights by attempting to change the settings on the clock it all worked well.

    do you still want me to try and get the directory list as you described?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's right!!! I forgot you had Vista.

    First let's see if we can write to the Carin folder.

    In the command prompt window just opened that shows the C:\ Users\Carin> prompt, try the below to see if we can create the log files.


    dir C:\windows > flist.txt <= there is a space after the dir

    dir /s C:\mgtools >> flist.txt <= there is a space after the dir , and after the /s and before the >> And yes the >> is correct.


    Attach the C:\ Users\Carin\flist.txt file to your next message if the above commands work.
     
  20. crimsonarc

    crimsonarc Private E-2

    the two lines you gave me were not denied but the third response was only another - C:\Users\Carin> - response looking for another command prompt.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean the third response? I only gave you two commands to run. The last item is for you to attach the log here. See: HOW TO: Attach Items To Your Post
     
  22. crimsonarc

    crimsonarc Private E-2

    I press enter after each command and the response after the second command is another C:\Users\Carin> just below it as if it is waiting for another command.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that's correct. The prompt is always the same.

    You just need to attach the file now.
     
  24. crimsonarc

    crimsonarc Private E-2

    I tried the attachments, looks like its there.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay apparently you did not successfully get those files copied into the C:\Windows folder. Probably for the same reason we could not create the flist.txt file there. However MGtools did run far enough to create its folders and files. Let's try the below. I'm signing off for the night in a couple minutes. I'll get back to you later in the work queue (been working with you out of queue order tonight to check to see if we have some kind of new infection to learn about).





    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\avenger.txt
    • the Win32kDiag log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 23, 2009
  26. crimsonarc

    crimsonarc Private E-2

    thats quite a bit, so I'll stop for the night as well...be back with a report tommorow morning sometime, say between 9 or 10am PST. i've never encountered a virus or malicious attack that counteracts every attempt to run a security scan or even to access such a program, so yeah it could be something different. hey thanks alot for all this! i appreciate the help, I may go a bit slower than a pro but I'll get there.
     
  27. crimsonarc

    crimsonarc Private E-2

    got as far as downloading the avenger tool and opening the command box and - input script here - copy and pasted everything in the quote box and pressed execute. the response was - invalid script. a valid script must begin with a command directive - aborting execution.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it now. It was late and there was no carriage return after the Files to move:

    Also make sure that you only copy what is in the box and not the Quote: line.
     
  29. crimsonarc

    crimsonarc Private E-2

    the second attempt worked on the first instruction and I got the notepad report after rebooting, then went to download the Win32kDiag but I interpreted the - must save it here - as the ' C:\ ' meaning Computer - OS (C:)
    and it said I didnt have permission see the administrator or would you like to save it to the Carin file? is that the ' C ' ? the Carin file or should it only go to Computer OS (C:) ? I'm asking because the - must save it here - sounds like a one time attempt so I'd like to get it right.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay since you still cannot save to the root folder, try it the below way.

    Download and save Win32kDiag to your Desktop

    Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK.

    "%userprofile%\desktop\win32kdiag.exe" -f -r

    When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log to your next message.

    Don't forget to attach the other logs too.
     
  31. crimsonarc

    crimsonarc Private E-2

    cant find the - C:MGtoolsbatlogfile. are the other two the right ones?
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that fixed a bunch of problems. Don't worry about the MGlogs.zip file for now. Just do the below.



    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    Now see if any of the below can be run from the READ & RUN ME:
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    If any run, attach the logs from them.
     
  33. crimsonarc

    crimsonarc Private E-2

    found - C:\MGtools\GetLogs ( no .bat at first then there was after I ran it ) ran as admin.

    the zip file would not upload - says it is invalid.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because othe steps from the READ & RUN ME about enabling viewing of hidden files was not completed....... at least not properly. GetLogs.bat tries to correct this automatically.

    You mean the C:\MGlogs.zip file? Don't worry about it for now since you still have problems writing to the root folder. Complete my other instructions.
     
  35. crimsonarc

    crimsonarc Private E-2

    I just uploaded that last reply as your most recent reply was coming up almost at the same time, I was able to comlete the MGtools\FixPerm.bat process and had about 5 or 6 ' OK ' windows pop-up. the prompt screen ( empty ? ) closed and I was able to download superanti spyware ( progress..I couldnt even access it before ) from run not save but I wasnt given the option of RUN AND READ ME from anywhere. I'm running a quick scan of my system, is this right or did I miss something, if so where is the RUN AND READ ME ? turn off the quick scan? ( it takes a while from past experience )
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm referring to what you even mentioned in your first message, and that is the READ & RUN ME FIRST cleaning procedure. It is one of the required reading sticky/pinned threads.
     
  37. crimsonarc

    crimsonarc Private E-2

    took a while to go thru the READ ME FIRST area, but I remember most of it at the beginning...sure I got all of it. did the three scans.

    superanti spyware - nothing found.

    and I'll include the two others and logs in this reply.
     

    Attached Files:

  38. crimsonarc

    crimsonarc Private E-2

    I should mention that my typing as text is jumping around ( a portion of a word I'm currently working on will show up in the line above what I just wrote intersecting another word randomly. it looks like the cursor ). anything to look into or may have come about as a result of the 3 scans ? perhaps something was affected in the removal / reboot?
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now make sure that UAC has been disabled and that you have rebooted after it is disabled ( you don't need to reboot if it was already disabled unless you have never rebooted once after disabling it). Disable any protection software too.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  40. crimsonarc

    crimsonarc Private E-2

    uploading the MGlogs.zip...if things work out can I get rid of all that new stuff cluttering my desktop since I began this process or do they need to stay for now? also the USB I use all the time during my problem is it infected or not ? ( mostly pictures some text documents ). seems like the typing cursor stopped jumping around too!
     

    Attached Files:

  41. crimsonarc

    crimsonarc Private E-2

    I forgot to say can I turn my UAC on back now? and also the most important thing of all...thank you for all your kind help in case you have moved on, my computer runs altogether better ( the point being I can access my security systems ) and this process even fixed some old problems.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just one more thing to do and then final steps which should address all your questions and will get you properly protected.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

    After clicking Fix, exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  43. crimsonarc

    crimsonarc Private E-2

    in terms of your last instructions I got as far as - go to add/remove programs and uninstall HighjackThis - I cant do so because I remembered last week before you started helping me I fiddled with changing the admin user rights as an experiment to see if I could, and there is something about resetting the profiles of that process before I can change them again? ( I set the admin rights from admin to genxie, my username - now it cant be uninstalled ) is there a process for resetting the security profiles you can advise me on or getting it back to admin rights?
     
  44. crimsonarc

    crimsonarc Private E-2

    as for my last reply, it was under the subject - how to take ownership of a file or program - that someone earlier advised for me to do, and i didnt realize my computers' problems were deeper. hope I can still re-access HighjackThis and put ownership back to admin. ( I changed it to C:\Carin not genxie ).
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  46. crimsonarc

    crimsonarc Private E-2

    it says do not run instructions if I have other than - windows 2000 / windows server 2003 / or XP - I have vista. still go ahead with it? it also sounds like if i dont get the process right it could cause a problem. is it strictly a registry issue or can I tackle it another way?
    originally I was presented with a pop-up window that said to reset my security profiles for the program if I wanted to re-access the program or alter it again, I didnt so was that a one time thing or can I try to do it again by going into HighjackThis and trying to modify it? or is that the point ; I cant now without re-setting the registry?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I forgot you had Vista. Just do the below. Not sure if you already removed Avenger so I will repeat the instructions for downloading it.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now continue with my finalinstructions at step 7.
     
  48. crimsonarc

    crimsonarc Private E-2

    went thru 7-8 on the last instruc list. went well. looked over 9.

    the HighjackThis is still on the add/remove programs list and desktop but I'm assuming its not in the registry where it counts, just leave it?

    with the hardware firewall, where do I access it to see if it's on ond create password for it etc. ?

    with the software firewall, it would seem part 9 gives me the option of downloading one from the net or staying with windows firewall but not both. I'd just like to stay with the windows one, can I call the windows firewall enough?

    everything else on part 9 I've either done or will do without any further help.

    and the last question is about that USB flashdrive I mentioned where all my important pics and text documents are that was used during the ' problem time ' ... is that going to re-infect my PC? or is it OK to use, whenever I want now?
     
  49. crimsonarc

    crimsonarc Private E-2

    forgot to ask : part 9 said that if i wanted to download AVG free not to run another anti spyware... I have superanti spyware now ( free version ), so get rid of it and run only the AVG free ( as it apparenty has the anti-spyware ability ) ?

    or keep superanti spyware and get another anti-virus program other than AVG?
     
  50. crimsonarc

    crimsonarc Private E-2

    also that microsoft update ( windows malicious software removal tool - november 2009 KB890830 ) keeps trying to install but either cant or is doing so everytime, is that a problem or something that microsoft cannot make a connection on my computer for some reason?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds