I dont know how, but here we go!

Discussion in 'Malware Help (A Specialist Will Reply)' started by methodryder, Apr 7, 2007.

  1. methodryder

    methodryder Private E-2

    I dont know if my girlfriend downloaded something stupid, or if I did but I am in the middle of a battle right now:

    I am running WIN XP HOME

    I have a little sheild in my system icon tray...it continually pops up various fake error messages indicating:

    registry errors
    spyware errors
    virus errors

    Every once in awhile it will also pop up a browser that takes me to things like:

    winantivirus 2007 or something like that
    registry cleaner 2007 or somethig like that

    blah blah blah

    If I go to right click on the sheild to see what it is it automatically pops up a bunch of errors that try to make me download things

    I have run a few spyware programs over and over to try to get rid of it...no help...lol...while im typing this it just gave me an error too...lol "WARNING YOUr COMPUTER Is AT RISK" blah blah blah...in any case, I am doing trend micro house call scan right now, but who knows how that will work out

    Any ideas, suggestion or thoughts would be appreciated...i would be happy to follow instructions precisely, generate hijack logs or whatever anyone needs to help me, thanks and I will be online refreshing for awhile until i get this sorted out
     
  2. methodryder

    methodryder Private E-2

    Warning, your computer is infected!

    Your registry has been corrupted

    just got that message
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    Well apart from getting rid of the girlfriend and re-formatting your PC... ok just joking! the best bet for you is to start with the below and once finished attach the requested logs to your next posts in this thread.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. methodryder

    methodryder Private E-2

    I will do! Thanks for your help...be back in a few with the results!
     
  5. methodryder

    methodryder Private E-2

    well i went through this stuff...just made things worse...before, at least the computer ran normal...now...well safe mode is SLOWWWW it took 5 hours to complete the stupid counterspy scan...and EVERYTHING is slowed down...now i have an error on startup too:

    Error loading c:\windows\system32\jylqpunx.dll

    ??? now what?
     
  6. methodryder

    methodryder Private E-2

    here's my hijack log
     

    Attached Files:

  7. methodryder

    methodryder Private E-2

    well it appears I have corrected the issue...and I'm kind of suprised at the lack of support I recieved over here...maybe everyone was busy because of the holiday? IDK...i remember a few years ago when I got jammed up there were a million people trying to help and we got it all figured out...because of the limits of posting on other threads I cannot offer any advice but I did notice someone else having a similiar issue so I hope that they or someone will read this post and direct the solution to the appropriate person:

    1st off...the ussual cleaning methods worked, to a certain extent...but to another extent, they created more issues...the malware was removed, but the references in the registry and startup were not removed so there were alot of errors coming up on boot...the solution I ran accross involved a helpful program that I believe should be asses here by someone in authority as it performs a similiar task as hijack, but in a much more user friendly fashion:

    Advanced Windows Care Professional 2.0

    Is available for free download in trial version but is fully functional during the 15 day trial

    Perform a scan

    Resolve all issues, then expand the "startup" issues that are not automatically repaired...then you can inspect the entire startup series of programs...AWC will automatically give recomendations and information based on known and "trusted" startup programs...then it will list the "unknowns"...simply verify the unknowns with what you are running...if you dont know, you can easily check the registry entry...you also have the option of simply disabling the entry or deleting it entirely...if you delete...it will remove the instances of the program itself and the registry entries....easy breazy and beautiful

    for my issue, the startup program causing the majority of the problem was "tcpipmon.exe"

    this is the program that causes the balloon with the invalid popup warnings

    Hope this helps the next guy...i had to work all day by myself on this thing
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's all part of your problems and if you would have attached the requested logs from the READ ME we could help you remove all of your problems. And you probably still have a bunch of them. You have a lot more problems than tcpipmon.exe. Without the logs we requested, we cannot help you.

    You need to have patience. We are extremely busy and it is a holiday weekend! You are getting free support that could easily cost you about $200 dollars at a repair shop. Everyone needs to wait their turn in the work queue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds