Another Computer...

Discussion in 'Malware Help (A Specialist Will Reply)' started by vizarati, Mar 8, 2010.

  1. vizarati

    vizarati Private E-2

    Ok before I get yelled at I know that I do not have logs in this post. Im sorry that I am breaking the rules, but ill explain why. My brother is having major computer problems, when ever he tries to load the internet a box pops up saying something like "Thanks for visiting Grandmas doing ******* for ******" its just a popup that looks like the add to favorites popup in IE(it changes everytime). Hes not sure how this happened it had to have happened during a party and now its messed up badly. I cant connect to the internet on his computer at all with AOL, IE, Firfox and/or Firefox-Safe.

    So I downloaded the programs in the READ me - Link to Windows XP cleaning. Save to a disk and then installed them. I cant connect to the internet or the computer will freeze completely, so I wasnt able to update the definitions. I cant boot into safe mode at all, when trying to enter it it starts to load the disk drives then goes to load window but almost instantly and so fast I cant read it, a blue screen pops up then reboots in a nanosec.. I had to boot in normal mode and undo the wireless card, this allowed me to run the programs as they came from the links. No form of safemode runs btw.

    So main question is this alright for me to do? Will the logs still count when im thru running all of them and if it is I will be attaching them to the next post.

    Thanks and I hope we can fix this. As of now im still running SuperAS, its been going for 42 mins and has found almost 12 things =/
     
    Last edited: Mar 8, 2010
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should have used the instructions we gave you in the READ & RUN ME for performing manual updates for both SAS and MBAM.

    Yes continue on with what you are able to do, note down any errors to let me know of, and get back with what logs you have. :)
     
  3. vizarati

    vizarati Private E-2

    i didnt want to start a new thread but the computer this thread was originally created for crashed completely, tried to get it fixed but the repair shop said the hard drive was gone oh well....

    anyways i have one last computer thats having a problem, mainly when i try to open java popups it takes like 2 mins for them to open and some other minor things, that one being the most annoying one.

    i ran the read me and heres the logs, no errors on this computer, its my personal one and mostly games or bills, maybe talking on yahoo is done on it

    btw the manage attachments button on this site is taking 2 mins to load as well, not sure if its java based or not
     

    Attached Files:

  4. vizarati

    vizarati Private E-2

    and last one
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look clean to me. What actual malware problems are you having now if any?

    Let's just do this, and then I will be giving you final steps soon after.

    Please go to Add/Remove programs and uninstall the following software as requested per the R&R:

    • Viewpoint Media Player

    Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

     
  6. vizarati

    vizarati Private E-2

    ok i removed all of the files in that folder and uninstalled view point again ( i did do in during the RRM)

    major things are java popups still run slow, takes them for ever to open. i have just noticed that there are two new folders in my partion drive that has never been there. they are hidden:

    RECYCLER
    System Volume Information

    when opening this one i get this message

    Media (M:)
    ---------------------------
    M:\System Volume Information is not accessible.

    Access is denied.

    ---------------------------
    OK
    ---------------------------



    it was never there before i dont know whats going on
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well what is drive M? You ran the scans on your C Drive.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Normal.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds