Another safewebnavigate.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by hollyhock, Sep 17, 2008.

  1. hollyhock

    hollyhock Private E-2

    Hello all,

    Read all the symptoms in this thread: http://forums.majorgeeks.com/showthread.php?t=141133

    and since last night my computer also got affected by this virus. I run MS Windows XP SP2 with Nod 32 completely updated. I had to hard reset my computer, because it didn't respond to anything anymore.

    In short:
    -I'm getting pop ups and that claim to be windows security...
    -I got the big red biohazard splash screen (which I manage to get rid of)...
    -I have three shortcuts on the desktop which I can delete, but will appear again after a restart...
    -I get several popups from time to time, that I have to connect to a certain website to get rid of these viral attacks and stuff (i disconnected my PC from the internet now)...
    -My system files which might be affected are protected now (says Nod 32)...
    -I can't reach the Task Manager (the Administrator says I cannot acces this, so this is also affected, cause the only one working on the PC offcourse is me)...

    Can I follow the same steps that were in the above mentioned thread? Or do I have to post other logs (and how to get these logs) to determine what my exact problem is?

    Greets and thanks in advance.:(
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    You should never do the fix given for someone else's computer!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. hollyhock

    hollyhock Private E-2

    Update:

    Since my computer wouldn't let me startup completely when I disconnected it from the net, I had to connect it to the net. The thing that happened then was that the computer rebooted as soon as it arrived in Windows. So I had to do thing in Safe Mode.

    I toggled on show hidden files, msconfig wasn't also a problem, the settings were correct there. I could not delete old Java-stuff, as I didn't have the privilege of an Administrator.

    As mentioned, first I did CCleaner in both administrator and my own username (safe mode).

    After that it didn't startup in normal mode again, so from step 3 onwards, still doin some of the things in safe mode.

    The first tool I tried was SauperANTISpyware, but it didn't let me install the program, cause of the non-administrator mode I was in. Even in safe mode, administrator mode. I will try this one at a later point.

    Spybot Search and Destroy got updated and ran a full scan. There were quite a lot items in my PC infected, and Spybot got rid of it. Except for 4 items. He said he would remove them as soon as I restarted my PC. But restarting also became some sort of problem. It seems to keep hangin on the welcome screen, but when I toggle a bit, I get into the small Spybot screen. Run a scan again, but still not sure If he deleted the items. It's difficult to say, because it really had problems at the moment to start up, even in safe mode sometimes.

    Between this I tried to install Superantispyware, but it still didn't let me.

    The next thing I did, is try to startup as normal as possible. It came into Windows, but rebooted again immediately. As far as I could see most of the items I saw when the malware was around, disappeared. But it got night already, and had to begin early (now) so that's why I stop trying to fix the problems for the moment.

    I will move on this afternoon when I get back home. I'll do another Spybot run just to be sure.

    keep you posted...
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just because one thing does not work...continue on with the rest.

    I need at the very least the C:\MGLogs.zip from running the C:\MGTools.exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds