Big Problem(s)!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mntsitalons, Jun 29, 2008.

  1. mntsitalons

    mntsitalons Private E-2

    Here's what's been going on:

    A few weeks ago my computer started running extremely slow. My CPU usage was constantly 100%, so I ran McAfee's virus scan and found nothing. I also ran a few other programs but was unable to find anything (maybe I was looking in the wrong places). I finally got to the point where I used my restore discs that I recieved with my computer.

    I cleaned (or thought) everthing so that it was the same as when I bought it. This has always fixed any problems I've had in the past, but not this time.

    When I try to run hijackthis it says "runtime error 481 invalid picture" it also says the same thing when trying to run adware and spybot. It works in safemode but everything seems to run fine in safe mode and I can't find anything in safe mode.

    I've also ran msconfig and disabled all startup exe's and I get a message telling me I don't have administrator rights. I only have 1 user set up and when I go to the user settings it says I have admin rights. NOTE: I can only get to the user settings in safe mode.

    I'm not able to install any active x so I can't run online scanners. When I try to start my viruscan it doesn't start.

    I'm extremely frustrated, can anyone help please???
     
  2. abri

    abri MajorGeek

    Hi mntsitalons,
    Welcome to MajorGeeks!

    See if you are able to go through the instructions in the READ & RUN ME FIRST. Most of the scans can be done in SafeMode, so if this is your own possibility, start there. If you can get any of them, in particular the MGTools to run in Normal Mode, that would be helpful. Attach any logs you get with your next posts. When you finish those instructions, please do the following and then attach that log as well:


    Running GMER to detect rootkits

    Thanks.
    abri
     
  3. mntsitalons

    mntsitalons Private E-2

    Alright I was finally able to get some of these programs to work. It seems to be working better now, it found 3 tracking cookies. Spybot also found 3 corrupt files.

    I'll attach the files that the MG program created.
    Do you see anything wrong? Thanks for all the help.
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi mntsitalons,

    Something put a lot of files into your computer on June 17th and I wonder if this had to do with Zune? In any case, please go to the following two directories and delete all the files Windows will allow you to delete. You may have to do them a few at a time to start with and please note, that you will not be allowed to delete files with the current date. That is normal.

    C:\Documents and Settings\Keith Velishek\Local Settings\Temp\
    C:\WINDOWS\Temp\


    On the basis of just your MGlogs.zip, I don't see any malware in your computer, but I do see that Spybot's Teatimer is enabled. This will prevent any changes being made to settings on your computer, which is a problem if someone is trying to help you fix things. To deactivate Teatimer, please do the following:

    Disabling Spybot's TeaTimer can be done two ways.
    First:
    • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
    • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
    • If you have Version 1.4, Click on Exit Spybot S&D Resident
    or Second, For Either Version :
    • Open Spybot S&D
    • Click Mode, choose Advanced Mode
    • Go To the bottom of the Vertical Panel on the Left, Click Tools
    • then, also in left panel, click Resident shows a red/white shield.
    • If your firewall raises a question, say OK
    • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
    • OK any prompts.
    • Use File, Exit to terminate Spybot



    After you finish the above, please run CCleaner at the default setting with the Windows tab as the one on top.

    Then try to go through the rest of the scans in the READ & RUN ME FIRST
    and attach the requested logs of any you are able to complete. The last log will be a fresh copy of the MGlogs.zip which you will get by double-clicking on the file C:\MGTools\GetLogs.bat

    Thanks.
    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds