Browser hijack, computer freezing, McAfee disabled

Discussion in 'Malware Help (A Specialist Will Reply)' started by ello, Mar 29, 2009.

  1. ello

    ello Private E-2

    Hello!

    Dell Inspiron E1505 running Windows XP Media Edition. Computer freezing up and unable to shut down. Firefox redirecting to sites like 'Stopzilla' and 'Webroot'. McAfee disabled.

    Was only able to run cleaning procedure in Safe Mode. SuperAntiSpyware and Malwarebytes ran OK. Could not download or run Combofix or access bleepingcomputer. MGtools continually gave error "C:\WINDOWS\system32\cmd.exe HLVDD.DLL. An installable Virtual Device Driver failed Dll initialization." Clicked close and it reappeared multiple times until I finally just shut it down.

    Thanks in advance for your help!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not allow MGTools to run to completion. You need to make the agreement for HJT and let it continue until it tells you it is finished.

    In the meantime, lets just do this until you get me a new MGLogs.zip

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  3. ello

    ello Private E-2

    Hi Tim, thanks for your help!

    When I ran MGtools initially I received the same error message about 10 times so shut it down. I'll be happy to try running it again.

    Ran fixME.reg in safe mode but no success message. Tried again in normal mode and received message 'Dr. Watson Postmortem Debugger has encountered a problem and needs to close.' Rebooted and tried again and received no message at all.

    Double clicked on GetLogs.bat but the .zip file did not update. Tried attaching just in case but forum would not let me.


    btw Monday I was able to DL ComboFix from another computer but nothing happened when I ran it. Also, I have to work in Safe Mode as my computer will freeze in normal mode.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Using MGtools link given in the READ & RUN ME explains several types of error messages that may occur. Yours was explained there in Error Message Type 2 which you need to apply.
     
  5. ello

    ello Private E-2

    Regedit won't open in either normal or safe mode. (typing 'regedit' in the run box)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try downloading and installing this RegLite

    If it installs and runs, use it to make the changes.
     
  7. ello

    ello Private E-2

    Virus removed. Thanks for your advice.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds