can't run AV, can't get clean...

Discussion in 'Malware Help (A Specialist Will Reply)' started by chopperboi89, Oct 23, 2009.

  1. chopperboi89

    chopperboi89 Private E-2

    So, I don't know how it got on my laptop, all networks I connect to are all secure. But there is some kind of virus/adware/spyware, I'm not sure witch one, I get a pop-up every now and then, also when I turn it off, I need to let it start, a notice comes up saying windows will shut down in one min. Then I shut it down holding the power button, when the option shows on the screen, I start in safe mode, let it load, run in safe mode for a bit, then restart windows and run normal; if that doesn't work, i have to format to an earlyer point. From then on it works fine. Windows defender will come up saying it detects a virus, and asks me what to do with the virus, I select "remove" and then it takes a second, then says "actions taken: quarantine." There is something with the virus blocking malware bytes, and super anti spyware, when i try to run them, i get a notice saying "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item." I get the same notice when I right click and "run as admin."

    Running:
    Toshiba Satellite
    AMD Athlon x2-64
    ATI Radeon graphics
    System NTFS Hard Drive; 222GB
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:

    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools

    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. chopperboi89

    chopperboi89 Private E-2

    Well, here's the only one I could get, I had to restart when i was setting up to use "MGtools." Now I cant run windows normally, I'm stuck using "safe mode." When I start windows normally, I get a message that comes up that basically says "windows has encountered a problem and will restart in one min." So at this point I'm at a total loss of what to do. I ran "http://www.superantispyware.com/onlinescan.html" and it found 14 ad-ware, and removed them, but that didn't really do much after that, I restarted then, and it took me a bit to get it to run normal windows, but then I got to where I am now... :cry
     

    Attached Files:

    Last edited: Oct 27, 2009
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why did you have to restart when you were setting up MGTools? All you needed to do was install it. Then let it run to completion.

    Is it installed now? Can you run it?

    Exactly what happens?
     
  5. chopperboi89

    chopperboi89 Private E-2

    Well, it wanted me to change the UNC setting or something like that, something that needed admin. approval, and now the problem has changed, I couldn't even get it to start in safe mode, so I had to run a windows system restore (witch took a few forced system shutdowns holding the power button, turning it back on, then forced shutdown again), witch was stupid because the recommended time to restore to was just a few hrs. before I had the problem starting in safe mode (the most recent problem), so I'm currently compressing files and e-mailing them to myself so I don't lose them, and if I'm still having problems in the near future, I'm doing a full system restore, and the 1st thing I'm getting is malwarebytes (I didn't know of the program, or this site until a friend of mine told me about it, and I was already having problems then.)
    :banghead:***:cry

    The program is not on the computer due to the forced restore I had to do
     
    Last edited: Oct 28, 2009
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I would suggest that since you have done a restore, you should go back and follow the Read and Run First instructions and attach the requested logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds