Comp going crasy with vir warning

Discussion in 'Malware Help (A Specialist Will Reply)' started by JohnNitro, Nov 12, 2005.

  1. JohnNitro

    JohnNitro Private First Class

    Man my comp it freaking out. I have all these virus warnings, like(adware Generic.BUO) things and other .something(.DNS,DNU,etc...) but most of the paths are C:\PROGRAM FILES\mywebsearch\bar\3.bin\.(different lettters here)dll, exe. And some are screensaver paths, I did a scan and healed them but my comp still get them I got it when I try to open something, and I did a system restore but the virus stuff was still there but it fixed a something that was wrong with the net( all the letters looked big) I tried downloading a download manager but once installed all these error messages appeard. that the DAP cause a error with this and that. Can anyone help me restore my lab top to a regular running order. I thought about formating since all that is on the lab top is things I downloaded, but I dont ahve any disc or books for it. All I have and know it the power cord and the cord that connects to the net and the cerfti. of Autenticity. its on a sticker on the bottom of this comp. Please someone help me quick.
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis
     
  3. JohnNitro

    JohnNitro Private First Class

    I did the steps and I dont see no more messages and a lot od adware stuff was fixed I guess, I restore system restore and unchecked enable start menu so I reboot normal, but now it seems the pc is slower. It loads slow when restarted, the system tray icons don't load as fast as they did before.

    this is the hack this log:

    This is the counter spy results, on the guide it said it did not say not to fix, but I pressed the take action buttom and it did as recommemded, this were the results:



    So is there anything you can tell me especially why my pc is loading at restart so slow.
     

    Attached Files:

    Last edited by a moderator: Dec 28, 2005
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Go back and follow directions. You have not run either of the requested on-line Antivirus scanners.

    Logs are not to be posted inline, they are to be posted as attacments. If for some reason they won't attach then let us know in your post. I will attach them.

    Post the logs for BitDefender and Panda ActiveScan along with a fresh HijackThis, once you a completed the tutorial, don't skip any steps.
     
  5. JohnNitro

    JohnNitro Private First Class

    oops sorry didnt see that part ok these are the panda and bitdefender logs.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix the following:
    REBOOT to Safe mode.

    Open Windows Explorer, navigate to and delete the following:
    Reboot to Normal Mode.

    Post a fresh HijackThis log.

    How is your computer running?
     
  7. JohnNitro

    JohnNitro Private First Class

    how do I fix with hjt, and about the fiestabar it a with ads and it gives you points for the time you have it open, do I still delete the fiestabar stuff.

    Ill do the HJT.
     
  8. JohnNitro

    JohnNitro Private First Class

    O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
    O4 - HKCU\..\Run: [CashFiesta] C:\DOWNLOADS\CASHFIESTA.EXE

    only deletes ZTServerSwitch atm, waiting to see what you say about fiesta bar.
     
  9. JohnNitro

    JohnNitro Private First Class


    have no idea how to do what you just asked me, to get to windows explorer I right click start right? But from there I dont understand how to find the above items
     
  10. JohnNitro

    JohnNitro Private First Class

    ok done, idelete all except the cashbar and fiesta items.
    here the HJT log
     

    Attached Files:

  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    These are undesirable applications, and something you don't wont on your system. http://vil.mcafeesecurity.com/vil/content/v_131121.htm

    CashFiesta generates pop-ups on your system while browsing.
     
  12. JohnNitro

    JohnNitro Private First Class

    Sorry I never said Thank you. You helped a lot. I installed the fiestabar, because they give youmoney for letting the pop up so up. Regarding the waring I dont see them anymore but my laptop still runs a slow, but not all the time. When I reboot, it runs fine but after a while it starts to slow down, the pages load much slower. So thats my only complaint, is there anything to do for that or do you think its still the adware this slowing it down?
     
  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You still have adware and spyware on your system.

    Run CCleaner before doing the below.

    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
    They are paying you, to let them infect your computer with Spyware and Trojans?

    http://www.securitystronghold.com/gates/spyware-adware-solutions/CashFiesta_Cashfiesta.exe_solution.htm
    http://www.bleepingcomputer.com/startups/Cashfiesta.exe-10309.html
     
  14. JohnNitro

    JohnNitro Private First Class

    should I report that to them?,, ok I run cc and then the program you said. post when Im done.
     
  15. JohnNitro

    JohnNitro Private First Class

    ok heres the log.
     

    Attached Files:

  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    They know, because they're the ones that put the spyware and trojans in the software.
     
  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Copy & paste the contents of the below quote box to notepad and save as FixReg.reg to you desktop.
    Exit notepad, double-click FixReg.reg and answer 'Yes'.

    Next scan with HijackThis and fix the following lines:
    REBOOT to Safe Mode.

    Open Windows Explorer, navigate to and delete the following:
    REBOOT to Normal Mode.

    Post a fresh HjackThis log.

    How is your computer running?
     
  18. JohnNitro

    JohnNitro Private First Class

    so you dont think Ill get any money for it?
     
  19. JohnNitro

    JohnNitro Private First Class

    it said it couldnt import the file is not a regisrty scritp.
     
  20. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Sorry.

    Use the above.
     
  21. JohnNitro

    JohnNitro Private First Class

    so I just make a notepad of this and then the steps below, also what about a registry cleaner. I tried teh reg mechanic but since it a pay one it only did a little bit, but I notice 2 that looked ok to me here so I downloaded them but have not installed then. what do you think should I install them. On is tweaknow regcleaner and the other is regcleaner.
     
  22. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Follwo teh previous procedures with teh fix I posted.

    Don't run any tools I don't ask you to run.
     
  23. JohnNitro

    JohnNitro Private First Class

    oh ok, sorry so should I restoer what i did, Ill do that and just continue from where we left off.
     
  24. JohnNitro

    JohnNitro Private First Class

    sorry has ran the registry mechanic but it had a restore feature so I restored all that it removed, but it didnt seem to make a diff maybe a little. Ok I did what you said I delete the stuff.
     

    Attached Files:

  25. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  26. JohnNitro

    JohnNitro Private First Class

    that was one of the things that the registry mechanic fixed.... Ok so now Ill fix those. You know so far its not running better it still slow on start up and the smc sometime doesnt responed. But at least I havent had any virus, but I sometimes get a error about the kernal.dll, like explorer cause a errror in kernal.ddl.
     
  27. JohnNitro

    JohnNitro Private First Class

    ok delete the items you said should I restart my pc or anything like that????
    its running same as before from what I can see. I just defrged and ran ccleaner and adware and spybot, all clean :), but dont notice a change. but we will see Im hopeful :)
     
  28. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Try a different firewall. What
    does that do for your system performance?
     
  29. JohnNitro

    JohnNitro Private First Class

    I use sygate personel firewall...after I rebooted it seem to be running ok. :)
     
  30. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    FYI. SPF is a discontinued product, and will no longer be supported by Synmantec. You may want to consider changing firewalls in the near future.
     
  31. JohnNitro

    JohnNitro Private First Class

    can you recommend one
     
  32. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    ZoneAlarm Free
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds