1. DocCountry

    DocCountry Private E-2

    I have never had a virus on a computer before but I think I have one now. at boot up there is a blue circle flashing ? in center. a ballon pops up stating Critical System Error! and when you click on it Explorer opens and want to sell virus burst ..

    Its my daughters computer and she does not know what she did but while we were being presented with this and other similar ads, she wanted to click on them ... I am sure that is what happened. I ran adaware but it did not remove, Norton Anti-Virus and it saw nothing wrong.


    I looked in the add remove programs and there is a program called Internet Security Add-On which will not uninstall.

    Can you direct me to a thread where this has happened to someone else?

    Thanks.
    Doc
     
  2. Bladesofhalo

    Bladesofhalo MajorGeek

  3. matt.chugg

    matt.chugg MajorGeek

    Welcome to MajorGeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat[/B]
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!

    This thread will be moved to the malware forum.
     
  4. DocCountry

    DocCountry Private E-2

    Thanks I will get on it.
    since my post I ran AdAware and Spybot and there were many ..... including zlob, winAntiVirus pro , the "fix" action did not elimintate the annoying Critical System Error message from popping up ever minute or so.

    DC
     
  5. DocCountry

    DocCountry Private E-2

    PS should I start over in the Malware area? happy to.
    dc
     
  6. matt.chugg

    matt.chugg MajorGeek

    OK first run the following procedure:

    SpywareQuake & SpyFalcon Removal Procedure

    This will clean up some of the Zlob infection.

    THEN run the steps I gave you above.

    If you don't see this till you come back then run the SpywareQuake & SpyFalcon Removal Procedure as well and let me know
     
  7. matt.chugg

    matt.chugg MajorGeek

    You ARE in the malware area, we moved your thread here......
     
  8. DocCountry

    DocCountry Private E-2

    I was able to run the various scans. I will attach all the files .txt and logs.

    It appeared that bit defender removed some things but panda says I still have some issues

    I just saw the spyquake spyfalcon recomendaiton, I will wait till you see these result before proceeding with that.
    thanks.
    DC
     

    Attached Files:

  9. DocCountry

    DocCountry Private E-2

    and the panda and HJT
     

    Attached Files:

  10. matt.chugg

    matt.chugg MajorGeek

    Procede with it now, you still need to run it.

    THEN after your done with it post the other logs.
     
  11. DocCountry

    DocCountry Private E-2

    Ok I need glasses. I did not find any of the files on the two lists to rename as .DDD or to delete.

    My computer seems to be better....

    The only thing I see it doing now is the blue circled ? in the bar is blinkin with a red circle and every so often popping up a Critical Error Balloon. I have not clicked on it to see what will happen. At the beginnig it went to a Virus Burst website.

    attaching the smithfiles.txt

    I may take a day off,
    Will I know when this is clean?
     

    Attached Files:

  12. DocCountry

    DocCountry Private E-2

    PS I did add/remove in safe mode the Internedt Explorer Security Plugin, Internet Security Add-On and PCODEC 6.0

    Thanks again for your help.
    DC
     
  13. matt.chugg

    matt.chugg MajorGeek

    Please rename Hijackthis.exe to analyze.exe as instructed in the readme, this is very important as some infections now look for hjt in running processes and hide themselves. renaming it means we can see a lot more if this is the case.

    Theres probably not much point taking the day off, I have to go to work too so I can only answer when I am free.

    Post a new HJT log.
     
  14. DocCountry

    DocCountry Private E-2

    Analyse.exe
    hjt log
     

    Attached Files:

  15. DocCountry

    DocCountry Private E-2

    I ran Panda again. because it was the only one that seemed to see the invisible programs here is the log.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are using HijackThis from the wrong location. You are now using:

    C:\Documents and Settings\Britney\Desktop\hijackthis\Analysethis.exe

    In message number 9 you were using:

    C:\Program Files\HJT\hijackthis\HijackThis.exe

    You need to rename the one in C:\Program Files as requested and only use that one to obtain logs. AND you need to delete the below folder completely so you do not use this anymore:

    C:\Documents and Settings\Britney\Desktop\hijackthis
     
  17. DocCountry

    DocCountry Private E-2

    So sorry. I forgot where it was.
    here is from the programfiles\hjt\hijackthis\analysethis.exe log
     

    Attached Files:

  18. DocCountry

    DocCountry Private E-2

    Any more thoughts?
    I still have the flashing blue Circle with the intermittent balloon popping up with the "Critical System Error"
    Thanks DC
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\PCODEC\isaddon.dll (file missing)
    O8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTM
    O21 - SSODL: died - {7fa55359-7223-410f-bc82-efb3e3ded07f} - C:\WINDOWS\system32\gtpbx.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\PCODEC <--- the whole folder
    C:\WINDOWS\system32\ToolBand.dll
    C:\WINDOWS\system32\gtpbx.dll

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and attach a new HJT log.
    Also download the current versions of ShowNew and GetRunKey and attach new logs from them.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  20. DocCountry

    DocCountry Private E-2

    At this point I do not see any of the blinking error messages and the computer seems to be working fine.
    attached runkeys and shownew logs.
     

    Attached Files:

  21. DocCountry

    DocCountry Private E-2

    And the HJT log

    I am resetting the restore now as well.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But we were not done cleaning yet! You still had some registry keys I needed to fix related to the gtpbx.dll file I had you remove.

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new log from GetRunKey.
     
  23. DocCountry

    DocCountry Private E-2

    RegEdit has been run.
    here is new runkey file.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  25. DocCountry

    DocCountry Private E-2

    Thank You
    DC
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds