help :( im so over getting malwear

Discussion in 'Malware Help (A Specialist Will Reply)' started by mummygeek, Oct 12, 2008.

  1. mummygeek

    mummygeek Private E-2

    i followed your read me run me thing.. now what.. im still getting the fake wrnings and ads popping up...
    i have avg and spybot search and destroy.. i ran the cc cleaner...
    i dont know what else to do.. please help
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now you attach the requested logs:
    ComboFix
    Superantispyware
    MalwareBytes
    C:\MGLogs.zip --> from running the C:\MGTools.exe
     
  3. mummygeek

    mummygeek Private E-2

    I have attachec logs.. but icant ind the other ones your asking for where will they be?
     

    Attached Files:

  4. mummygeek

    mummygeek Private E-2

    found this one... as well..
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We ask that you run the scans in order to fix the things that they find. Please re-run MalwareBytes and have it fix everything it finds. Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and the new MWB's log.
     
  6. mummygeek

    mummygeek Private E-2

    I did as you asked, ran scan, attached files. Its not as bad anymore but i still get rapidvirus ads popping up?
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please look at the log for MWB's that you attached and you will see that "no action was taken"......are you having difficulty running this program and fixing the malware it finds?

    Running MalwareBytes
     
  8. mummygeek

    mummygeek Private E-2

    i have been doing the scan as you say, i selected remove.. ill try again :(
     
  9. mummygeek

    mummygeek Private E-2

    the scan worked this time i think, but im still getting popup ads and my comp is slow... and noisy? like beeping cos the virtual mem is low?? i have no idea..
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good...:)

    Now lets do a little more:

    If you haven't already, please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 3"
    Java 2 Runtime Environment, SE v1.4.2_05"
    Java(TM) 6 Update 5"
    Java(TM) 6 Update 6"
    Java(TM) 6 Update 7"
    Java(TM) SE Runtime Environment 6

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  11. mummygeek

    mummygeek Private E-2

    I cant even get past the first step, when i try to remove the first java thing this error comes up, see attached.... :(:cry:cry
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please just continue on with the rest of it. :)

    If something doesn't work, let me know, but continue with the rest.
     
  13. mummygeek

    mummygeek Private E-2

    i did it all except removin the java files as i said in last post. files attached. :)
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Much better.....as to the java. Did you disable TeaTimer before you tried uninstalling?

    What malware issues are you still having?
     
  15. mummygeek

    mummygeek Private E-2

    Teatimer?? whats that? :-o I havent actually had any malewear probs since the last reboot. My pc is running slow but now ads have come up yet. What was happening was when ever u searched something with google a ie window would open up with some ad and it would freeze up etc. the malwear i had originally when i posted this thread seems to have gone (the one where it was warning me to fix pc etc)
    so fingers crossed its all good thanks for all your help xoxo
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    To Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot.

    You may also wish to use a Startup Manager.

    We can do this to help with your start up time:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If you are not having any other malware issues, then:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds