Help Please!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ap7891, Mar 24, 2008.

  1. ap7891

    ap7891 Private E-2

    Hi,
    I'm new here and noticed that your site is very helpful in fixing these kinds of problems.
    Ever since last night my computer has been running really slowly. The first noticable sign was that my computer came up with a blue screen surrounded by the semi-official "warning! spyware detected on your computer" background. I have run the HP Cleaning procedure and attached it. the background has gone but I was wondering if there were still any problems to explain why my computer is running so slowly.
    I have attached the 3 logs from the programs that your site advised me to run.
    Thanks for your help!
     

    Attached Files:

  2. ap7891

    ap7891 Private E-2

    Hi again,
    as I was sending this thread it also occurred to me that there was another problem.
    To my knowledge I haven't installed "Symantec Email Proxy" but since this morning it was coming up with multiple "email checks" checking supposed "messages" when i wasn't sending any.
    Please help as they are crowding up my screen as i write this reply!
    Thank you!
     
  3. ap7891

    ap7891 Private E-2

    And I've just deleted Symantec Antivirus from my computer. it's too early to tell whether or not it's fixed the problem but it deleted the 'quarantined' files.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. ap7891

    ap7891 Private E-2

    Ok, thanks, I'll do that now
     
  6. ap7891

    ap7891 Private E-2

    Wait, weren't the logs that you required the 3 logs that I attached in the original post? i'm new here and not quite sure what to do.
    Thanks!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Some days are better than others.....:cry ....I'm looking at them now and will get back to you.

    OK..do you know what this is:
    C:\Documents and Settings\Ashley Piper\Application Data\DVDCSS
    C:\-1673227394
     
  8. ap7891

    ap7891 Private E-2

    C:\Documents and Settings\Ashley Piper\Application Data\DVDCSS i think is from a program i used to download some dvds onto my computer - it was when i tried to crack it using a program off the net that i started to have some further problems (the program was MagicDVDRipper5.2.1 and i downloaded a "crack" with 3 files in it. not sure which one it was exactly - i've deleted it off my computer)

    C:\-1673227394 - i have no idea what this file is or how it got there. but it was created on the day i started to have problems

    thanks for your help
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...good you deleted both and downloading cracks is a sure way to get malware.

    Please do the following:
    Use add/remove programs to uninstall:
    Java(TM) 6 Update 3"
    Java(TM) SE Runtime Environment 6 Update 1

    And this is a puzzler ....so please use windows explorer to find and delete it:
    C:\WINDOWS\system32\mhkjqtsneh.bmp

    To be sure, please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  10. ap7891

    ap7891 Private E-2

    Hi, i've deleted those two programs and the image. that image was the one that was my desktop background which wouldn't go away (i managed to after going through the cleaning process)
    i've run the .bat file and have attached the log for you to look at.
    what should i do with these files?

    C:\Documents and Settings\Ashley Piper\Application Data\DVDCSS (i no longer need these [I'm 99% sure])
    C:\-1673227394 (I have no idea what this file is)
    thank you so much for your help!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes you can remove those two....as well as this one:
    C:\WINDOWS\dump8712.tmp

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now install:
    Java Runtime 6
    Tell me what problems you are having.
     
  12. ap7891

    ap7891 Private E-2

    Hi,
    I've done that successfully.
    I also noticed that in my window's task manager processes i have 2 versions of ati2evxx.exe running (which sometimes comes up with a "read" error and 8 versions of the svchost.exe program running. i've heard that some of these may be malware, should I do anything about them?
    Thanks for your help!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    ATI2evxx.exe is related to ATI Technologies Inc. hardware. It is normal behaviour that it shows up twice in the Task Manager. You should not need to end the process.
    The svchosts file handles a lot of processes and is normal also.
     
  14. ap7891

    ap7891 Private E-2

    Hi,
    i've just tried to log into hotmail via my mozilla browser, could the steps i have taken changed my settings by accident? i've looked around and can't see why i wouldn't be able to access it properly.
    The same problem was happening with windows explorer but i'm now able to access that.
    Are there any other problems i need to fix?
    Thanks.
     
  15. ap7891

    ap7891 Private E-2

    I've also just tried hotmail again on windows explorer but it's not working, it comes up with this error:

    Service Unavailable - DNS failure
    The server is temporarily unable to service your request. Please try again later.
    Reference #11.2d08d93f.1206688113.15b5e41


    i've never seen this error before and only started to happen after taking the below steps.
    Thanks!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is possible that the malware has messed with your setting or
    if it was thru your hotmail account ..they may have blocked you.

    Can you not get to this screen:

    http://login.live.com/login.srf?wa=...ly=http://mail.live.com/default.aspx&id=64855

    Tell me exactly what all is happening.
     
  17. ap7891

    ap7891 Private E-2

    when I went in through the way you suggested it worked fine in both mozilla and windows internet explorer.
    after that i tried www.hotmail.com and it went through fine, but when i wasn't logged in when i typed in www.hotmail.com in mozilla it just came up with this site: http://login.live.com/login.srf?wa=...ly=http://mail.live.com/default.aspx&id=64855
    it was blank and said "done" down the bottom and did nothing.

    Also, with internet explorer, when i'm not logged in it comes up with the error i mentioned below - but only sometimes.

    The thing is that i hadn't had any trouble with it until a couple of days ago (after speaking to you)
     
  18. ap7891

    ap7891 Private E-2

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sure...blame it on the malware geek ...:D

    Have you cleaned out all of your internet temp files?
     
  20. ap7891

    ap7891 Private E-2

    haha - of course not!
    how do i clean them out in Mozilla? i've only started using it since i had this problem so i'm not 100% sure how to do that yet.
    i've done it on windows explorer though.
    thanks for your help - it's fixed the background problem and all the other popups that come up - it's just this last tiny little issue that needs to be resolved!
    Thanks!
     
  21. ap7891

    ap7891 Private E-2

    hi,
    i worked it out and it worked first time!! (i made sure that i deleted the cookies as well)
    i think that it's all working properly again now!
    are there any other problems that you could see that need to be fixed?
    if not thank you SO much for all your help!!!!!
    I was really worried about it and worried that i'd need to get it wiped, if any of my friends have similar problems with their computers i'll definitely be suggesting this site to them!
    thank you!
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to tools / options / privacy / show cookies (clear all) and then clear private data..... Click the Privacy icon to get to the cache options. Now you can click the 'Clear Now' button.
    Watch for a drop down box to appear with numerous checkable boxes. Check 'Cache' and press the 'Clear Private Data Now' button

    Let's try this ...start / run / type "cmd" without quotes and at the command prompt:
    ipconfig /flushdns
    enter
    exit


    Now how are things?

    We posted over each other ....no there is nothing else I see that you need to do.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  23. ap7891

    ap7891 Private E-2

    thank you for all your help!
    i'll run through those final steps now.
    The hotmail is working fine again! thank you!!! you've been a massive help!
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....and please PM either MA or Halo regarding changing your user name...using an email account leaves you open to bots harvesting their crop.
     
  25. ap7891

    ap7891 Private E-2

    ok!
    will do!
    thank you once again!
     
  26. ap7891

    ap7891 Private E-2

    um, the reason i didn't change it was because i couldn't work out how to actually change it using your site. is there a way to do it or do i need to delete my account first and start again?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds