In A Pickle

Discussion in 'Malware Help (A Specialist Will Reply)' started by Stiina59, Dec 18, 2015.

  1. Stiina59

    Stiina59 Private First Class

    Hi Geeks,
    I'm back, plans to protect my new computer were thwarted.

    I was getting thousands of errors when running routine Super Anti Spyware, but not so much with Avira or MBam. Honestly, it started and I deleted McAfee and installed Avira and I don't recall whether I actually got a scan in, because right after that, my computer would not boot and I could not restore anything. I ended up having to completely wipe the HDD and reinstall Win7 then the Win10 upgrade.

    After recovering my computer, I thought that maybe some of the SAS detections could be some of the Win10 tracking software, so I also installed the DWSlite. All was fine until I ran the DWS. Now here's what I'm not sure about, but our wireless router also went down around the same time I was recovering and it isn't clear whether the DWS caused the problems or I was having problems with connectivity, but I ended up doing another recovery.

    Bottom line is I can't hardly do anything, can't get my software working right, can't install anything and now I got this pop up message in IE that said my computer has been blocked (right since I'm on line right now) and the cause is:

    spy_on_pops.exe

    I did a search in the forum and couldn't find anything on this.

    Help!

    :confused:

    StiinaQT / Laura
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  3. Stiina59

    Stiina59 Private First Class

    Cannot get the ESET online scanner to run. I've tried at least 5 times and it keeps timing out.

    I'm attaching the DWS log in case that's any help. I don't know if it permanently has hurt my Win10 software.
     

    Attached Files:

    • DWS.log
      File size:
      7.7 KB
      Views:
      4
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    There is little that we can do if you can't provide us with the logs and reports generated by running the READ & RUN ME procedure.

    Can you do the following?

    Please do the below so that we can boot to System Recovery Options to run a scan while Windows is offline.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.
    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note:
      Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  5. Stiina59

    Stiina59 Private First Class

    Long story, finally got the frst.exe to run, but I immediately was thrown into the repair/reinstall loop and could not get my computer to work. I ended up going to a local geek to get me going again and I'm now reinstalling everything.

    For now, I'm just trying to get back to ground zero.

    Thanks for your help.

    Stiina / Laura
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome and "Thanks" for the updated status report.
    *This is a good time for you to look into creating backup images of your hard drive. ;)
     
  7. Stiina59

    Stiina59 Private First Class

    Here's the deal. When I ran the frst.exe process, I selected a flash drive that was infected with a nasty virus that I've yet to identify and clean. When I got my computer back from the geeks, I plugged in my external drive which, you see it coming, was now also infected. I cleaned things up again, but am concerned that I didn't fully isolate the critter when I recleaned the HDD.

    I am including all of the logs. Looks like only one scan picked up anything of concern. If it's not a problem, next I need some guidance on how to clean up my HDD image on my external drive so I can recover my data.

    Thanks!!
    Stiina / Laura
     
  8. Stiina59

    Stiina59 Private First Class

    Unable to attach my logs...guess I'll start a new thread.
     
  9. Stiina59

    Stiina59 Private First Class

    Reposted:

    Here's the deal. When I ran the frst.exe process, I selected a flash drive that was infected with a nasty virus that I've yet to identify and clean. When I got my computer back from the geeks, I plugged in my external drive which, you see it coming, was now also infected. I cleaned things up again, but am concerned that I didn't fully isolate the critter when I recleaned the HDD.

    I am including all of the logs. Looks like only one scan picked up anything of concern. If it's not a problem, next I need some guidance on how to clean up my HDD image on my external drive so I can recover my data. Guess I could have included the logs on the previous thread, everything looks so different now, sorry.

    Thanks!!

    Stiina / Laura
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Stiina59

    Please attach the MGlogs.zip folder.
     
  11. Stiina59

    Stiina59 Private First Class

    Ooops, sorry about that! I didn't realize that I was supposed to run that too. Will do ASAP.

    Stiina / Laura
     
  12. Stiina59

    Stiina59 Private First Class

    The first time I ran MGTools, it stalled at the first stop and after 2 hr, I x'd out of it and restarted. Not sure if that matters, just an FYI in case there's something that shows up in the log.
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your logs are clean. ;)
     
  14. Stiina59

    Stiina59 Private First Class

    Thank you!
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You are welcome.

    If you are not having any other malware problems, it is time to do our final steps.
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    Last edited: Dec 30, 2015

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds