Is my computer hijacked?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by forrest mc, Feb 17, 2012.

  1. forrest mc

    forrest mc Private E-2

    My computer is under attack. It is very slow.

    The second email welcoming me and advising to read first came up as "Internet Explorer cannot display the webpage" and in the address line was: http://%22http//forums.majorgeeks.com/showthread.php?t=35407"]READ",,-1,0,,,,

    It seems that Internet Explorer gets redirected. Have run AVG 2012 and Malwarebytes in Safe Mode, CCleaner, SmartDefrag, SUPERantispyware. I used CCleaner to turn off unneeded Startup programs. I removed and downloaded latest Jave and disabled most Add-ons. I tried turning off System Restore but got "Encountered problem disabling one or more drives".

    May be of interest: When I last ran Malwarebytes quick scan it ran thru 6 minutes of c\documents & settings\networksercive\local settings\temporary internet files\content.IE5\ files despite having just run CCleaner.

    Obviously I need help on this AMD based machine running Windows XP HomeEdition Version 2002, Svc Pk 3. Thanks for any help you can offer.

    Forrest Mc
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. forrest mc

    forrest mc Private E-2

    Computer is running much faster. I changed browsers and did all but one of the requested items on the lists. I could not unzip/run rootrepair. Winzip gave me an error 1722 code. Also, when I did an AVG uninstall I got an error code 0XE001D02B. A search for AVG shows tons of files still.

    I turned Windows Firewall back on but haven't tried to reinstall AVG, fearing problems.
     

    Attached Files:

  4. forrest mc

    forrest mc Private E-2

    I neglected to add: Rootkit.Boot.Pihar.b was detected and cured with SUPERantispy scan. The scan log is gone, however.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run TDSSKilller and fix this:
    Code:
    14:03:24.0531 1604    \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    14:03:24.0531 1604    \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip 
    Now download MGtools and save it to your root folder. Run the exe and attach the resultant C:\MGLogs.zip.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds