Need serious help before a divorce!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mcradtke, May 21, 2008.

  1. mcradtke

    mcradtke Private E-2

    My computer is infected with what seems to be, viruses, trojan, malware, etc. Downloaded AVG, performed scan, quarantine, and re-boot but nothing happened. The blue screen is still coming up telling me my PC is infected and now cannot do anything on my computer. I do not have the chance to download anything or even get into the contol panel to add or remove anything. I tried running the AVG scan in safe mode but it did nothing for me. What I am worried about is loosing the pictures and video of my son growing up. Is this even possible? Please help! At this point I can only navigate in safe mode. Thanks to anyone who has some advice.
     
  2. mcradtke

    mcradtke Private E-2

    I am not very tech savy so any help will do. Am I able to do the READ ME FIRST post in safe mode? If so I will do that. Just at work and not on my home computer and would really like some advice. Thanks
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...if you are unable to run in normal mode...you can do the scans and logs in safe mode. Attach them to your next post and we will see what we can do. :)
     
  4. mcradtke

    mcradtke Private E-2

    Thanks will do. Any way my videos or pictures will or already got lost?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only way the pic's would be lost is if they are infected and one of the scans removes them/it. Not to worry...it would be rare.:)
     
  6. mcradtke

    mcradtke Private E-2

    Got to downloading SuperAntiSpyware but a pop up tells me administrator set up to prevent me from downloading. What next? Also, I know the instructions tell me to get out of safe mode, however, i treid and still cant do anything in regular mode. Will everything still work out in safe mode. Thanks. Dont know if this helps but everytime i try to go into regular mode a blue screen pops up running thru "CHKDSK is verifying files". Is this normal? Thanks again.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you running...xp or vista?

    You may want to let chkdsk run and see if it finds any faults...

    And yes you can do the scans in safe mode.
     
  8. mcradtke

    mcradtke Private E-2

    XP. chkdsk does run but doesnt tell me about any faults. when i ran ccleaner it did tell me there was a file that was unreadable. is there a way to get into the administrator and change things to let me download superantispyware?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The malware is messing with permissions.....so the best course would be to download ComboFix to a diff. computer and transfer it to the infected one....it doesn't require an install....run it in safe mode.
     
  10. mcradtke

    mcradtke Private E-2

    Can I save it to a disk and transfer it to my computer? This is definitely teachig me a lesson, what a pain in the as*
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Certainly....:)
     
  12. mcradtke

    mcradtke Private E-2

    whats the problem with downloading on my computer and running it......same thing as superanti?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Could try.....and it would be better if you could...let me know.
     
  14. mcradtke

    mcradtke Private E-2

    Telling me I cant rename combofix as combofix, need to rename it preferably using alphanumeric
     
  15. mcradtke

    mcradtke Private E-2

    then doesnt allow me to rename it, just goes away
     
  16. mcradtke

    mcradtke Private E-2

    anyone living in western md wanting to help a brother out come on down.....this blows
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try renaming combofix.exe to combo-fix.exe and see if that works. If not then just run it without renaming it. Make the appropriate adjustments in the command given to run it from the Start, Run box.
     
  18. mcradtke

    mcradtke Private E-2

    I can type in combofix.exe in the start run, it comes up, has its little blue scroll bar then tells me a cant change name from combofix to combofix[2]. I cant find it anywhere in the temp files where it says it is. UGH!
     
  19. mcradtke

    mcradtke Private E-2

    Isnt there a way to go into the administrator file and change some things to allow me to download superanti? Also, what would it do for me to completely swipe my computer. I have a portable hard drive I have saved everything on and then start from square one? Would that take care of everything/
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be working in an account with administrative rights. So when you download a file, right click it and see if there is a securty tab....your account should be on it.
    If you are doing it in safe mode...you should also be in the administrator account no other account.

    When you download a file, note where it is going ...and change it to your desktop!

    You can do a search (all files and folders) for COmboFix....move it to the desktop and double click it.

    If you can get on line, it might be good to try an online scan:

    Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  21. mcradtke

    mcradtke Private E-2

    Tried Bitdefender and got this "Could not load the Online Scanner! Service Pack 2 was detected on this computer.Click on the information bar and select "Install ActiveX Control...". Should I install active x?
     
  22. mcradtke

    mcradtke Private E-2

    Finally got Combofix to run. I attached the report. Hope this helps a bit. Thanks
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you should have allowed the installation of the activeX for the scan to run.

    However....ComboFix has removed a large amount of trash and we will remove some more, after which you should be able to run all the scans as instructed in the Read and Run First.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now do as much of the read and run first instructions as possible.
     
  24. mcradtke

    mcradtke Private E-2

    Will get to these tonight when I get home from work. Just a few questions after scanning some other posts.

    1. I disabled my system restore a couple days ago, should I restore it before going ahead? Have a created a problem in doing so?
    2. Should I remove AVG 8 before downloading and running any of the downloads in Read me First. And if I do should I go with another providor afterwards? Seems like there might be better ones out there after reading a couple of threads.
    3. If the computer allows, should I do the Read me First in regular boot mode or stay in safe mode. FYI, I can only get in the administrator in safe mode.

    Thanks again, you guys rock!
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to right click the tray icon for AVG and disable it. Then do as much of the Read and Run as you can ...safe mode is fine if you can't do it in normal mode. Then attach the logs. :)

    Do not activate system restore until we know you are clean.
     
  26. mcradtke

    mcradtke Private E-2

    Still cannot download SAS. Giving me the same prompt as before that the administrator is not allowing it. I attached the avenger text if that helps. In the last post you tell me not to activate the systme restore, does that mean turn it back on and then off after everything is clean or keep it off for right now. Sorry, sounds like a stupid question but just thought I would double check. Thanks
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I want you to re-run combofix....but first let's fix my mistake:

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Where you able to run the reg. patch? Did you get any errors doing it?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  28. mcradtke

    mcradtke Private E-2

    Tim-
    I will give that a go tonight after work. I did run the reg patch and did not get any errors in doing so.

    Still have the question about the system restore as my last post.

    Thanks again.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Leave system restore off for now. :)
     
  30. mcradtke

    mcradtke Private E-2

    Off it is! I attached the avenger and MGlogs zip. Should I run combo fix now? Thanks
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't already, please disable the Guest account in User accounts.

    It appears as though you have both Trend Micro and AVG8 installed....you should only have one anti-virus program.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  32. mcradtke

    mcradtke Private E-2

    WOW! Thats alot. Will get it taken care of tonight and let you know. Thanks so much
     
  33. mcradtke

    mcradtke Private E-2

    This is a stupid question, I know you told me to right click the bar icon for AVG8 but there is not any. I cant find a way to disable either AVG 8 or Trend Micro. Should I just remove them?
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If they are installed ( and it is in your startup keys _ trend Micro) ir should be in the system tray...do you have it hidden? If it is something you can re-install, then go ahead and uninstall them while you do the fix.
     
  35. mcradtke

    mcradtke Private E-2

    I just uninstalled the SOB's
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    LOL.....okay...now do the fix and after, don't do anything on the web other than attach the logs.....(until you re-install 1 anti-virus) ...now can I eat my dinner??? :-D
     
  37. mcradtke

    mcradtke Private E-2

    Here is some reading material while you eat :-D. I figured you would want the avenger text as well. While deleting files from WINDOWS\Temp file I could not delete one file-it said it was being used by another file or user. Other than that everything went off without a hitch. I will install some new anti virus tomorrow. Look forward to hearing the news. Thanks ALOT
     

    Attached Files:

  38. mcradtke

    mcradtke Private E-2

    Do you see any problem with me getting online to download Avast? I would like to try something new and it seems there are a few people in the forums that like it. Or even if you have time, what do you suggest across the board for full protection (I read the "How to Protect yourself from Malware" forum), just alot of info in there to digest. I hope to upgrade everything once I get up and running (hopefully soon). I was very laid back about my protection before but this really woke me up and I now realize I need to take all precautions. Thanks
     
  39. mcradtke

    mcradtke Private E-2

    Just checking in. Dont mean to be pushy just anxious to see what is going on. Sorry. Thanks
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry...we have been a bit swamped...go ahead and download/install avast...I will double check your logs in the AM.
     
  41. mcradtke

    mcradtke Private E-2

    No problem. Thanks alot so far for everything. Got Avast installed already, figured it couldnt hurt. Have a good one.
     
  42. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your still showing traces of Symnatec......however:

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6"
    Java(TM) 6 Update 3

    Now for a few files pretending to be legit:
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now hopefully one last time run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  43. mcradtke

    mcradtke Private E-2

    I will take care of Symantec. I saw it but never remember installing it or anything so I just assumed it wasnt doing anything. I will take care of everything tomorrow. Thanks again.
     
  44. mcradtke

    mcradtke Private E-2

    Here you go. Look forward to hearing the good news. Thanks
     

    Attached Files:

  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good...Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  46. mcradtke

    mcradtke Private E-2

    Tim-
    Everything is running good. Got into regular log and did everything needed. Seems to be running pretty good. I did get a warning from Avast saying there was some malware on the computer. It ran its scan and seemed to have taken care of it. It only found the one during the scan so we should be OK. Thank you so much for your patience and your expertise! What you guys do on this site for free is truely unbelieveable. I will spread the good word and let everyone know about what a great site this is. If I have anymore troubles I will start a new post. Thanks again, your my hero!
     
  47. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds