Please Help Me is this a malware? - :confused

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by NHJ, Mar 14, 2012.

  1. NHJ

    NHJ Private E-2

    Hi all...
    I have a major problem when I am trying to download a mediafire file a pop up screen with a message "please wait while the connection is beeing established" with a german translation below.It is blocking my desktop, I cannot use clrtl+alt+delete, cannot acess task manager, restart/ shutdown not allowed and preventing my from accessing the safe mode! Please help me I am so desperate as I need to submit my assignment in a few days and most of it is in the laptop. I am using windows 7 64 bit. I have tried the advice from 'chaslang', but the fixlist.txt is unique to that person.I dont have windows installation disc as the windows come with laptop package. I have downloaded the frst64,exe to my usb drive. Please helppp meee....if anybody got any suggestions/solutions
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything. Note if you cannot save things in C:\ then just save them to your Desktop. Make sure that you have disable UAC and rebooted first if you are running Windows Vista or Windows 7.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.



    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!

    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:


    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. NHJ

    NHJ Private E-2

    Hi TimW,
    First of all thank you for your reply, I really appreciate your help and dedicating you time for this.
    I have made the attempt to follow all the instruction in READ & RUN ME FIRST Malware Removal Guide (incl. spyware, virus, trojan, hijacker)
    This 'malware/virus/trojan' somehow disabling me from accessing anything from my computer, not responding to ctrl+alt+del to task manager/shutdown/restart.
    I cannot access anything in safe mode, literally anything at all is the same like normal windows. I have tried downloading the tools SUPERAntiSpyware
    in the CD to install them in safe mode, but unfortunately I cannot even see my desktop/windows icon to perform any malware cleaning or run any programme. The screen only have a display that says 'Please wait while the connection is beeing established' with a german translation which is like an image blocking everything. So I tried Malwarebytes Anti-Malware, and ComboFix finally MGTools, but all failed to run from the CD that i donwloaded in.
    I have then downloaded the tools/malware cleaning and removal software from USB as well. Run it in safe mode, but still the same thing, the malware didn't let me access my USB drive. Yes, I’m still having problems, and I cannot get any logs or any files from the computer in safe mode/normal mode as I cannot access any folder/files/dektop. The malware didnot let me do anything. Please advice. My gratitude for all your help.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you cannot boot in any mode ( safe or normal mode ) and you cannot run any of the READ & RUN ME there is not much we can do for you except suggest what is in the below quote box
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  6. NHJ

    NHJ Private E-2

    Thanks TimW,

    I will perform the below steps and post to you the frst.xt file soon.
    Thanks again for your kind help, really do appreciate it!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome. I'll be here when you are ready. ;)
     
  8. NHJ

    NHJ Private E-2

    Hi TimW,

    Kindly find the attached frst.txt file. Thanking you in advance for your help.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not run it in the Windows Recovery environment. Please do it again and follow the instructions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds