Serious computer problems after virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dena_Walker, Feb 27, 2008.

  1. Dena_Walker

    Dena_Walker Private E-2

    Hi all,

    I am running Windows XP home SP2 on a T5026 Emachines approximatly a 3 year old computer. I have not used the computer much in the last year since I got a newer Hp computer. Yesterday I was in the process of cleaning out the old emachine computer so that my daughter could use the computer.

    I downloaded some desktop themes from my hp computer and then I transfered the files to the older emachines computer with a usb flash drive. After I extracted the theme files on the old emachines it got a virus called

    Win32/Gaelicum.A

    The computer would not boot up to xp. but I was able to get into safe mode. I ran the vcleaner tool and it scanned forever while it fixed all of the exe files that the virus took over. After it finished fixing files I was able to boot up into windows xp.
    But now my computer is just a serious disaster. Nothing seems to work right. I immediatly tried to access the internet to use the virus tools to scan the computer........but that was a no go....the computer would not connect. I ran a scan in the help and support of windows xp on the network diagnostics and the errors were sickening to see. A long line of WMI errors and failed reports. Dr watson doesn't work anymore and neither does the System configuration utility it says it has encountered a problem and needs to close.

    I am wondering if this problem can even be fixed. I cant access the internet from that computer to use the tools that I need to to update virus/spyware definitions. The only thing I can do is transfer files with a usb flash drive from one computer to the other. And to be honest I don't even know where to start fixing because there seems to be so many errors and problems.

    If anyone has any thoughts, suggestions It would be much appreciated. I know my way around a computer but I am not computer tech savvy when it comes to technical issues.

    Sorry for the long post,
    Thanks,
    Dena
     
  2. Lev

    Lev MajorGeek

    Welcome to MajorGeeks.com!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. You can download to a USB flash drive and move them over to the infected PC in this way to run.

    Read & RUN ME FIRST Before Asking for Support
     
  3. Dena_Walker

    Dena_Walker Private E-2

    Hi Lev,

    I hope I have done all of this correctly.
    I am still working on getting updates from avg to my old computer.
    And I am still working on downloading sunjava like it said to do. I am on dial-up so this is taking some time. I have dowloaded all of the programs for the scans like it said to do and I have uploaded the log files.
    I am still having the issues described in my first post.

    Thank you so much for helping me with this,
    Dena
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...it's a mess...let's start with this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  5. Dena_Walker

    Dena_Walker Private E-2

    Hi TimW,
    After I rebooted after this step of running avenger.exe

    "You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself"

    I am getting this message:

    C:\WINDOWS\system32\cmd.exe
    The system cannot find the file spcified.
    Could not find C:\avenger\*.reg
    The system cannot find the file specified.
    zip warning:C:\backup.zip not found or empty
    adding: avenger\backup.reg <188 bytes security> <stored0%>
    ---------has another box that says:
    WINDOWS - NO DISK
    there is no disk in the drive.Please insert a disk into drive.

    That is what is on the screen after I rebooted.
    I will wait for a response before I continue.

    Thanks,
    Dena
     
  6. Dena_Walker

    Dena_Walker Private E-2

    Hi TimW,

    I went ahead and exited out of the message stated in my last post.
    Apparently I didn't have the avenger download in the specified location.
    I transfered the file to my downloads folder and then I extracted the avenger exe file to the desktop and ran it from there. You will be unhappy to know that the avenger text file did not create itself after I rebooted. The text file was empty. (sigh)

    I went ahead and ran the MGtool and uploaded the log.

    Thank you so much for trying to muddle through all of this
    mess with me!
    Dena
     

    Attached Files:

  7. Dena_Walker

    Dena_Walker Private E-2

    Me again.....lol

    I am having problems trying to figure out how to update avg manually.
    can someone direct me to a link to the definitions download file and then tell me how to manually install the definitions once I get them on my computer. I downloaded a .bin file earlier from avg that I thought was an update file.....but I can't figure out where to put it so that avg will recognize it.

    Also.......TimW, You asked how my computer was running after I did the last steps.....
    my computer still has some serious issues that I stated in my first post. Still can't access system configuration utilities, the dr. watson error log still not working. Both still say has encountered a problem and needs to close. Still have the WMI errors in Network dagnostic. Still can't access the internet. Has a lot of DCOM errors in the Computer managment under Event Viewer/system.
    Just ran another SASpyware scan just to see if it finds anything. Didn't find anything.
    I appreciate all of the help that you have givin me! You people on this board are so talented and the knowledge is amazing! I wasn't expecting any miracles in getting all of this mess cleaned up and fixed. But this board was my last hope before I beat the computer to death (the satisfaction would be wonderful) and chunked in it the dumpster! LOL! (not really but I want to)

    So kudo's to all of you people on here who help others everyday!
    Dena
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall:
    Actual Spy
    Spyware Doctor 3.2 --> this is an old version. (Is it a trial or paid for?)

    Use windows explorer to find and delete:
    C:\DOCUME~1\Owner\LOCALS~2\Temp\200822723223_mcinfo.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\45b5cc51.exe
    C:\WINDOWS\inet20026

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Do you have your xp cd?
     
  9. Dena_Walker

    Dena_Walker Private E-2

    Went to add and remove programs to remove the 2 programs that you listed..... and no its not a paid version.
    window pops up and says something about the uninstall bins are missing please correct the problem and try again. I don't know how to correct the problem.

    Computer didn't come with xp cd. And unfortunatly I don't have the recovery discs either.

    Should I go ahead with the rest of your instructions?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....do the rest ....do you have an xp cd that you used for a different computer? Same version?
     
  11. Dena_Walker

    Dena_Walker Private E-2

    no I don't.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This may be a problem as some of the issues you seem to be having may well require doing a repair install ...but we will deal with that later ...finish the fix...then re-run ComboFix and attach it with the new MGLogs.zip.
     
  13. Dena_Walker

    Dena_Walker Private E-2

    Tim,

    I hate to bail out on ya.....but I really feel like this computer just needs a clean install of windows (and I am sure you will agree). There are so many files on it that is corrupted. And my husband is sick of seeing me sitting at the computer night and day trying to fix it. So my husband drug it down to a computer shop this afternoon and they are going to wipe out the system and do a clean install of windows.

    Thank you for all of your time and trouble Tim!
    This board is awesome!
    Thanks for everything,
    Dena
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Might be the best action all in all ...sorry we couldn't do more. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds