Virus is Disabling my Computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by ant1g33k, Jul 15, 2008.

Thread Status:
Not open for further replies.
  1. ant1g33k

    ant1g33k Private E-2

    I have recently been infected with a Virus which is, as the title suggests, disabling my computer from all the functional glory that it used to be. It is RIDICULOUSLY slow, it freezes every so often. Right-clicking? Forget about it. I am posting this in SafeMode with Networking.

    This is what this cursed virus has done to my computer:

    -It has disabled TaskManager.
    -It has disabled ControlPanel, Search, Run, "All Programs", and many more from my start menu.
    -It has disabled FireFox.
    -It has disabled RegEdit.
    -IE is useless. I will do a search to try and download antivirus programs, but it will go to www.asiuoqgusdbaksd.com for a few seconds, and then redirect me to some other random website. I am accessing MajorGeeks as well as posting this VIA a Proxy Bypass website since my IE won't allow me to access MajorGeeks, or GeeksToGo, as it will redirect me, as stated earlier.
    -My homepage is not my set homepage. Instead, it is a cruddy site which attempts to pursuade me to download and install some program because I have a virus...gee thanks...
    -New IE Toolbar, named qdsfmao or something.
    -I will get pop-ups in normal mode saying that VAV (VISTA Antivirus, a program that I don't even have, oddly enough) has detected a critical system error, and that I should install this program to scan and get rid of it.
    -I am unable to do online virus scans such as PandaActiveScan, or KasperskyOnlineScan since the virus will redirect the site.
    -I am unable to download anything, since the virus will redirect the site. The Proxy Bypass sites aren't download friendly.
    -I am unable to install anything in SafeMode, and in normal mode, it will not install or even boot for that matter.

    I did an earlier scan with COMODO FirewallPro, and it detected 2 things on two different dates. The first one being Adware.VirtuMonde, and the second one being Adware.c(starts with c for sure, can't recall the exact name). I deleted both of them, the virus still persists.

    My computer is a vegetable. Please help.

    PS: Remember I am unable to download/install programs, (I have tried relentlessly for a few hours to download Malwarebytes' Antimalware, to no avail) unfortunately a log from a program might not be available. I have Hijackthis, so I can post one of those logs, but I'm not sure if booting in SafeMode would affect the log or not.
     
    Last edited: Jul 15, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Due to your problems, I'm going to bypass our normal procedures of running the READ & RUN ME FIRST procedure. But we need at least some form of info in the way of logs collected from your PC to know what is going on.

    Please download this MGtools.exe to your Desktop (also not normal place) and then double click it to run it. Allow it to finish running. It will produce a log in the root folder of your Windows boot drive. Normally this will be the C drive. Thus you would have a file named C:\MGlogs.zip that you need to attach here.

    See: HOW TO: Attach Items To Your Post


    NOTE IF YOU ARE RUNNING VISTA: If you are running Vista, you will not be able to do the above. You will have to follow the instructions in the below to get MGtools to run properly.

    Using MGtools
     
  3. ant1g33k

    ant1g33k Private E-2

    I tried for a ridiculously long time to try and get this MGTools onto my computer in safe mode, but the virus keeps on redirecting me to a site that sells Viagra at $1.49 each or something. SafeMode is the only way I can access MajorGeeks. (Un)fortunately, I have posted another log in the GeeksToGo Forums and they informed me to post a HJT log. Since HJT is the only program that I am able to run and produce a log from, here it is.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must not work in multiple forums. So please pick one an stick with it. ( I see your other forum post here:http://www.geekstogo.com/forum/Virus-Disabling-Computer-t205168.html )

    If you wish to work here and begin working from a HijackThis log, you really need to rename the executable file first otherwise components of your infection could be hiding from it. You need to rename the below:

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    to

    C:\Program Files\Trend Micro\HijackThis\analyse.exe

    Then do the below just to get started.

    In your first message below you said you could not download Malwarebytes Anti-Malware. Are you sure you meant to say download? Or did you mean you cannot install it? Or a third choice is that you already downloaded and installed it, but you cannot run it. If the problem is that you cannot install it, just rename the downloaded file to something else ( like mb.exe for example) then see if you can run the installer.


    Run C:\Program Files\Trend Micro\HijackThis\analyse.exe by double clicking on it .(select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [d0e84b22] rundll32.exe "C:\WINDOWS\system32\ixperysd.dll",b
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O21 - SSODL: evgratsm - {38D471AF-C050-4BEF-B53B-19C15F5613FC} - C:\WINDOWS\evgratsm.dll

    After clicking Fix, exit HJT.

    Now reboot your PC back into safe boot mode and see if you can find and delete the below files:
    C:\WINDOWS\evgratsm.dll
    C:\WINDOWS\system32\ixperysd.dll

    Let me know the results!

    Now see if you can boot into normal mode to do the below. If not just do the below in safe boot mode.

    See if you can run MGtools.exe now. If you can then attach the MGlogs.zip file.

    Attach a new HijackThis log if you cannot run MGtools.
     
    Last edited: Jul 16, 2008
  5. ant1g33k

    ant1g33k Private E-2

    Sorry chasling, I realised my stupid mistake soon after posting in both Forums. I guess it was a "I NEED HELP BADLY PLEASE HELP ME PLEASE" sort of thing where I just went crazy and posted everywhere.

    Again, my apologies for wasting your precious time, as I see you have posted in nearly every single thread here, and are clearly very busy with other people who HAVE NOT posted in two Forums :eek::cry
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This thread is close since you are working in the other forum.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds