Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Jul 30 2008, 08:52 AM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 30-July 08 From: New York, New York Member No.: 80,629 Operating System: Windows XP |
After searching online to find an appropriate tech forum Web site, I am so happy to have found "What the Tech." This seems awesmoe! I just got what seems to be a pretty malicious virus on my Dell laptop yesterday, and would love help on getting it removed. I am not very computer-saavy... I don't know how to post the logs which highlight coding of the potential problem. So I'll just share what I think happened on my computer and what's going on with it now. I know exactly where I got the virus, but am embarrassed to share the site, and I don't know if I'm allowed to say it on here, which should give insight into where I was anyway. I am never listening to frat boys' advice on "hysterical" videos again. Now, my desktop was replaced with a red background that says, "your privacy is compromised," or something to that effect, and a variety of spyware and malware removal programs continually pop up on my computer. The most prominent one is "Vista Antivirus 2008," but others, like "Privacy Protector," pop up almost every 15 seconds. I can't even utilize Internet effectively (am on a different computer now). I also noticed that I can't access my Control Panel, and it said the administrator (which I thought was me?) disabled that functionality. There are also five documents that continually appear on my computer - they look like Internet Explorer files. I've tried deleting them, then emptying the recycling bin, but they keep coming back, so I'm assuming they're already pretty ingrained in the coding. Again, I really don't know much about computers, so specific Layman's terms are much appreciate. Thanks in advance for any help you can give. |
|
|
|
Jul 31 2008, 05:02 AM
Post
#2
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Hello TheRogueStar
Welcome to the Whatthetech Malware Removal Forum Download Trendmicros Hijackthis to your desktop.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required. |
|
|
|
Jul 31 2008, 07:51 AM
Post
#3
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 30-July 08 From: New York, New York Member No.: 80,629 Operating System: Windows XP |
Hi Ken545! Thanks so much for the prompt response! I'm going away on a trip tonite, but will try this as soon as I return Monday. I will let you know what happens. Enjoy your weekend, and thanks again!
|
|
|
|
Aug 7 2008, 04:48 PM
Post
#4
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 30-July 08 From: New York, New York Member No.: 80,629 Operating System: Windows XP |
Hi Ken545!
I've been trying to download from the link you sent, but whenever I do so, it gets redirected to: Malicious Link Removed Any thoughts? I appreciate any advice you can give! Also, it seems like the virus is slowly DEvolving, perhaps. the background on my computer is now back to normal. Thanks much, Jessica |
|
|
|
Aug 8 2008, 08:58 AM
Post
#5
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Hi,
I am away my self with limited internet access until Monday night but I will check in here when I can. It looks like the malware has altered you hosts files. Do a few things, you need to be able to access another known good Computer and download these programs, copy them to a CD or a Flash drive, then you can transfer them to this computer and run them. 1. This will reset your HOSTS FILE back to Microsofts default settings. After you run it you should be able to get to the links I posted Download the HostsXpert 4.2.0.0. - Hosts File Manager.
2. Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
3. Download Trendmicros Hijackthis to your desktop.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required. Post the Malwarebytes log and then run HJT and post the log please |
|
|
|
Aug 9 2008, 08:36 AM
Post
#6
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 30-July 08 From: New York, New York Member No.: 80,629 Operating System: Windows XP |
Hope you're doing something fun this weekend, Ken!
I transferred all those programs to a CD, but I when I inserted into my laptop, nothing happened. (It worked and ran, but then the usual "open disc" box didn't appear). I then checked "My Computer" and realized I can't access anything I normally can on my computer - the only items present were My Documents. I don' t know how I can open up the disc, or if I'll even be able to. Thank you! |
|
|
|
Aug 9 2008, 09:17 AM
Post
#7
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Can you try downloading HJT from the link in my signature on the bottom of this post? Can you download HostsXpert or Malwarebytes from the infected computer?
|
|
|
|
Aug 9 2008, 09:21 AM
Post
#8
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
I uploaded HJT for you , its a zip file so you will have to unzip it. Then follow the instructions to install it and post the log
Attached File(s)
|
|
|
|
Aug 9 2008, 02:52 PM
Post
#9
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Hi,
Are you making any progress ? I am attaching HostsXpert also, this is what I would do. Unzip HostsXpert to your desktop and run in via my previous instructions, this should prevent you from being redirected by bringing your hosts file back to the Microsoft default. Then if your not redirected, download and run Malwarebytes, then unzip and run Hijackthis. Post the log from Mawarebytes and then the Hijackthis log. Ken
Attached File(s)
|
|
|
|
Aug 12 2008, 12:27 PM
Post
#10
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 30-July 08 From: New York, New York Member No.: 80,629 Operating System: Windows XP |
Hello! Hope you enjoyed your weekend away!
I am not making any progress. I've been e-mailing myself the links you've been sending, and trying to open up or download from there, but I always get redirected or a pop-up makes me stop. So I've been unable to open or download anything you've sent! Any other ideas? Thank you for your continued help! |
|
|
|
Aug 12 2008, 03:52 PM
Post
#11
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Hello,
Lets try this. Boot to Safemode with Network Support. This may take a few tries to get the timing right so don't give up. After you boot to safemode, access this site and try to download HJT and post the log. To Enter Safemode
Tutorial if you need it How to boot into Safemode If you can try running Malwarebytes. I am going to give you a few other programs to run, try downloading them in Safemode, one should work. You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site. Download SmitfraudFix Extract the content (a folder named SmitfraudFix) to your Desktop.
The report can also be found at the root of the system drive, usually at C:\rapport.txt Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
|
|
|
|
Aug 18 2008, 08:09 AM
Post
#12
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 30-July 08 From: New York, New York Member No.: 80,629 Operating System: Windows XP |
Hi Ken!
So... it seems like the steps you had me do in Safemode really helped clean my computer up! It seems like those annoying pop-ups are gone, finally. YAY! Thanks so much for all your help! Some of my Administrative settings seem to be a bit funky still though. For example, my clock shown on the toolbar on the bottom of my computer is in military time and says "SAFETY ALERT" or something like that. I can at least get into my Control Panel now, but it looks like my clock settings are where I'd want them to be. Below please find the text file you asked me to include, which appeared after the SmitfraudFix action. (I'm not sure this is relevant, but I had to do it twice before a text file popped up). I don't know what a HijackThis log is though, sorry. And also, I was unable to download Deckard's System Scanner to my desktop. Thank you! SmitFraudFix v2.337 Scan done at 23:16:56.03, Sun 08/17/2008 Run from C:\Documents and Settings\Administrator.JESSICAELKER.000\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» VACFix VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri C:\WINDOWS\nfavxwdbxpw.dll deleted. C:\WINDOWS\fdkowvbp.dll deleted. »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix S!Ri's WS2Fix: LSP not Found. »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\privacy_danger\ Deleted C:\Program Files\PCHealthCenter\ Deleted C:\Program Files\VAV\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» IEDFix IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» RK »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel® PRO/Wireless 2915ABG Network Connection - Packet Scheduler Miniport DNS Server Search Order: 192.168.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\..\{8B48C28B-C75A-4860-BDA0-D59877587AAA}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{8B48C28B-C75A-4860-BDA0-D59877587AAA}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{8B48C28B-C75A-4860-BDA0-D59877587AAA}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End |
|
|
|
Aug 18 2008, 10:13 AM
Post
#13
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Hi,
I would like to see the Deckard report along with a new HJT log please. |
|
|
|
Aug 18 2008, 11:39 AM
Post
#14
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 30-July 08 From: New York, New York Member No.: 80,629 Operating System: Windows XP |
Absolutely, but what is the Deckard report (or where can I get it), and how do I do anHJT log? Sorry, I'm not the most computer saavy. Thank you!
|
|
|
|
Aug 18 2008, 11:58 AM
Post
#15
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Lets bypass Deckard for the time being but I need to see a Hijackthis log to see if there is anything else we have to go after.
Download Trendmicros Hijackthis to your desktop.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
6 | Boston | 44 | Today, 08:14 PM Last post by: Tomk |
|||
![]() |
18 | MotownMark | 232 | Today, 07:32 PM Last post by: mschroe919 |
|||
![]() |
0 | electriccrayon | 7 | Today, 12:01 PM Last post by: electriccrayon |
|||
![]() |
1 | Ted Guinness | 28 | Today, 11:40 AM Last post by: John B.. |
|||
|
Time is now: 8th January 2009 - 11:33 PM |