This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Malware problems - SOS!

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My wife was reading her email this a.m. and strange things started to happen. She heard audio playing but couldn't tell where it was coming from and went to watch a Youtube video but the audio was still playing. She restarted and it went into the blue screen where the physical memory was dumped. On further restarts it would hang up going into windows. I went into safemode and ran AVG where it said it found and quarantined the Win32/Crypter virus. I then ran checkdisk and tried to run disk defragmenter and it states that it cannot start. I was able to to go into windows normally after that but when I went to Google to search on viruses/spyware, the browser was redirected so I feel strongly it has been hijacked. I tried to run Spybot but it would never open it even after downloading it again. I was able to run AdAware which found a few things and SuperAntispyware. I tried a system restore but it will not work. It just hangs up and never fully starts on a previous checkpoint. I was able to enable Tea Timer after downloading Spybot and during a restart it stated it had found two registry changes. I went to post my Hijack This log here but I had an older version so I couldn't post it. I downloaded the newer version but it won't run once I double click on it, and I have had to go back into safe mode as the physical dump has happened several times again. PLEASE HELP!!!!!!! :pullhair:
Hello & Welcome to What the Tech
Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this ensure Enable email notification of replies? is ticked on the Post Reply page.

In the meantime please note the following:
  • Any recommendations made are for your computer problems only and should NOT be used on any other computer.
  • Please DO NOT run any scans/tools or other fixes unless I ask you to. This is very important for several reasons. Here are just two of them:
    1. The tools that we use are very powerful and can cause >>irreparable damage<< to your computer if not used correctly.
    2. Commercial scanners, for the most part can not completely remove some of the more "resistant" infections. This makes it much more difficult to get rid of completely.
  • If you get stuck or are unsure of something please ask for a further explanation, do not guess.
  • Continue to respond to this thread until I give you the All Clean!
Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave & if there is no contact for that amount of time I will have to assume you have abandoned your topic.

Thanks

DDS
Download DDS.scr by sUBs from one of the following links & save it to your desktop.
http://www.techsupportforum.com/sectools/sUBs/dds
http://download.bleepingcomputer.com/sUBs/dds.scr
http://www.forospyware.com/sUBs/dds

  • Double-Click on dds.scr and a command window will appear. This is normal
  • Shortly after a log will appear
  • Click Yes at the next prompt, another log named attach.txt will appear
  • A window will open instructing you to post both logs. Copy the contents of both logs & post in your next reply
Gmer
Download GMER Rootkit Scanner from here.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


To post in next reply:
DDS log
Attach.txt log
Gmer log
jmw3, I very much appreciate you taking the time and effort to respond to my post. Unfortunately I have had to take my computer in to have the viruses removed since I wasn't able to open any downloaded program and my wife uses it for her work. Thank you for your efforts and all you do. Matt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI