Hi
I have a wallpaper that has appeared that says " your system is infected! system has been stopped due to a serious malfunction. spyware activity has been detected."…… It has also locked me out of the task manager, system restore etc.. I cannot get online on that computer at all. I have AVG 9.0 and have run it several times the first time I got 13 viruses/warnings removed them and now it is coming up with two each time. I am not sure how to run the clean up programs since I can't get online to access them. I am not sure how to go about fixing this problem. Any help would be appreciated. I am not the computer savvy so simple explanations would be great
hmoore
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
Please make sure to carefully read any instruction that I give you.
Reading too lightly will cause you to miss important steps, which could have destructive effects.
If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together
Because of this, you must reply within five days. I will post a reminder should you seem to fail to do this, however, if you fail to reply within three days then,
unless I have been notified of your absence in advance, the topic shall be closed!
Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system. Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.
I am checking over your log, I will post back shortly with instructions.
I assume you have access to another computer. We are going to need to download a few programs onto your clean computer and then transfer them over to the infected computer. You can use a USB Drive or a blank DVD to copy the files onto.
On the clean computer download the following programs:
1. Download Flash_Disinfector.exe by sUBs from here.
2. Download exeHelper.
3. Download DDS from this link DDS.scr
4. Download GMER Rootkit Scanner from here or here.
NEXT
Please run Flash Disinfector on the USB Drive or DVD on the clean computer. Instructions on how to do this are posted below:
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.
NEXT
Copy and Paste the following programs onto your USB Drive or DVD Drive:
exeHelper
DDS
GMER
Plug the USB Drive into your computer or put the DVD into the DVD drive of your computer.
Continue with the instructions below:
Run exeHelper
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan) Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
In the right panel, you will see several boxes that have been checked. Uncheck the following …
Sections
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Please make sure you include the following items in your next post: 1. The log that was produced after running exeHelper. 2. The logs that were produced after running DDS. (DDS.txt & Attach.txt) 3. The log that was produced after running GMER. 4. An update on how your computer is currently running.
It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Unfortunately, it looks like something happened when you attempted to copy and paste the exeHelper log here. Could you please try to post the log again.
1. 📎exehelperlog.txt
2. 📎DDS.txt
3. 📎dds_attach.txt
Sorry. here are the DDS and the exe helper logs. I can't get the gmer program to run completely. It freezes in the middle and shuts down. Not sure how to get around that.
In the right panel, you will see several boxes that have been checked. Uncheck the following …
Sections
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Post the contents of the GMER.txt log in your next post.
Hello hmoore!
It's been several days since I last posted instructions for you to complete. Do you still require assistance in getting your computer cleaned up?
Thanks,
SweetTech.