Home / Software / Computer viruses and spyware / VIRUS HELP
0 Members and 2 Guests are viewing this topic. « previous next »
Pages: 1 2 [All] - (Bottom) Print
Author Topic: VIRUS HELP  (Read 1978 times)
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« on: September 05, 2009, 12:49:38 AM »

I am using windows xp.
sony vaio, media center edition 2005

i am using avg8.5 and malwarebytes' anti malware.(not sure i should be running both at the same time).

This blue screen pops up, dont know what is says, flashes too quickly for me to read it. I run it on safe mode. I couldnt run the avg before, it would quit on me, but now its running all the way.

results of the scan from avg: 2 threats found "C:\WINDOWS\system32\drivers\ntfs.sys";"Virus identified Packed.Protector.C";"Object is white-listed (critical/system file that should not be removed)"

computer running slow,sometimes i can get on line, sometimes i cant. cant run internet explorer, downloaded firefox.


 

[attachment deleted by admin]
IP logged
876543219
Beginner



Thanked: 3
Posts: 117


« Reply #1 on: September 05, 2009, 01:16:45 AM »

http://www.computerhope.com/forum/index.php/topic,46313.0.html

go to above , complete , post the 3 logs here an expert will see them
IP logged

Believe half of what you see and none of what you hear                     microsoft windows xp professional  version 2002 service pack 3 celeron 2.80ghz 20gb hardrive 504mb ram
Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #2 on: September 05, 2009, 05:08:10 AM »

Please upgrade HJT to version 2.0.2 and create another log....
IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« Reply #3 on: September 05, 2009, 06:15:43 AM »

Thanks for the fast response. i have downloaded everything advised, waiting for scans to be completed to post logs.

Thanks
IP logged
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« Reply #4 on: September 05, 2009, 09:04:27 AM »

1.) SuperAntispyware
2.) Malwarebytes' Anti-Malware
3.) HJT log file


These three processes took hours, 7 maybe 8. When i needed to restart computer after downloads, it would restart, show start menu, background pic, but i couldn't do anything, i had to restart the computer a couple times to get it running.
AVG dropped my firewall, when i clicked on AVG to put the firewall back up, comp froze, had to restart.
Kept getting NTAUTHORITY/SYSTEM status code 107374819 warnings, system restarted 2 maybe 3 times.

while i was using malwarebytes and superantispyware AVG would show pop up alerts saying these files were virus.

Hope i've given enough details, if not, please let me know.

Thanks for the assistance and fast responses.
Fevah


[attachment deleted by admin]
IP logged
Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #5 on: September 05, 2009, 09:34:18 AM »

Go the process tool, enter your HJT log and follow directions for cleaning.....http://www.computerhope.com/cgi-bin/process.pl
IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« Reply #6 on: September 05, 2009, 07:05:42 PM »

I followed all the steps given. Here's my new HJT log. Computer seems to be running as it should be. Ran Malwarebytes, clean. updated programs, I hope i did all this right.

Again, Karnac  thanks for the super fast response to my dilemma/*censored*/migraine. Hope it worked.

Hope I did it right.

[attachment deleted by admin]
IP logged
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« Reply #7 on: September 05, 2009, 08:38:54 PM »

AVG just ran its scheduled scan.

The virus C:\windows\system32\drivers\ntfs.sys Virus identified as Packed.Protector.C
(object white-listed[critical/system file that should not be removed])

still infected, and with about 20 other warnings. although computer seems to be running normal/everything working as should scans coming up infected.

Dont know if AVG is giving positive reads, it wasnt before.
IP logged
Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #8 on: September 06, 2009, 09:17:48 AM »

Here's the link to the analysis of your HJT log.

http://www.computerhope.com/cgi-bin/process.pl?o=681547

Follow the directions for cleaning......
IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« Reply #9 on: September 06, 2009, 07:42:49 PM »

Yeah, no! Im not going to assume I know what im supposed to be doing because I dont. I dont understand what im supposed to do with

Verify your IE settings:

I understand everything after that.

Please forgive my ignorance, and thank you for your assistance and patience.

FEVAH
IP logged
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« Reply #10 on: September 07, 2009, 05:13:54 PM »

I don't have internet explorer to be able to check those settings.
IP logged
SuperDave
Malware Removal Specialist
Moderator
Prodigy



Thanked: 617
Posts: 7,007

Certifications: List
Experience: Experienced
OS: Windows XP



« Reply #11 on: September 07, 2009, 05:21:56 PM »

Fevah, it means exactly what it say.
Quote
Verify the below links correctly correspond to the web pages you want to be using. If these links are not recognizable it's possible your browser has been hijacked. To fix these settings check the corresponding boxes in the R0-R4 section.
If you're not getting the correct pages when you open and work with your IE, then you will have to fix some of these.
IP logged

AMD Athlon XP 1900+ 1.47 GHz  3 GB Ram Windows XP  Home with SP3, MicroSoft Security Essentials, Spybot S&D. SuperAntiSpyware  and Threatfire with Comodo Firewall & Windows Defender
Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #12 on: September 07, 2009, 05:34:22 PM »

Dont know if AVG is giving positive reads, it wasnt before.

Perhaps you should also try another AV to keep AVG honest.

Try...

 http://evilfantasy.wordpress.com/bitdefender-rescue-usb/
IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« Reply #13 on: September 07, 2009, 08:00:42 PM »

Here's the new HJT log file.
Thank you all for pointing me in the right direction.

Fevah

[attachment deleted by admin]
IP logged
Karnac
Mentor



Thanked: 211
Posts: 1,987


« Reply #14 on: September 07, 2009, 08:17:43 PM »

So, here's the link for the process tool analysis of your HJT log.

http://www.computerhope.com/cgi-bin/process.pl?o=719649

Follow the directions for cleaning and you'll also have to use LSP fix for one of your entries.
Download LSP fix and hilite the file to remove on the left hand side and move it to the right hand side and remove it.
Any questions, just follow up
IP logged



Never argue with a stupid person, they'll drag you down to their level and beat you with experience.
FEVAH
Topic Starter
Greenhorn



Thanked: 1
Posts: 9


STREETSRUS.COM
« Reply #15 on: September 09, 2009, 10:24:26 AM »

My computer seems to be getting worse. ccleaner/superantispyware/malwarebytes/avg are still finding viruses. Their multiplying! Computers extremely slow, keeps freezing on me, I keep having to reboot it.

I found:

trace.pandex c:\documents and settigns\oashdihasidhasuidhiasdhiashdiuasdhasd

rogue

trajan

and more.....

invasion of the computer viruses. what do i do? :||x

[attachment deleted by admin]
IP logged
xon1234
Newbie



Posts: 1


« Reply #16 on: December 05, 2009, 01:15:54 AM »

I had the same problem but i ran "Spyware Cease" and it solved it for me. It found a trojan and killed it !!
IP logged
Pages: 1 2 [All] - (Top) Print 
Home / Software / Computer viruses and spyware / VIRUS HELP « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.137 seconds with 20 queries.