Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: I've got this Freakin' internet security 2010 stuff..  (Read 3674 times)

0 Members and 1 Guest are viewing this topic.

shadowman-x

    Topic Starter


    Starter

    I've got this Freakin' internet security 2010 stuff..
    « on: January 16, 2010, 01:48:30 AM »
    so, i followed everyones advice, got malwarebyes adn tried to install it from a USB disk, restarted, even got a force delete program to delete what little i could but i still dont have admin priveleges (on the ONLY ADMIN ACCOUNT) so none of the malware removal programs are working.
    I'm stumped, frustrated, sad & COMPLETELY not computer savvy at all. I can type well, that's about it.
    I make freakin' knives for a hobby, i'm a simpleton.
    Please help me fix my broken magic light box machine.  :-[

    harry 48



      Egghead

    • lay back , relax and chill out
    • Thanked: 129
      • Yes
      • Yes
      • Yes
      • Dribbling Pensioner
    • Certifications: List
    • Experience: Familiar
    • OS: Windows 7
    Re: I've got this Freakin' internet security 2010 stuff..
    « Reply #1 on: January 16, 2010, 07:08:51 AM »
    re-name , mbam.exe to mbam2.exe and run

                      or

    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    go to above and complete and post 3 logs an expert will see them

    shadowman-x

      Topic Starter


      Starter

      Re: I've got this Freakin' internet security 2010 stuff..
      « Reply #2 on: January 16, 2010, 11:35:46 AM »
      I've already tried to install all of those programs, it's blocked administrator priveleges, I can't even update windows. I can't install a single one of those programs. Should I install Mbam ONTO the USB stick  and run it from there?

      harry 48



        Egghead

      • lay back , relax and chill out
      • Thanked: 129
        • Yes
        • Yes
        • Yes
        • Dribbling Pensioner
      • Certifications: List
      • Experience: Familiar
      • OS: Windows 7
      Re: I've got this Freakin' internet security 2010 stuff..
      « Reply #3 on: January 16, 2010, 11:48:45 AM »
      Download a boot time anti virus scanner (pick one: http://www.google.com/search?hl=en&rlz=1T4GGLL_enUS304US305&ei=WHFCS-DZLMW8lAeTsP2fBw&sa=X&oi=spell&resnum=0&ct=result&cd=1&ved=0CAYQBSgA&q=download+boot+time+av+scanner&spell=1). Burn it to a cd and put the cd in the infected computer. Make sure the cd is at the top of the boot order in bios, then boot to the cd and run the scan.

                                                     or

      Hello and welcome to Computer Hope Forum. The first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, We will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate.

      shadowman-x

        Topic Starter


        Starter

        Re: I've got this Freakin' internet security 2010 stuff..
        « Reply #4 on: January 17, 2010, 12:23:00 AM »


        Avira AntiVir Personal
        Report file date: Thursday, January 20, 2000  21:10

        Scanning for 1543014 virus strains and unwanted programs.

        Licensed to:      Avira AntiVir Personal - FREE Antivirus
        Serial number:    0000149996-ADJIE-0000001
        Platform:         Windows XP
        Windows version:  (Service Pack 2)  [5.1.2600]
        Boot mode:        Normally booted
        Username:         SYSTEM
        Computer name:    NOAH

        Version information:
        BUILD.DAT     : 8.2.0.354      17048 Bytes  10/23/2009 13:15:00
        AVSCAN.EXE    : 8.1.4.10      315649 Bytes  11/18/2008 17:21:26
        AVSCAN.DLL    : 8.1.4.0        40705 Bytes   5/26/2008 16:56:40
        LUKE.DLL      : 8.1.4.5       164097 Bytes   6/12/2008 21:44:19
        LUKERES.DLL   : 8.1.4.0        12033 Bytes   5/26/2008 16:58:52
        ANTIVIR0.VDF  : 7.10.0.0    19875328 Bytes   11/6/2009 04:39:44
        ANTIVIR1.VDF  : 7.10.1.11    1395568 Bytes  11/19/2009 04:39:51
        ANTIVIR2.VDF  : 7.10.2.193   2157984 Bytes   1/14/2010 21:04:57
        ANTIVIR3.VDF  : 7.10.2.201    201728 Bytes   1/15/2010 21:02:03
        Engineversion : 8.2.1.142
        AEVDF.DLL     : 8.1.1.2       106867 Bytes   9/15/2009 21:03:22
        AESCRIPT.DLL  : 8.1.3.7       594296 Bytes    1/3/2010 21:02:19
        AESCN.DLL     : 8.1.3.1       127348 Bytes    1/6/2010 21:06:19
        AESBX.DLL     : 8.1.1.1       246132 Bytes  11/28/2009 04:39:59
        AERDL.DLL     : 8.1.3.4       479605 Bytes   12/1/2009 04:38:57
        AEPACK.DLL    : 8.2.0.5       422262 Bytes    1/6/2010 21:06:15
        AEOFFICE.DLL  : 8.1.0.38      196987 Bytes   8/25/2009 02:25:58
        AEHEUR.DLL    : 8.1.0.195    2232695 Bytes    1/6/2010 21:06:06
        AEHELP.DLL    : 8.1.10.0      237942 Bytes    1/6/2010 21:05:16
        AEGEN.DLL     : 8.1.1.83      369014 Bytes    1/3/2010 21:02:10
        AEEMU.DLL     : 8.1.1.0       393587 Bytes   10/3/2009 22:17:03
        AECORE.DLL    : 8.1.9.5       184693 Bytes    1/6/2010 21:05:08
        AEBB.DLL      : 8.1.0.3        53618 Bytes  10/14/2008 19:05:56
        AVWINLL.DLL   : 1.0.0.12       15105 Bytes    7/9/2008 17:40:05
        AVPREF.DLL    : 8.0.2.0        38657 Bytes   5/16/2008 18:28:01
        AVREP.DLL     : 8.0.0.3       155688 Bytes   8/25/2009 02:25:45
        AVREG.DLL     : 8.0.0.1        33537 Bytes    5/9/2008 20:26:40
        AVARKT.DLL    : 1.0.0.23      307457 Bytes   2/12/2008 17:29:23
        AVEVTLOG.DLL  : 8.0.0.16      119041 Bytes   6/12/2008 21:27:49
        SQLITE3.DLL   : 3.3.17.1      339968 Bytes   1/23/2008 02:28:02
        SMTPLIB.DLL   : 1.2.0.23       28929 Bytes   6/12/2008 21:49:40
        NETNT.DLL     : 8.0.0.1         7937 Bytes   1/25/2008 21:05:10
        RCIMAGE.DLL   : 8.0.0.51     2371841 Bytes   6/12/2008 22:48:07
        RCTEXT.DLL    : 8.0.52.0       86273 Bytes   6/27/2008 22:34:37

        Configuration settings for the scan:
        Jobname..........................: Complete system scan
        Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
        Logging..........................: low
        Primary action...................: interactive
        Secondary action.................: ignore
        Scan master boot sector..........: on
        Scan boot sector.................: on
        Boot sectors.....................: C:,
        Process scan.....................: on
        Scan registry....................: on
        Search for rootkits..............: off
        Scan all files...................: Intelligent file selection
        Scan archives....................: on
        Recursion depth..................: 20
        Smart extensions.................: on
        Macro heuristic..................: on
        File heuristic...................: medium

        Start of the scan: Thursday, January 20, 2000  21:10

        The scan of running processes will be started
        Scan process 'avscan.exe' - '1' Module(s) have been scanned
        Scan process 'avcenter.exe' - '1' Module(s) have been scanned
        Scan process 'audacity.exe' - '1' Module(s) have been scanned
        Scan process 'firefox.exe' - '1' Module(s) have been scanned
        Scan process 'killbox.exe' - '1' Module(s) have been scanned
        Scan process 'explorer.exe' - '1' Module(s) have been scanned
        Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
        Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
        Scan process 'Ymsgr_tray.exe' - '1' Module(s) have been scanned
        Scan process 'Vid.exe' - '1' Module(s) have been scanned
        Scan process 'daemon.exe' - '1' Module(s) have been scanned
        Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
        Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
        Scan process 'smss32.exe' - '1' Module(s) have been scanned
        Scan process 'LWS.exe' - '1' Module(s) have been scanned
        Scan process 'avgnt.exe' - '1' Module(s) have been scanned
        Scan process 'winampa.exe' - '1' Module(s) have been scanned
        Scan process 'qttask.exe' - '1' Module(s) have been scanned
        Scan process 'SMax4.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
        Scan process 'ehtray.exe' - '1' Module(s) have been scanned
        Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
        Scan process 'alg.exe' - '1' Module(s) have been scanned
        Scan process 'dllhost.exe' - '1' Module(s) have been scanned
        Scan process 'YahooAUService.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
        Scan process 'LVPrcSrv.exe' - '1' Module(s) have been scanned
        Scan process 'jqs.exe' - '1' Module(s) have been scanned
        Scan process 'ehSched.exe' - '1' Module(s) have been scanned
        Scan process 'ehRecvr.exe' - '1' Module(s) have been scanned
        Scan process 'avgemc.exe' - '1' Module(s) have been scanned
        Scan process 'avgupsvc.exe' - '1' Module(s) have been scanned
        Scan process 'avgamsvr.exe' - '1' Module(s) have been scanned
        Scan process 'avguard.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'sched.exe' - '1' Module(s) have been scanned
        Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'lsass.exe' - '1' Module(s) have been scanned
        Scan process 'services.exe' - '1' Module(s) have been scanned
        Scan process 'winlogon.exe' - '1' Module(s) have been scanned
        Scan process 'csrss.exe' - '1' Module(s) have been scanned
        Scan process 'smss.exe' - '1' Module(s) have been scanned
        49 processes with 49 modules were scanned

        Starting master boot sector scan:
        Master boot sector HD0
            [INFO]      No virus was found!
        Master boot sector HD1
            [INFO]      No virus was found!
            [WARNING]   System error [21]: The device is not ready.
        Master boot sector HD2
            [INFO]      No virus was found!
            [WARNING]   System error [21]: The device is not ready.
        Master boot sector HD3
            [INFO]      No virus was found!
            [WARNING]   System error [21]: The device is not ready.
        Master boot sector HD4
            [INFO]      No virus was found!
            [WARNING]   System error [21]: The device is not ready.

        Start scanning boot sectors:
        Boot sector 'C:\'
            [INFO]      No virus was found!

        Starting to scan the registry.
        The registry was scanned ( '63' files ).


        Starting the file scan:

        Begin scan in 'C:\'
        C:\pagefile.sys
            [WARNING]   The file could not be opened!
        C:\System Volume Information\_restore{DB97561B-5F82-4714-8981-7435806ABFD7}\RP516\A0111112.pif
            [DETECTION] The file contains an executable program that is disguised by a harmless file extension (HIDDENEXT/Crypted)
            [NOTE]      The file was moved to '38b8f6b4.qua'!
        C:\WINDOWS\system32\ntos.exe
            [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
            [NOTE]      The file was moved to '38f70265.qua'!
        C:\WINDOWS\system32\~.exe
            [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
            [NOTE]      The file was moved to '38ed02ad.qua'!
        C:\WINDOWS\system32\drivers\sptd.sys
            [WARNING]   The file could not be opened!


        End of the scan: Thursday, January 20, 2000  22:55
        Used time:  1:45:05 Hour(s)

        The scan has been done completely.

          10245 Scanning directories
         253235 Files were scanned
              3 viruses and/or unwanted programs were found
              0 Files were classified as suspicious:
              0 files were deleted
              0 files were repaired
              3 files were moved to quarantine
              0 files were renamed
              2 Files cannot be scanned
         253230 Files not concerned
           7695 Archives were scanned
              6 Warnings
              3 Notes

        htis iss what my antivirus found.

        harry 48



          Egghead

        • lay back , relax and chill out
        • Thanked: 129
          • Yes
          • Yes
          • Yes
          • Dribbling Pensioner
        • Certifications: List
        • Experience: Familiar
        • OS: Windows 7
        Re: I've got this Freakin' internet security 2010 stuff..
        « Reply #5 on: January 17, 2010, 01:04:34 PM »
        just try the other 3 and see if you can get the logs an expert should be along