Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Please review- Help !!! 3 Different problems !  (Read 3670 times)

0 Members and 1 Guest are viewing this topic.

Spicegirl

    Topic Starter


    Greenhorn
    Please review- Help !!! 3 Different problems !
    « on: January 30, 2010, 09:22:26 PM »
     ???
    - I have tried to download the NEW 9.0 AVG - and it will not load - gets to the end and says it can't be installed. ( I have 8.5 running)
    - I TRIED to load the SuperAntispyware - Website is temporarily unavailable.....
    I did run the hijack This - log attached
    I ran MalwareBytes -Log attached
    I ran AVG in safe mode and got a bunch of problems .. -Log attached
    So far the 3 main issues i have found are -
    Packed.DelfCrypt
    Vundo.JP
    and   Fake Alert.OQ
    I don't even know where to start as everytime I try run the scan it just freezes and shuts down - however I did run AVG in safe mode
    Any help would be greatly appreciated !
     Thanks ,
    M3lani3
     :-[

    [Saving space, attachment deleted by admin]
    M3L !
    :P

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Please review- Help !!! 3 Different problems !
    « Reply #1 on: January 31, 2010, 11:35:25 AM »
    Welcome to CH Spicegirl.

    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    • O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    • O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
    • O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
    • O20 - AppInit_DLLs: 71.dll
    • O20 - Winlogon Notify: d4a6afe8757 - I:\WINDOWS\
    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    Note: Realtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers

    ----------

    Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

    Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

    Exit out of MessengerDisable then delete the two files that were put on the desktop.

    ----------

    If you already have ComboFix be sure to delete it and download a new copy.

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note:  It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
     
    Double click combofix.exe & follow the prompts.
    Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFix

    Spicegirl

      Topic Starter


      Greenhorn
      Re: Please review- Help !!! 3 Different problems !
      « Reply #2 on: January 31, 2010, 01:27:55 PM »
       :-\
      Thank You Evil - I have done as instructed and then did a new log from combo fix...
       I did run the Malware bytes again last night and got it down to 4 infections- still need to upgrade my AVG -
      My IE still hangs - wont move off of the front page .... Only Firefox running at this point- can you help me with that too?? Is it all still connected to the Viruses/ spyware?
       ::)

      Greatly Appreciate all your help ~!
      M3L

      [Saving space, attachment deleted by admin]
      M3L !
      :P

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Please review- Help !!! 3 Different problems !
      « Reply #3 on: January 31, 2010, 01:36:47 PM »
      Let me know how things are after this.



      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It must be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [Select]
      KillAll::

      File::
      i:\program files\Save\Save.exe

      Registry::
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
      "BootExecute"=hex(7):61,75,74,6f,63,68,65,63,6b,20,61,75,74,6f,63,68,6b,20,2a,00,00

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
      "WhenUSave"=-


      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

      Spicegirl

        Topic Starter


        Greenhorn
        Re: Please review- Help !!! 3 Different problems !
        « Reply #4 on: January 31, 2010, 03:18:51 PM »
        Thanks again Evil ..
         I have done as instructed again , and attaching the log ...
        STILL no IE - brings up yahoo homepage , then just sits .. Can't do anything .. Thankfully Firefox , still ok..

        Anymore suggestions to fix the IE ?
         Thanks again !

        M3L !
         ???


        [Saving space, attachment deleted by admin]
        M3L !
        :P

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Please review- Help !!! 3 Different problems !
        « Reply #5 on: January 31, 2010, 03:43:29 PM »
        Download the Fix IE Utility to your desktop.

        Before running the utility, make sure that all your Internet Explorer windows are closed!

        * Extract the contents of the .zip file to your desktop.
        * Double click the Fix IE Utility button to run the tool.
        * Click Run Utility
        * Click OK when you see 'Re-registered all files'
        * Open Internet Explorer and see how it works.


        Let me know how things are now.

        Spicegirl

          Topic Starter


          Greenhorn
          Re: Please review- Help !!! 3 Different problems !
          « Reply #6 on: January 31, 2010, 07:43:05 PM »
           :-*
           THANK YOU, THANK YOU, THANK YOU !!!!!
          I **THINK** it is all back to normal now ... I am writing to you again through IE this time (YAY!!)
           I have run AVG and nothing comes up - will run the Malware Bytes again this evening , but seems to be running alot better ...
           Thanks soooo much for all your help Evil!
           I have applied to learn to fight malware(@ GeekPolice Acadamy) to assist others like you have done for me !
          Do I need to delete the combofix , hijack this and various other things from my computer now ? Or shall I keep them just in case?? ( suppose I could always just re-install them all ..)

          Once again , THANK YOU !!!!! (I'd hug ya if I knew ya better !!!)  ;D
          M3L !
          :P

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Please review- Help !!! 3 Different problems !
          « Reply #7 on: January 31, 2010, 11:41:11 PM »
          * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
          * Now type Combofix /Uninstall in the runbox
          * Make sure there's a space between Combofix and /Uninstall
          * Then hit Enter

          * The above procedure will:
          * Delete the following:
          * ComboFix and its associated files and folders.
          * Reset the clock settings.
          * Hide file extensions, if required.
          * Hide System/Hidden files, if required.
          * Set a new, clean Restore Point.

          ----------

          Clean out your temporary internet files and temp files.

          Download TFC by OldTimer to your desktop.

          Double-click TFC.exe to run it.

          Note: If you are running on Vista, right-click on the file and choose Run As Administrator

          TFC will close all programs when run, so make sure you have saved all your work before you begin.

          * Click the Start button to begin the cleaning process.
          * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. 
          * Please let TFC run uninterrupted until it is finished.

          Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

          ----------

          ESET Online Scan

          Scan your computer with the ESET FREE Online Virus Scan

          * Click the ESET Online Scanner button.

          * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
          * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
          * Double click on the esetsmartinstaller_enu.exe icon on your desktop.
          * Place a check mark next to YES, I accept the Terms of Use.

          * Click the Start button.
          * Accept any security warnings from your browser.
          * Leave the check mark next to Remove found threats and place a check next to Scan archives.
          * Click the Start button.
          * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
          * When the scan completes, click List of found threats.
          * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
          * Click the <<Back button then click Finish.

          In your next reply please include the ESET Online Scan Log

          Spicegirl

            Topic Starter


            Greenhorn
            Re: Please review- Help !!! 3 Different problems !
            « Reply #8 on: February 01, 2010, 08:11:14 PM »
            Well, it all SEEMED good ! hhahah ! 
             The ESET found 2 infected files .. ???
             Log Attached ..
             
            Thanks Evil...

            [Saving space, attachment deleted by admin]
            M3L !
            :P

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Please review- Help !!! 3 Different problems !
            « Reply #9 on: February 01, 2010, 10:16:04 PM »
            Those were nothing to worry about.

            Disable/Enable the System Restore Utility to flush old infected restore points

            1) Right click the My Computer icon on the Desktop and click on Properties.
            2) Click on the System Restore tab.
            3) Put a check mark next to Turn off System Restore on All Drives
            4) Click the OK button.
            5) You will be prompted to restart the computer. Click the Yes button.

            Now re-enable System Restore

            To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

            1) Right click the My Computer icon on the Desktop and click on Properties.
            2) Click on the System Restore tab.
            3) Remove the check mark next to Turn off System Restore on All Drives
            4) Click the OK button.

            ----------

            Use the Secunia Software Inspector to check for out of date software.
            • Click Start Now
            • Check the box next to Enable thorough system inspection.
            • Click Start
            • Allow the scan to finish and scroll down to see if any updates are needed.
            • Update anything listed.
            .
            ----------

            Go to Microsoft Windows Update and get all critical updates.

            ----------

            I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

            I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

            SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            * Using SpywareBlaster to protect your computer from Spyware and Malware
            * If you don't know what ActiveX controls are, see here

            Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

            Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

            Use only trusted security software like the programs listed on this page. Trusted security tools & resources

            Spicegirl

              Topic Starter


              Greenhorn
              Re: Please review- Help !!! 3 Different problems !
              « Reply #10 on: February 02, 2010, 08:14:44 PM »
              Thank You for your help Evil -
              I have done as you instructed above - did have to update the Java , and have now added the WOT , so hopefully it helps me out !
               I really appreciate all the help !
              Mel
              M3L !
              :P

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Please review- Help !!! 3 Different problems !
              « Reply #11 on: February 02, 2010, 08:21:41 PM »
              Your welcome.

              Safe surfing...