TechSpot

Urgent help required

By dommy575
Sep 3, 2009
Topic Status:
Not open for further replies.
  1. hello all,

    i clicked on a site today and my computer went beserk!! i ran a AVG free scan which found some viruses but didnt get rid of them, its like someone is controlling my computer!! i have tried downloadin malware byte etc but it just crashes when i try installing it, it has happend with other applications where it says i dont have privelages to run etc, pleae please please i need you help guys!! i can get on internet ok, but music plays in backgound although nothing open and when i google sumthing it doesnt take me to the desired page!!

    this is what my AVG free found

    "\\?\globalroot\systemroot\system32\UACxdvfpjyevj.dll";"Virus found Win32/Cryptor";"Moved to Virus Vault"
    "\\?\globalroot\systemroot\system32\UACxdvfpjyevj.dll";"Virus found Win32/Cryptor";"Moved to Virus Vault"
    "\\?\globalroot\systemroot\system32\UACxdvfpjyevj.dll";"Virus found Win32/Cryptor";"Moved to Virus Vault"
    "\\?\globalroot\systemroot\system32\UACxdvfpjyevj.dll";"Virus found Win32/Cryptor";"Moved to Virus Vault"
    "\\?\globalroot\systemroot\system32\UACxdvfpjyevj.dll";"Virus found Win32/Cryptor";"Moved to Virus Vault"
    "C:\Program Files\Internet Explorer\iexplore.exe (1116)";"Virus found Win32/Cryptor";""
    "C:\Program Files\Internet Explorer\iexplore.exe (1300)";"Virus found Win32/Cryptor";""
    "C:\Program Files\Internet Explorer\iexplore.exe (180)";"Virus found Win32/Cryptor";""
    "C:\Program Files\Internet Explorer\iexplore.exe (2832)";"Virus found Win32/Cryptor";""
    "C:\WINDOWS\explorer.exe (308)";"Virus found Win32/Cryptor";""


    saying 10 viruses found - moved and healed 5 but not removed or healed 5.

    i have been on the forums and been advised to download specific spyware tool, the only problem is my computer blocks me 'running' the programme. i cannot get you specific rootrepeal info because my computer says ' windows cannot access the specified device, path or file. you may not have the appropriate permissions to access the item'

    music plays in the background although no internet window is open etc

    please find attached the result of my DDS

    i also have sophos info if you require that also?

    many thanks for your time in resolving this matter, i look forward to receiving your expert advice!

    thank you

    dom
     

    Attached Files:

    • DDS.txt
      File size:
      14.9 KB
      Views:
      6
  2. dommy575

    dommy575 TS Rookie Topic Starter

    forgot to say the virus is stopping me from downloading any Anti spyware product.... wont even let me run AVG scan now!!!
     
  3. dommy575

    dommy575 TS Rookie Topic Starter

    just ran a symantec online scan - results are below -

    D:\Documents and Settings\Domo\Local Settings\Temporary Internet Files\Content.IE5\EJINI9I3\Antivirus_95[1].exe is infected with Trojan.Fakeavalert
    D:\Documents and Settings\Domo\Local Settings\Temp\Temporary Internet Files\Content.IE5\FF3OCIX1\functions.js[1].htm is infected with Downloader
    C:\WINDOWS\Temp\NSIS_Install_igb.exe is infected with InternetGameBox
    C:\WINDOWS\Temp\NSIS_Install_igb.exe is infected with Adware.Gen


    does this help at all

    many thanks
     
  4. snowchick7669

    snowchick7669 TS Maniac Posts: 698

    I suspect that no one here currently has the expertise to read a DDS log.

    You may be instructed to follow the 8 steps as pointed out here

    However, with the temporary lack of trained malware staff you may wish to try Tech-101 or Geeks to Go :)
     
  5. brucethetech

    brucethetech TS Enthusiast Posts: 301

    i've never heard of dds but it looks no different than hjt or any other query application. cryptor is not hard to remove. trash everything in the vault, dump your temporary internet files, give it a restart, and run the scan again. If you can't scan reboot in safe mode and check your startup application in the registry at hklm/software/microsoft/windows/current version/run.
     
  6. brucethetech

    brucethetech TS Enthusiast Posts: 301

    FYI you may be able to manually remove the ones reported by norton since you know their location. until the infection is clean they may come back but give it a shot
     
  7. dommy575

    dommy575 TS Rookie Topic Starter

    right...new problem... i think it has removed the shortcut on my desktop for internet explorer, every time i click on it it just doesnt do anything. does anyone know how to get my explorer back on line??

    im only on here now using safari which was downloaded with my iphone

    many thanks

    dom
     
  8. brucethetech

    brucethetech TS Enthusiast Posts: 301

    you did only remove the ones reportd by norton? if youve deleted iexplorer.exe you need to reinstall IE in add/remove programs/ add or remove windows components
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.