|
#1
|
|||
|
|||
|
Hey there, last time I was here it was April, and I had a PC-Antispyware problem, and it seems I now have a new one.
I am having a really hard time trying to get HijackThis to open at all, so I can't even post a log for you. And I ran Malwarebytes and can't find the log for that either (And I know where I have to look, but I can't seem to get to the right folder?) As far as what I'm experiencing, my Spybot S&D was giving me a lot of "Allow this?" suddenly when I was trying to find a new episode of a show I watch, and I kept denying, but they kept popping up. Suddenly my computer kept warning me about how my computer is not protected, etc. It just suddenly shut off on me with a blue screen explaining that if it were the first time I saw that warning, to try and reboot and look for the problem, and then it said "beep.sys" as the problem? I'm not too sure. Needless to say, it took me a long time to get myself rebooted, because it kept freezing or not loading properly. I got into Safe Mode and performed a scan through Malwarebytes. It found 28 problems, and I deleted/quarantined it all. Then I rebooted normally, and now I have this pop up which I know is not a good sign: ![]() So, how can I get HJT to work to show you whats going on? :[ EDIT I think I have this Brastk problem as I've read a few others, and I do remember spybot trying to have me allow that and I kept saying no, and now none of my anti spyware stuff is working. I am going to attempt to get SAS and will update soon. so i went into safe mode and deleted the karna and brastk files from inside c\windows and c\windows\system32. i couldn't find an antivirus 2009 file anywhere, so i am going to assume that i didn't get that. but im stuck now, seeing as HJT and antimalware bytes is not opening, and i cant download SAS! what do i do?? ok, was able to locate the MBAM log! I hope this will reveal something. tricked my computer into letting me download and open SAS! will post log as soon as I can get it. Hope someone reads this soon :[ so i did a quick scan with SAS, because the full scans were not working for me (the computer kept freezing after an hour, both times that i tried), so attached is the log. i rebooted, but the weird notice is still popping up from my tray. i hope someone will look at this :[ will anyone look and help, please? Last edited by kimsland; 02-26-2009 at 09:07 AM.. |
|
#2
|
||||
|
||||
|
Did you try renaming hijackthis.exe to crusty.exe like before? Combofix will show everything that hijackthis would anyways, so don't worry if you can't get it to run
Download and Install SDFix
Boot into Safe Mode
Run SDFix
=============================================== Run Smitfraudfix
===============================================
Combofix will automatically save the log file to C:\combofix.txt Attach Here: 1) Report.txt from SDfix 2) Rapport.txt from Smitfraudfix 3) Combofix.txt Last edited by Blind Dragon; 11-18-2008 at 10:30 AM.. |
|
|
|
#3
|
|||
|
|||
|
BlindDragon,
First off, thank you so much for the quick reply. I know you must be busy, and I appreciate you taking the time to help me once again. Yes, I had HJT renamed as Crusty.exe from the first time I used it back in April. I hadn't renamed it since, which makes me extremely confused as to why it's not working now. Unfortunately, it seems this virus is smarter than most, and won't let me download SDFix or ComboFix from the links you posted. I tried to find an alternate link on search engines (Google, Yahoo), but whenever I click a link where it's available, I get redirected to a random site. As for Smitfraudfix, I was able to download it, but in order to run it I had to change it's name (smitty.exe) to have it work. This is the only log out of the three that I can give you. EDIT! I got HJT to finally work! Had to move it outside its folder. Attached is that log. Last edited by jojoness; 11-18-2008 at 04:32 PM.. |
|
#4
|
||||
|
||||
Run Smitfraudfix
Also empty your recycle bin Try SDFix and Combofix again. |
|
#5
|
|||
|
|||
|
Blind, I will do that next. I just wanted to let you know that I got HJT to work and I posted the log in the previous post.
|
|
#6
|
||||
|
||||
|
Perfect, let me know once you have done the next step. About half the files are infected in there. Also, did you run a temp file cleaner like CCleaner or ATF cleaner? because there are a number of infected temp files that are also being autostarted from the registry. And it will decrease scan times with less temp files.
|
|
#7
|
|||
|
|||
|
I ran Smitfraudfix like you said if Safe Mode, but when it came for the program to remove temp files, smit disappeared, leaving the Disk Cleanup window up, but after 3-5 minutes, that disappeared as well, then there was just a black screen. I thought perhaps Smit would start up again, as if it were doing something without showing, but nothing happened about 5-10 minutes. I did this twice, and it happened both times.
I am running Disk Cleaner right now on normal mode. Hopefully the temp files will go this way, and I can run Smit again and hope for it to complete. |
|
#8
|
||||
|
||||
|
Did it get to the point where it asked you to clean the registry?
Also check to see if there was a log produced? If not, then run it again. If there is attach the log here Sometimes you have to reboot, and it will start up again after - look for logs in the root C:\rapport.txt |
|
#9
|
|||
|
|||
|
No, I never reached that point.
I cleaned out temp files while on Safe Mode too, to be sure they were gone, and when I ran Smit again, the same thing happened. I'm not too sure whats going on? But it seems to have left a log, which i will attach here. |
|
|
|
#10
|
||||
|
||||
|
Good. Now let's see if SDFix or Combofix will run.
Also can you go ahead and attach a fresh hijackthis log |
|
#11
|
|||
|
|||
|
nope, no luck on sdfix or combofix. here's fresh hjt.
|
|
#12
|
||||
|
||||
|
Ok, let's do the first part the hard way then.
Remove bad HijackThis entries
========================== OTMoveit3 by OldTimer Please download the OTMoveIt3 by OldTimer.
*if Otmoveit3 doesn't work let me know and we can try avenger |
|
#13
|
||||
|
||||
|
I forgot to mention you can rename combofix.exe but you need to uninstall it first, then rename it when you are downloading it.
|
|
#14
|
|||
|
|||
|
Alright, did HJT instructions, and as I checked "Fix", I had numerous pop ups telling me the admin was not allowing me to delete the keys, but I'm not sure if it did or not, because it seemed that HJT was able to complete? I'll post up a fresh log if you want me to.
And no, the 2nd program did not work. Quote:
I forgot to mention that the pop up in my tray has disappeared, but I still can't click the links you give me. Last edited by kimsland; 02-26-2009 at 09:08 AM.. |
|
#16
|
|||
|
|||
|
still no go :[ if i click it, i get a blank window open up. if i right click and save link as... then i get this:
![]() Sigh. |
|
#17
|
||||
|
||||
|
can you copy and paste this into your browser
http://www.forospyware.com/sUBs/ComboFix.exe If not we will go back to trying scripts and yes please attach a fresh hijackthis log |
|
#18
|
|||
|
|||
|
Address still doesn't work. Since I'm in firefox, I get a blank page. With IE, it says:
Internet Explorer cannot display the webpage Most likely causes: You are not connected to the Internet. The website is encountering problems. There might be a typing error in the address. There's still something preventing me from getting these :[ Oh, and fresh HJT! Last edited by kimsland; 02-26-2009 at 09:08 AM.. |
|
#19
|
||||
|
||||
|
registry editor is still disabled, so we will fix that, and if you don't mind I would like to continue experimenting a little bit to make things easier for everyone in the long run.
======================================= Making a .reg file Open notepad and copy and paste the text in the quotebox below in it: Code:
REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"=- "NoDispCPL"=- "DisableRegistryTools"=- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"=- "DisableRegedit"=- "NoDispCPL"=- "DisableTaskMgr"=- Change the "Save As" type to "All Files" and save it on the desktop. It should look like this: ![]() Double-click on it and when it asks you if you want to merge the contents to the registry, click yes/ok. ======================================== Download the AVZ Antiviral Toolkit. Extract it from the archive to its own folder. * Start AVZ and update its databases ("File" => "On-line automatic update "). Choose from the menu "File" => "Standard scripts " and mark the "Healing/Quarantine and Advanced System Investigation" check box. Click on the “Execute selected scripts”. Automatic scanning, healing and system check will be executed. A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip. Once scanning is finished, please attach the zipped logfile (virusinfo_syscure.zip) to your post. =========================================================== |
|
#20
|
|||
|
|||
|
Made the file, tried to open and I got a pop up saying "Registry editing has been disabled by your admin" and I can't get the link open for the other program.
This is a real bummer. Hey I have an idea, let me know if this would work or not: Do you think it would work to get these programs if i downloaded them onto a flash drive from my boyfriend's computer? That way, I can rename and run them here. Last edited by kimsland; 02-26-2009 at 09:09 AM.. |
![]() |
| Tags |
| hjt, spyware |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Malware/spyware problems - fling.com and bogus spyware popups | Virus & Malware removal | 4 | 11-13-2008 10:41 AM | |
| Corrupt Anti-Spyware + Spyware Comparsion | Virus & Malware removal | 2 | 07-05-2008 08:22 PM | |
| Spyware has killed my computer! Tskmgr will not open, keeps reloading spyware | Virus & Malware removal | 12 | 12-14-2005 02:51 AM | |
| desktop: spyware infection:your computer is infected with spyware | Virus & Malware removal | 2 | 12-03-2005 05:14 PM | |
| Trojan.Downloader.KavSvc and Unclassified.Spyware.61 Spyware | Virus & Malware removal | 6 | 08-05-2005 10:47 AM | |
All times are GMT -4. The time now is 06:15 PM.




Run Smitfraudfix


