Author Topic: [Inactive] Possible infection - need help  (Read 1969 times)

0 Members and 1 Guest are viewing this topic.

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22637
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Possible infection - need help
« Reply #15 on: January 17, 2012, 08:02:14 PM »
Try downloading a new copy and installing it. Then go thru the regular uninstall procedure, then run the removal tool and see what happens. If that does not work, I will try and get you manually cleaning procedures.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline mess89

  • Bronze Member
  • Posts: 97
Re: [In Progress] Possible infection - need help
« Reply #16 on: January 17, 2012, 08:31:26 PM »
error messages with whatever I try with AVG

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22637
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Possible infection - need help
« Reply #17 on: January 17, 2012, 09:00:54 PM »
Lets try another way. Download Windows Installer Cleanup and then run the file to install the program. Now run Windows Installer Cleanup and scroll down to AVG and then click the remove button. There may be more than one entry for AVG. You have to do each one.

Let me know if that works.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline mess89

  • Bronze Member
  • Posts: 97
Re: [In Progress] Possible infection - need help
« Reply #18 on: January 18, 2012, 06:59:50 AM »
seems it is uninstalled now.  what is the next step.  should I reinstall AVG?

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22637
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Possible infection - need help
« Reply #19 on: January 18, 2012, 08:07:49 AM »
Yes.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline mess89

  • Bronze Member
  • Posts: 97
Re: [In Progress] Possible infection - need help
« Reply #20 on: January 18, 2012, 07:55:35 PM »
OK AVG reinstalled and updated successfully.   windows update still not working.  error code 80096001.

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22637
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Possible infection - need help
« Reply #21 on: January 18, 2012, 08:02:03 PM »
Go to this page and run the fixit on this page. If it gives you the option, run the repair in aggressive mode. Once it is done reboot the computer and run windows update. Let me know if you get all, some or none of the updates to install. Also any error messages if they are different than the one you already get.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline mess89

  • Bronze Member
  • Posts: 97
Re: [In Progress] Possible infection - need help
« Reply #22 on: January 18, 2012, 08:14:45 PM »
ran the fixit, still not updating, same error code.

Offline mess89

  • Bronze Member
  • Posts: 97
Re: [In Progress] Possible infection - need help
« Reply #23 on: January 24, 2012, 12:03:32 PM »
is there anything else I can do here?

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22637
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Possible infection - need help
« Reply #24 on: January 24, 2012, 12:15:33 PM »
Sorry, I did not get notified of your response.

Other than this update, are you having any other problems at all?

Please run ccleaner to remove temporary files from your system, and to improve the scanning time of the other scans we may be running. Then please run Malwarebytes' Anti-Malware to check for malware. Both sets of instructions are below

1.Download and scan with CCleaner
When you get to the website, there is a dark grey box on the left side with two tabs along the top. Inside this Dark Grey box is a light grey box. Below that light grey box is where the download links are at. The pay amount is for paid support.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:

    • Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
    • Clean all the entries in the "Windows Explorer" section.
    • Clean all entries in the "System" section.
    • Clean all entries in the "Advanced" section.
    • Clean any others that you choose.


    In the Applications Tab
      • Clean all except cookies in the Firefox/Mozilla section if you use it.
      • Clean all in the Opera section if you use it.
      • Clean Sun Java in the Internet Section.
      • Clean any others that you choose.


      4. Click the "Run Cleaner" button.
      5. A pop up box will appear advising this process will permanently delete files from your system.
      6. Click "OK" and it will scan and clean your system.
      7. Click "exit" when done.


      Please download Malwarebytes Anti-Malware and save it to your desktop.
      alternate download link 1
      alternate download link 2

      MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
      • Make sure you are connected to the Internet.
      • Double-click on mbam-setup.exe to install the application.
      • When the installation begins, follow the prompts and do not make any changes to default settings.
      • When installation has finished, make sure you leave both of these checked:
        • Update Malwarebytes' Anti-Malware
        • Launch Malwarebytes' Anti-Malware
        • Then click Finish.
        MBAM will automatically start and you will be asked to update the program before performing a scan.
        • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
        • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
        On the Scanner tab:
        • Make sure the "Perform Quick Scan" option is selected.
        • Then click on the Scan button.
        • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
        • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
        • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
        • Click OK to close the message box and continue with the removal process.
        Back at the main Scanner screen:
        • Click on the Show Results button to see a list of any malware that was found.
        • Make sure that everything is checked, and click Remove Selected.
        • When removal is completed, a log report will open in Notepad.
        • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
        • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
        • Exit MBAM when done.
        Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

        Consumer Security

        If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

        Offline mess89

        • Bronze Member
        • Posts: 97
        Re: [In Progress] Possible infection - need help
        « Reply #25 on: January 25, 2012, 08:13:42 PM »
        Malwarebytes Anti-Malware 1.60.0.1800
        www.malwarebytes.org

        Database version: v2012.01.25.06

        Windows Vista Service Pack 2 x86 NTFS
        Internet Explorer 8.0.6001.19154
        Robin :: ROBIN-PC [administrator]

        1/25/2012 9:07:43 PM
        mbam-log-2012-01-25 (21-07-43).txt

        Scan type: Quick scan
        Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
        Scan options disabled: P2P
        Objects scanned: 200063
        Time elapsed: 5 minute(s), 15 second(s)

        Memory Processes Detected: 0
        (No malicious items detected)

        Memory Modules Detected: 0
        (No malicious items detected)

        Registry Keys Detected: 0
        (No malicious items detected)

        Registry Values Detected: 0
        (No malicious items detected)

        Registry Data Items Detected: 0
        (No malicious items detected)

        Folders Detected: 0
        (No malicious items detected)

        Files Detected: 2
        C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Quarantined and deleted successfully.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb (Rootkit.Zeroaccess) -> Quarantined and deleted successfully.

        (end)

        Offline Hoov

        • Malware Removal Mentors
        • Global Moderator
        • Diamond Member
        • Posts: 22637
        • Unwilling part owner of Gov't. Motors and Chrysler
          • Hoov's Personal Site
        Re: [In Progress] Possible infection - need help
        « Reply #26 on: January 25, 2012, 08:39:53 PM »
        * Anyone other than the originator of this thread, you would be best advised to not run combofix without guidance from someone trained in its use. It is a very powerful tool that can cause damage to your computer if used wrong.

        Run comboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

        http://www.bleepingcomputer.com/combofix/how-to-use-combofix

        * Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Also make sure you close all your browsers just before the instructions tell you to start the scanner.

        Please include the C:\ComboFix.txt in your next reply for further review.

        Note:
        Do not mouseclick combofix's window while it's running. That may cause it to stall

        Consumer Security

        If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

        Offline Hoov

        • Malware Removal Mentors
        • Global Moderator
        • Diamond Member
        • Posts: 22637
        • Unwilling part owner of Gov't. Motors and Chrysler
          • Hoov's Personal Site
        Re: [In Progress] Possible infection - need help
        « Reply #27 on: February 05, 2012, 09:07:58 AM »
        This thread is being closed due to inactivity. If you need it reopened send me a PM. This applies to the originator only. Anyone else please start a new thread.


        Consumer Security

        If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!