My baby is infected and shes begging for help!

Bigwoods

banned
My computer is infected by Antivirus Soft, which looks something like this
http://www.precisesecurity.com/wp-content/uploads/2010/01/antivirus-soft.jpg

I CANNOT access the internet at all, although if I press IE random X rated sites will pop up. Literally any program I press on, like Malwarebytes anti-malware, or CCleaner, a notification saying that the program is corrupted pops up..

What should I do? I have A LOT of important stuff and I haven't back-uped recently. Am I gonna have to reformat?

Thanks
 

johnb35

Administrator
Staff member
Do you have a flash drive where you can download a file from a different computer and run it on yours? If so, then download combofix from a different computer.

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply please post:
  • The ComboFix log
  • A fresh HiJackThis log
  • An update on how your computer is running
 

Bigwoods

banned
Whenever I try to download combofix.exe onto a USB I get :

Combofix.exe
Path does not exist.
Please verify that the correct path was given
 

Drenlin

Active Member
Restart your computer and open task manager before the virus starts up. From there you can end it, and carry on removing it as usual.
 

Bigwoods

banned
So I ended up finding the file, it was located in something like C:/Users/Local/.....

I deleted it, now I no longer have any antivirus soft pop ups so my computer is running perfectly fine, EXCEPT theres no internet connection! My internet works 100% (im using it now on the desktop right next to the infected one) What do i do?
 

johnb35

Administrator
Staff member
Are you able to run combofix yet? I suggest running it or malwarebytes and posting the logs along with a hijackthis log.
 

Bigwoods

banned
MalwareBytes log:


Malwarebytes' Anti-Malware 1.42
Database version: 3442
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

28/02/2010 10:39:21 PM
mbam-log-2010-02-28 (22-39-21).txt

Scan type: Full Scan (C:\|)
Objects scanned: 291057
Time elapsed: 1 hour(s), 8 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


HIJACKTHIS log
http://www.hijackthis.de/#anl
 
Top