need some help eliminating malware

noobeater

Junior Member
Dec 30, 2008
2
0
0
So i come home one day and find spyware guard 2008 running and instantly know its fake. I then proceed to try an get rid of it with malwarebytes and superantispyware but can't open or run them, even after reinstalling them. I Download anvira antivir and fully scan in safe mode. Got rid of a bunch of stuff then i used the script package from one of the security threads here. I can't download trend micro cause the page won't open nor will a majority of the other anti-virus/anti-malware/anti-spyware sites. The script package seems to have solved most of my problems with spyware guard 08 but i still get rerouted from certain web pages, my windows reverted from the XP style to the windows 95, and I still can't open malwarebytes or super antispyware. Any suggestions or ideas would be helpful to get rid of whatever i'm still infected with. I'm not crazy computer savvy so instructions would be nice. Thanks
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
If you have a system that can burn an .ISO to a CD, then download the F-Secure Rescue CD from this page or this direct link to the Zip file download and burn it. Then boot the infected system from the CD and let it update its virus definitions and run a scan. This is a good "second opinion" scan to supplement your AntiVir.

After that, see if you can now download TrendMicro's HijackThis. If you can, then run it and post the text from the logfile into this thread. Also, see if you can run Malwarebytes and Superantispyware after F-Secure's scanner has been run.

Also, right-click AntiVir's tray icon and choose Configure AntiVir. A panel will open. There's an "expert mode" checkbox. Enable "expert mode" and go down to General > Extended threat categories. Enable all the categories. Then run another complete scan.
 

VirtualLarry

No Lifer
Aug 25, 2001
56,554
10,171
126
Going with the "ounce of prevention is worth a pound cure"... once you do get the system cleaned up, or worst case, reformatted... learn about "Software Restriction Policies". (If you are using XP Pro.) It can prevent those sorts of infections.
 

cparker

Senior member
Jun 14, 2000
526
0
71
Have you tried system restore from a restore point at a time when your computer was uninfected?
 

MadScientist

Platinum Member
Jul 15, 2001
2,155
48
91
Cleaned this nasty off a computer last week. I had to use Combo Fix in Safe Mode to get rid of it. Even in Safe Mode this thing prevented SuperAntiSpyware and Malawarebytes Anti-Malware from scanning.
 

law9933

Senior member
Sep 11, 2006
394
0
0
This one is tough, you will probably still need the help of a trained HJT adviser.
 

noobeater

Junior Member
Dec 30, 2008
2
0
0
Originally posted by: MadScientist
Cleaned this nasty off a computer last week. I had to use Combo Fix in Safe Mode to get rid of it. Even in Safe Mode this thing prevented SuperAntiSpyware and Malawarebytes Anti-Malware from scanning.

Thanks scientist combo fix worked very well. i couldn't download it directly to my computer so i had to use my cousins and then transfer it over. i got rid of pretty much everything and now i can access sites as well as super antispyware and malwarebytes. Appreciate the help everyone.
 

MadScientist

Platinum Member
Jul 15, 2001
2,155
48
91
Happy New Year everyone. I hope my 401K, now a 201K, recovers this year. :roll:
I can't believe I'm up this early. Got a slight headache, but not bad. I was good only had a few drinks :wine: last night.

noobeater,
Glad to hear ComboFix worked for you. ComboFix doesn't catch everything though. Also update and scan your computer with SAS and Malawarebytes Anti-Malware; and as mechBgon suggested, run HijackThis and post the log here.

 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |