Avast WEBforum

Other => Viruses and worms => Topic started by: blueday on December 22, 2009, 06:40:51 AM

Title: Win32:inject-wo
Post by: blueday on December 22, 2009, 06:40:51 AM
I am completely hijacked.....

no safe mode, no msconfig, no nothin'

can't even upgrade avast....it was the only software I could install.....

nothing works except Firefox

please help

blue
Title: Re: Win32:inject-wo
Post by: Yanto.Chiang on December 22, 2009, 01:17:09 PM
HI Blueday,

First of all :
1. Please turn off your restore system : Control Panel\All Control Panel Items\Recovery (Win 7)

2. If you already got avast antivirus, please do a boot time scan with your system

3. Then install MBAM (http://www.malwarebytes.org/), SuperAntiSpyware (http://www.superantispyware.com/), Lavasoft (http://www.lavasoft.com/). After that please do the system scan

4. Then please download AntiRootkit tool (http://www.antirootkit.com/software/index.htm)


Anyway, how many AV installed at your system?
What is your previous AV before using avast antivirus?




Title: Re: Win32:inject-wo
Post by: blueday on December 22, 2009, 02:07:29 PM
thanks for the suggestions, however I cannot open any application.  I get a warning: 

"Application cannot be executed.The file is infected. please activate your antivirus softeware."

This is not come from avast.  What I did get from avast was:

avast! has detected a virus in the operating memory.  Suggests a scan in the boot phase.  I have done that a couple of times and I have 7 or 8 file in the chest. 

I normally use my computer on a protected network at work.  I was on vacation and used a home network and failed to realize I had no protection.



Just how screwed am I?
Title: Re: Win32:inject-wo
Post by: .: L' arc :. on December 22, 2009, 02:44:57 PM
Have you tried renaming MBAM.exe as anything else?
Title: Re: Win32:inject-wo
Post by: blueday on December 23, 2009, 05:53:18 AM
can't do anything, except Firefox. 

no applications open

renaming does nothing....

can anyone help me?

please?
Title: Re: Win32:inject-wo
Post by: blueday on December 23, 2009, 02:27:31 PM
This morning I tried to update avast!  and got this:

23.12.2009 08:13:36 package: Tried to download servers.def but failed with error 0x20000011.
23.12.2009 08:13:36 package: LoadAllDefs failed 0x20000011
23.12.2009 08:13:37 general: Err:The package is broken.

I also got the broken package msg when I attempted to install the upgrade version

Can anyone help?

Title: Re: Win32:inject-wo
Post by: .: L' arc :. on December 23, 2009, 03:19:04 PM
It seems like the Fake AV is blocking access to all apps. Please consider posting a list of your installed software. We'll enumerate those that need to be uninstalled to begin with.
Title: Re: Win32:inject-wo
Post by: blueday on December 23, 2009, 06:38:49 PM
I will, however I cannot access the Add/Remove program to delete anything. 

This just popped up from avast!

C:\WINDOWS\System32\Drivers\nqzjsmu.sys

I will now do a boot-time scan and move everything to the chest.....

this really sucks
Title: Re: Win32:inject-wo
Post by: blueday on December 24, 2009, 05:00:55 AM
Okay...

Security task mgr
reg cure
exterminate it
avast
ccleaner
quicken
iphone
picassa 3
quicktime
firefox
ie
apple software update
turbotax
school library catalog
epat launcher
etools live
testnav tutorial
sibelius 5
photoscore lite
realplayer
palm desktop
google earth
respondus
repsondus equation ed 4
a+learning systems
dyknow
netscape 7.2
thunderbird
ms office
itunes
integrade pro
finale note pad
examview pro
hp virtual rooms
interwrite learning
svp-5300 capture program
timeliner
llc
inspiration
photostory
design premium cs3
distiller
acrobat
extendscript tool kit
fireworks cs3
live cycle designer
spybot s+d
ad aware
wmp
audacity

I cannot open or use any program other than firefox and avast....but I could not upgrade from the free version....\

things are still sucking......
Title: Re: Win32:inject-wo
Post by: blueday on December 26, 2009, 05:52:56 PM
thanks for all the help


I fixed it myself


Title: Re: Win32:inject-wo
Post by: CharleyO on December 27, 2009, 11:32:00 AM
***

Welcome to the forums, blueday.   :)

Do you mind telling us how you fixed it?


***