Author Topic: Lets begin.....HELP ME...!!LOL.  (Read 4362 times)

0 Members and 1 Guest are viewing this topic.

Cabcrusher

  • Guest
Lets begin.....HELP ME...!!LOL.
« on: December 19, 2009, 06:34:00 AM »
Ok..I hope I am posting this in the correct place.I am too tired to really care right now.This is a LONG post so please bear with me...oh by the way,I am a NEMB to most of this so if you have complicated answers OR need to talk in stuff I dont understand,please remember I am new to this.About 4 days ago a problem started on my computer.I am running Windows XP by the way.I usually use Mozilla Firefox to do my browsing.Well when I signed on I got bombarded with all kinds of ads and pages stating my computer was infected.Hmm,I went to Ebay to check my account and finish my bids but when I signed on I was taken to a page I had never seen before.It asked for a bunch of private info.I contacted Ebay right away and they said they dont send that page out and my computer was infected.I went to Major Geek looking for programs to help me with my problem.I downloaded and installed Spyware Blaster,Malware Bytes,AVAST and a2squared..( also there Malware removal tool..) .I tried downloading Superantispyware but AVAST wont let me.I was also told to download Windows Defender but when I went to the Windows site,they said they dont support it anymore.Well I ran every program I had and found 4 trojans.A2Squared wouldnt let me delete them.
   Malware bytes found nothing..same as AVAST.Spyware Blaster did do anything either.I then deleted Mozilla and re-installed it...( SEVERAL TIMES..).When I first use it I have no problems,but within 2 to 5 seconds AVAST stops a TROJAN from downloading into my computer and I cant use Mozilla at all.I tried scanning again using Malware but all I am getting now is ERROR codes when I try to open it and run a scan.I tried sending an e-mail to Malware but it says.." NO e-mail available." Now I am at a loss and cant seem to get rid of it.
  This is what I see when AVAST stops the program.

   http//bcckools.com
   html:framer-1nf(trj)
   trojan horse
   vps version 091218-1
I really have no idea what to do or what more I can download to help me.I just tried Hitman pro 3 and it found nothing.ANYBODY with some help for the new guy.??!?

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: Lets begin.....HELP ME...!!LOL.
« Reply #1 on: December 19, 2009, 12:15:46 PM »
Hi, Cabcrusher, welcome to the forum.
Simple question, first off, what was the AV (of any) that you had installed before installing Avast?
Next, from what website did you get your Avast download?
And likewise, from where MBAM?
Please post the full addresses you went to to get these, the behaviour you are describing is not characteristic, in several ways.

Please right-click the "my computer" icon on your desktop, select "properties", and in the "general" tab (which it will open to) copy and post the information under the word "system", and also under the word "computer".

What is a NEMB?

Windows Defender is alive and well, and definitely still supported, you can get it here, but don't bother, for now. Something is probably redirecting your searches or browser to a place you don't want to go, or preventing some legitimate connections being made.
This can be done, if not by me, then by some of the experts here.
Please click here to directly download ATF cleaner. Save it to your desktop. The icon looks like a pale blue trashcan with the lid off. Double click it to run it. Place a tick in every checkbox, except history, and click on "empty selected".
This will not clean the malware, but it will make the cleanup easier, by removing all temporary files and reducing scan times; possibly taking some malware components at the same time.

Avast would not prevent you downloading Superantispyware. These two work together well.
Did you try updating MBAM before running a scan with it? If not, do that and try running a quick scan again.
There is no reason Asquared would have prevented you deleting what was found.  (Incidentally, never delete anything found, when there is an option to quarantine it. Always quarantine, never delete.) So that is why I'm curious to know where you got your programs from.
What message was presented when you tried to remove these trojans using A2?

Spyware Blaster is not a removal tool, it's a tool to help prevent malware. Good to have, but won't help clean you up.
Last thing I want to know is the name, and a download link to the MajorGeeks removal tool you tried, please.

Don't worry.
Unless it's a particularly nasty file infector (possible) it should be removable, with a bit of methodical action.
If you have access to a clean computer, I'd be inclined to change any passwords to sites like ebay, and banks/credit cards. It may pay to inform your bank of this infection, and that you are taking steps to fix it, if you do online banking on this computer. Different banks have their own policies about customer responsibility in this area. I would think most would want to be informed.
Windows 10,Windows Firewall,Firefox w/Adblock.

Cabcrusher

  • Guest
Re: Lets begin.....HELP ME...!!LOL.
« Reply #2 on: December 19, 2009, 02:50:33 PM »
Wow Tarq57,thanks for the quick response  ;D.I will try and answer everything you ask but some of it I cant due to the fact that I cant get back on Major Geek.Sorry,but I meant to type in NEWB.I was pretty tired when I started typing last night..anyway..here we go with what I know.
1). MBAM came from the site ASK A NERD.NET.
2). AVAST came from Major Geek after I went to there site and looked up SECURITY in the download page on the left of the screen.
3).When I tried downloading ATF Cleaner this morning..I get a RED FLAG WARNING.."UNKNOWN PUBLISHER,CAN NOT BE VERIFIED" and asks if I want to stop the download.Being too careful I didnt download it.
4).And yes..( I dont mean to argue..PLEASE understand this part..) AVAST STOPS Super anti spyware altogether from downloading.I can by-pass if I want to but again,being afraid I didnt.
5).A2 SQUARED was download first,but that was over several months ago.
6). This is what is under My Computer:
     Microsoft Windows XP
     Home Edition
     Version 2002
     Service Pack 2
     
     Intel(R)
     Pentium(R) 4CPU 1.80 GHz
     1.80 GHz,1.50GB of RAM
I tired to do everything you asked BUT some sites I cant get back on.I am going to delete AVAST and go to there website for a fresh install.Then I will try Superantispyware again.Thanks again and let me know what else might help.

Cabcrusher

  • Guest
Re: Lets begin.....HELP ME...!!LOL.
« Reply #3 on: December 19, 2009, 02:54:13 PM »
Knew I forgot a few other things.After getting rid of MBAM a few times I went to Bleeping Computer.com and downloaded it from another person on there forums.I got the A2Squared Malware removal tool from that forum too.But with being to so many sites I have lost track of what and where programs have been downloaded from. :-[

YoKenny

  • Guest
Re: Lets begin.....HELP ME...!!LOL.
« Reply #4 on: December 19, 2009, 03:31:43 PM »
Windows XP Service Pack 3 has been available for over a year and provides many Critical Updates plus performance improvements.

Go to Control Panel then Automatic Updates then select Automatic (recommended) or at least Notify me but don't automatically download or install them.

Go to Secunia Online Software Inspector then run it to see what other applications are vulnerable:
http://secunia.com/vulnerability_scanning/online

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: Lets begin.....HELP ME...!!LOL.
« Reply #5 on: December 19, 2009, 11:15:51 PM »
-What are the error messages displayed when Asquared is asked to quarantine the files detected as malware?
-What are the full names and paths of these files?
-Try Superantispyware from here. I think it is likely you are trying to download a rogue with a similar name. That is the only reason Avast would prevent it.
-ATF cleaner is safe to run. I would not recommend it if it wasn't. An alternative is the popular Ccleaner, publisher is Piriform.

You say you "got rid of MBAM a few times". Do you mean you installed then un-installed it? If not, what do you mean?
Do not delete Avast. It is (1) incorrect to do so- the program must be correctly uninstalled, and (2) probably not necessary at this point.

Again, what was the antivirus you used before downloading and installing Avast?
And again, what happens if you update MBAM and scan again?
Windows 10,Windows Firewall,Firefox w/Adblock.

snowflake

  • Guest
Re: Lets begin.....HELP ME...!!LOL.
« Reply #6 on: December 19, 2009, 11:33:21 PM »
Windows XP Service Pack 3 has been available for over a year and provides many Critical Updates plus performance improvements.

Go to Control Panel then Automatic Updates then select Automatic (recommended) or at least Notify me but don't automatically download or install them.

Go to Secunia Online Software Inspector then run it to see what other applications are vulnerable:
http://secunia.com/vulnerability_scanning/online

May I politely suggest that it is not a good idea to update to SP3 untill the computer is malware free.........

Is the OP also suggesting that this computer did NOT have any antivirus protection prior to the  recent installation of Avast?


Quote
I went to Major Geek looking for programs to help me with my problem.I downloaded and installed Spyware Blaster,Malware Bytes,AVAST and a2squared..( also there Malware removal tool..)

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: Lets begin.....HELP ME...!!LOL.
« Reply #7 on: December 19, 2009, 11:57:52 PM »
Quote from: snowflake
May I politely suggest that it is not a good idea to update to SP3 untill the computer is malware free.........
A very good suggestion, and one I hope YoKenny takes on board. The fix should be made first, then the bandages put on.

Quote
Is the OP also suggesting that this computer did NOT have any antivirus protection prior to the  recent installation of Avast?
Hard to know. 'S why I asked. The truth will out.
Windows 10,Windows Firewall,Firefox w/Adblock.