Author Topic: Desktop Hijacked - Lots of infections  (Read 7329 times)

0 Members and 1 Guest are viewing this topic.

thewebguy

  • Guest
Desktop Hijacked - Lots of infections
« on: November 11, 2012, 12:06:58 AM »
I have a laptop, dell XPS m1210 with windows XP on it.

I DO NOT have the xp discs (yet...trying to locate them)

Computer wont let you double click items, need to use the rightclick/OPEN to get things open.
Will not connect to internet...IE flashes open but closes right away.

was able to update avast and ran it. 5 infections found and removed. Issues persist.

When I tried to install malwarebytes, spybot and some others I get near the end of the installation and get the follwoing error:
CoCreation Instance Failed
Class Not Registered

I was able to run adwCleaner, Roguekiller, aswMBR (logs attached)

Any help would be great.

thewebguy

  • Guest
Re: Desktop Hijacked - Lots of infections
« Reply #1 on: November 11, 2012, 12:07:18 AM »
one more log attached

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: Desktop Hijacked - Lots of infections
« Reply #2 on: November 11, 2012, 02:37:14 PM »
hey also attach the OTL log please.

http://forum.avast.com/index.php?topic=53253.0
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

thewebguy

  • Guest
Re: Desktop Hijacked - Lots of infections
« Reply #3 on: November 11, 2012, 03:32:35 PM »
While running OTL got an ACCESS VIOLATION at address 0052CDD7 in module OTL.exe
clicked ok and it just appears to have hung up at "Scanning C:|Documents and Settings\All Users\Start Menu\Programs\start Menu Folder...
I am leaving it alone now to see if it finishes the scan or not. If it does finish, Ill post the log.


Note: still cant access internet from that laptop.
Also now I am getting popups asking to block/unblock the following (I Keep saying to "ask me later")
1) ActiveSync RAPI Manager
2) BackWeb-8876480

also wirless networks found window popsup every few seconds.

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: Desktop Hijacked - Lots of infections
« Reply #4 on: November 11, 2012, 08:09:15 PM »
hey. okey you have to wit for an malware expert to guide you from here. it could be because of the infection why the otl is not running.
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Desktop Hijacked - Lots of infections
« Reply #5 on: November 11, 2012, 11:07:50 PM »
Hi could you try to run this.. From safe mode if necessary

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

thewebguy

  • Guest
Re: Desktop Hijacked - Lots of infections
« Reply #6 on: November 12, 2012, 12:50:46 AM »
Combofix ran see attached

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Desktop Hijacked - Lots of infections
« Reply #7 on: November 12, 2012, 08:33:08 PM »
OK lets now look at the net problem

Download and run farbar service scanner



Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

thewebguy

  • Guest
Re: Desktop Hijacked - Lots of infections
« Reply #8 on: November 12, 2012, 10:05:58 PM »
FSS log attached

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Desktop Hijacked - Lots of infections
« Reply #9 on: November 12, 2012, 11:36:04 PM »
FSS can access the web

Download  Windows Repair (all in one)  from this site

Install the programme then run



Go to step 3 and allow it to run SFC



On the start repairs tab click start


Select the following  items and tick restart system when finished


thewebguy

  • Guest
Re: Desktop Hijacked - Lots of infections
« Reply #10 on: November 13, 2012, 10:48:19 PM »
Errors I encountered. When trying to install directly to desktop it would not let me. Could not install unistall dorectory...
Ran the program from my flash drive.
In the SFC section, it asked for the windows XP disc multiple times(which i currently dont have but am trying to find) so I had to skip/cancel that section...

Ran repair option and system restarted.

Some items seem to be working now...IE stays connected...

What now?
« Last Edit: November 13, 2012, 10:57:53 PM by thewebguy »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Desktop Hijacked - Lots of infections
« Reply #11 on: November 13, 2012, 11:34:02 PM »
What are the current problems after running the repair


thewebguy

  • Guest
Re: Desktop Hijacked - Lots of infections
« Reply #12 on: November 14, 2012, 09:38:41 PM »
s l o w ...

When I tried to install malwarebytes, spybot and some others I get near the end of the installation and get the follwoing error:
CoCreation Instance Failed
Class Not Registered

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Desktop Hijacked - Lots of infections
« Reply #13 on: November 14, 2012, 11:29:09 PM »
Download and run MBAM clean exe from here http://downloads.malwarebytes.org/file/mbam_clean  the try a reinstall of MBAM

thewebguy

  • Guest
Re: Desktop Hijacked - Lots of infections
« Reply #14 on: November 15, 2012, 12:01:45 AM »
cleaned mbam....reinstall and got same errors. It installs and wants to run/update, but all those errors are poping up during install of it.

EDIT: tried to run OTL...same errors as before

EDIT: still have to open some items by right clicking and selecting OPEN

EDIT: trying to run malwarebytes to see what happens...EDIT#2: so far objects are beging detected. Will post when its complete EDIT #3: been running for about 1hour 45minutes...im going to bed...will post reulsts tomarrow
« Last Edit: November 15, 2012, 01:39:19 AM by thewebguy »