Unsolved

This post is more than 5 years old

59 Posts

17556

February 27th, 2009 13:00

Emergency! I need help quick!

Hi Everyone!

I believe that my laptop has a virus.  It started last night with messages popping up.  Here are the details. I'm hoping from the desktop to the laptop because the connection is so slow so if I don't respond right away you know why.

I have a Inspiron E1505, running windows XP

I have ran updates, scanned for viruses and adware, malware

Problems:

It seems that the computer is trying to install a program that I did not download. I suspect that one of the kids clicked on something or opened something that began this whole thing.  It looks as if the problem is coming from a website which I think is called Magic Software Inc.  This is the web address that I copied:

https://secure.spy-protect-2009.com/order?prodid=1&r=17.2

When you go to this page it will only let you place an order with this company. There is no place to click for help, uninstall or anything.

another one that pops up:

kaka://c:Windows\sysguard.exe/htmlMain.htm

It first started with a small window popping up on the bottom tool bar saying windows detected that someone was trying to hack into the computer and this virus program needed to be ran. When you "x" out of the program that is when the window to purchase comes up.

Some of the other messages are as follows: (please note that all of these are coming at different times)

The exception breakpoint a breakpoint has been reached(0x80000003) occured in the application at location 0x00406eef

click ok to term. click cancel to debug

 

Another file that was trying to open:

wmiprvse.exe

I have tried to restart the computer at which time a message saying that googleupdate has a problem with this:

googleupdate.ext

Different message:

0x012e9bbf ref memory @ 0x012e9bbf memory could not be written

 

These are just various different things that popped up and wrote them down in case they mean something:

tk2.stc.s.-msn.com

msnportal.112.207.net

http://browser-security.microsoft.com/block.php?k=17.2

 

I have also tried to do a system restore and it won't let me.  Web pages take long to load as if I were using dial-up....I have DSL. Somtimes the icons on the desktop do not show up and I have to restart the computer again. Right now it is in active desktop mode.

Any help that anyone can offer is greatly appreciated!  If no one can help here I don't know what else to do.

Thanks everyone

Gina

 

4 Apprentice

 • 

20.5K Posts

February 27th, 2009 14:00

Try scans with these two programs in the following order:

Please disable other security software that may cause conflicts with the scans. (Don't forget to enable it afterward.)

Instructions on how to do that are HERE.

Please download to your desktop Malwarebytes' Anti-Malware from Here or Here 

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checkedPhotobucket
    Click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Extra Notes:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.
* If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "catchjunk.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the file to the infected computer. Install the "catchjunk.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.

 

Download and scan with Super Anti-Spyware Free for Home Users. It is available HERE:
*Double-click SUPERAntiSypware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):

Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.

* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".

If that does not fix the problem, it might be good to post a log for review on the Malware Removal Forum.

Be sure to read instructions at the top of the forum.

 

59 Posts

February 27th, 2009 15:00

I tried this and it dowloads to the desktop but won't open to perform the scan.

4 Apprentice

 • 

20.5K Posts

February 27th, 2009 16:00

* If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "catchjunk.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the file to the infected computer. Install the "catchjunk.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.

4 Apprentice

 • 

20.5K Posts

February 28th, 2009 06:00

Did you rename MBAM before transferring it?

59 Posts

February 28th, 2009 07:00

Yes.  I thought it transferred to the flash drive.  When I put the flashdrive in my laptop it showed that the file was there. When I clicked on it to install it when through the process quickly but then that is all. Nothing else happened.

 

4 Apprentice

 • 

20.5K Posts

February 28th, 2009 08:00

When I put the flashdrive in my laptop it showed that the file was there. When I clicked on it to install it when through the process quickly but then that is all.
Were you trying to run it from the flashdrive, or did you transfer the renamed file to the infected computer and then try to run it?

59 Posts

February 28th, 2009 08:00

Could downloading highjackthis and running it possibly help?

59 Posts

February 28th, 2009 08:00

I tried it both ways and neither works.

 

59 Posts

February 28th, 2009 08:00

First I downloaded the file to the working computer then renamed it and transferred it to the flashdrive.

Then transferred that to the laptop (broken computer) it whet through the installation process but then it didn't run the program or do anything.

I then erased the file on the flashdrive and tried downloading it directly to the flashdrive.  Renamed it transferred it to the laptop, didn't work.

 

1 Rookie

 • 

27 Posts

February 28th, 2009 09:00

When it comes to removing spyware there are a huge number of options.

I recommend:

Webroot Spysweeper

Yahoo Toolbar

But there are a lot more out there.  What it looks like to me; you have several viruses, malware, and adware.  Did someone get a little upset?  This is what i would do.  I would download some spyware removal softwares to the infected computer.  I would then install the software and then disconnect if from the internet.  If I needed to update definitions I would connect it to the internet, but for the most part I want it disconnected to prevent any virsuses from sending data to a host.

After that is complete I would run virus scans to remove and viruses.  AVG free or Clam, or Avast!  are free anti virus programs.

That should remove a good portion of the adware and spyware.

59 Posts

February 28th, 2009 09:00

Ok, could you please give specific instructions on how to do something like this. I am not that knowledgeable about this stuff.

Also, it is extremely slow trying to get connected to the internet.  So trying to download things is close to impossible. Of course the biggest no no on my part is that my Norton expired and was running on a trial version. 

 

 

1 Rookie

 • 

27 Posts

February 28th, 2009 11:00

How specific do I need to be?

Go to web site, download software, install software, run software, delete spyware.

You are having a hard time downloading on that computer?  Then download it with another computer and copy it to a CD or a USB flash drive.

You don't have Norton?  Then get Avast, or Clam AV, or AVG Free.  Good luck getting a manual sized description of what to do.  It can happen but the answer is just as simple as I explained it.  The longer it takes you to understand how simple it is download and install the software the longer you are at risk of losing valuable data.

4 Apprentice

 • 

20.5K Posts

February 28th, 2009 11:00

We'll continue this on the Malware Removal forum where there are trained analysts.

No Events found!

Top