Unsolved
This post is more than 5 years old
59 Posts
0
17556
February 27th, 2009 13:00
Emergency! I need help quick!
Hi Everyone!
I believe that my laptop has a virus. It started last night with messages popping up. Here are the details. I'm hoping from the desktop to the laptop because the connection is so slow so if I don't respond right away you know why.
I have a Inspiron E1505, running windows XP
I have ran updates, scanned for viruses and adware, malware
Problems:
It seems that the computer is trying to install a program that I did not download. I suspect that one of the kids clicked on something or opened something that began this whole thing. It looks as if the problem is coming from a website which I think is called Magic Software Inc. This is the web address that I copied:
https://secure.spy-protect-2009.com/order?prodid=1&r=17.2
When you go to this page it will only let you place an order with this company. There is no place to click for help, uninstall or anything.
another one that pops up:
kaka://c:Windows\sysguard.exe/htmlMain.htm
It first started with a small window popping up on the bottom tool bar saying windows detected that someone was trying to hack into the computer and this virus program needed to be ran. When you "x" out of the program that is when the window to purchase comes up.
Some of the other messages are as follows: (please note that all of these are coming at different times)
The exception breakpoint a breakpoint has been reached(0x80000003) occured in the application at location 0x00406eef
click ok to term. click cancel to debug
Another file that was trying to open:
wmiprvse.exe
I have tried to restart the computer at which time a message saying that googleupdate has a problem with this:
googleupdate.ext
Different message:
0x012e9bbf ref memory @ 0x012e9bbf memory could not be written
These are just various different things that popped up and wrote them down in case they mean something:
tk2.stc.s.-msn.com
msnportal.112.207.net
http://browser-security.microsoft.com/block.php?k=17.2
I have also tried to do a system restore and it won't let me. Web pages take long to load as if I were using dial-up....I have DSL. Somtimes the icons on the desktop do not show up and I have to restart the computer again. Right now it is in active desktop mode.
Any help that anyone can offer is greatly appreciated! If no one can help here I don't know what else to do.
Thanks everyone
Gina


Bugbatter
4 Apprentice
•
20.5K Posts
0
February 27th, 2009 14:00
Try scans with these two programs in the following order:
Please disable other security software that may cause conflicts with the scans. (Don't forget to enable it afterward.)
Instructions on how to do that are HERE.
Please download to your desktop Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
Click Remove Selected.
Extra Notes:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.
* If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "catchjunk.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the file to the infected computer. Install the "catchjunk.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.
Download and scan with Super Anti-Spyware Free for Home Users. It is available HERE:
*Double-click SUPERAntiSypware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
If that does not fix the problem, it might be good to post a log for review on the Malware Removal Forum.
Be sure to read instructions at the top of the forum.
ginar66
59 Posts
0
February 27th, 2009 15:00
I tried this and it dowloads to the desktop but won't open to perform the scan.
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 27th, 2009 16:00
* If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "catchjunk.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the file to the infected computer. Install the "catchjunk.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 28th, 2009 06:00
Did you rename MBAM before transferring it?
ginar66
59 Posts
0
February 28th, 2009 07:00
Yes. I thought it transferred to the flash drive. When I put the flashdrive in my laptop it showed that the file was there. When I clicked on it to install it when through the process quickly but then that is all. Nothing else happened.
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 28th, 2009 08:00
ginar66
59 Posts
0
February 28th, 2009 08:00
Could downloading highjackthis and running it possibly help?
ginar66
59 Posts
0
February 28th, 2009 08:00
I tried it both ways and neither works.
ginar66
59 Posts
0
February 28th, 2009 08:00
First I downloaded the file to the working computer then renamed it and transferred it to the flashdrive.
Then transferred that to the laptop (broken computer) it whet through the installation process but then it didn't run the program or do anything.
I then erased the file on the flashdrive and tried downloading it directly to the flashdrive. Renamed it transferred it to the laptop, didn't work.
Prof_Ebral
1 Rookie
•
27 Posts
0
February 28th, 2009 09:00
When it comes to removing spyware there are a huge number of options.
I recommend:
Webroot Spysweeper
Yahoo Toolbar
But there are a lot more out there. What it looks like to me; you have several viruses, malware, and adware. Did someone get a little upset? This is what i would do. I would download some spyware removal softwares to the infected computer. I would then install the software and then disconnect if from the internet. If I needed to update definitions I would connect it to the internet, but for the most part I want it disconnected to prevent any virsuses from sending data to a host.
After that is complete I would run virus scans to remove and viruses. AVG free or Clam, or Avast! are free anti virus programs.
That should remove a good portion of the adware and spyware.
ginar66
59 Posts
0
February 28th, 2009 09:00
Ok, could you please give specific instructions on how to do something like this. I am not that knowledgeable about this stuff.
Also, it is extremely slow trying to get connected to the internet. So trying to download things is close to impossible. Of course the biggest no no on my part is that my Norton expired and was running on a trial version.
Prof_Ebral
1 Rookie
•
27 Posts
0
February 28th, 2009 11:00
How specific do I need to be?
Go to web site, download software, install software, run software, delete spyware.
You are having a hard time downloading on that computer? Then download it with another computer and copy it to a CD or a USB flash drive.
You don't have Norton? Then get Avast, or Clam AV, or AVG Free. Good luck getting a manual sized description of what to do. It can happen but the answer is just as simple as I explained it. The longer it takes you to understand how simple it is download and install the software the longer you are at risk of losing valuable data.
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 28th, 2009 11:00
We'll continue this on the Malware Removal forum where there are trained analysts.