Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.
MalwareByte's Anti-Malware Download

Important Announcement: We have two terrific contests running on the site that I wanted all our members and guests to know about.

The first contest is the HP Magic Giveaway, which is underway as of November 28th. More information can be found at this topic, which will be updated very soon with further information.

The second contests, is for the chance to win two Seagate FreeAgent external hard drives. More information about this contest can be found here.

These are both amazing contests and I suggest everyone submit an entry for them.

- BleepingComputer Management

> 

When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.

 
Reply to this topicStart new topic
> Computer Is Horribly Infected, Malware has taken over 2000
Soriku Enix
post May 29 2008, 02:34 PM
Post #1


New Member
*

Group: Members
Posts: 1
Joined: 28-May 08
Member No.: 212,347



Hello. I'm posting in this forum because I was wondering if anyone has gone through the same things that I am currently.

I run Windows 2000 Professional, and the other day, my roommate was harmlessly searching for game cheats on the internet through Google when he came across a site that matched his entry perfectly, so naturally he thought "Oh yeah! This is it!" and he clicked on it.

He said that it brought him to a website with a media player in it, and it kept wanting him to download an ActiveX control to play the movie. He denied every pop-up that came across, and finally got fed up with it all and closed the window. Suddenly, pop-up after pop-up came up of porn (which got my attention, because he was searching for game cheats after all).

Once I got home from work, I checked out the problem by going to the website (because he wasn't all too clear in explaining what was wrong...he thought that it downloaded porn onto my computer). Well, it was actually me that caused the spyware and such to infiltrate my computer, because I actually opened up the ActiveX control download, knowing that it wasn't being downloaded from the official site! (*sigh*) Don't know why, but I did it...

So, pop-ups flooded with porn, my background image was changed to neon blue with a yellow window in the middle saying "Spyware is detected on your computer. Run an antivirus or antispyware program to clean it immediately", and after 5 seconds of idle mouse movement, cockroaches would appear from the sides of the screen and "eat away" my desktop as the screen saver.

I panicked and shut off my internet connection once I saw the flashing of command prompt screens (thus frying my wireless USB adapter, I think). I shut off the computer and rebooted into safe mode. I manually took out the files "ctfmona.exe", "ctfmonb.bmp", and "blackster.scr" along with any other registry files that the .exe created.

However, whenever I boot up in normal mode, under ANY created account, I soon lose access to control panel, registry files, my C:\ drive, my display panel, and my task manager. And during all of this, my clock changes itself to military time, in the format of "hh:mm: VIRUS ALERT!" while pop-ups of Windows Security Alert and Spyware Alert continue to appear on my screen.

I've been trying to manually take out this virus due to my outdated antivirus software and my lack of internet connection to download anything from home (I'm typing this from work right now). I know that the virus is still in my computer somewhere because of the obvious clock and system properties settings, and because of Windows Security pop-ups (when Windows Security and System Restore wasn't even invented until Windows XP!) So if anyone can make it through this novel of a post to help me, it would be greatly appreciated. I have a Hijack This log file made, but I won't post it here, so if you can help, I'll move this to the appropriate forum.

Thank you for your time!

This post has been edited by rigel: May 29 2008, 02:42 PM
Reason for edit: Mod edit - Moved to a more appropriate forum.
Go to the top of the page
 
+Quote Post
boopme
post May 30 2008, 01:05 PM
Post #2


To INSANITY and BEYOND !!
******

Group: Moderator
Posts: 9,533
Joined: 10-September 04
From: NJ USA
Member No.: 2,608



Hello and welcome. Is this an XP machine?
Lets try to get this onto the PC via CD or USB and return a scan log.



Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


--------------------
Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 1st December 2008 - 01:34 PM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides

© 2003-2008 All Rights Reserved Bleeping Computer LLC.