Announcement

Collapse
No announcement yet.

Computer infected?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Computer infected?

    My computer has been popping up a bunch of ads when I open a new window and it doesn't go to my home page anymore it gets redirected to some google page but never fully opens that page.Does anyone know of some sights I could go to to download a malware/spybot cleaner? I'm kind of technotarded so make it easy for me.
    Originally posted by Nash B.
    Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.

  • #2
    You rang...

    What do you currently have for AV? Have you scanned with it yet or is it disabled?

    See if you can DL this. http://goo.gl/yPsB

    Saved and Texan by the Grace of God, Redneck by choice.

    Comment


    • #3
      I don't think I have anything for antivirus right now or if I do I don't know what it is, I know pretty bad, but I've had this computer for years and years and never had any issues.
      Originally posted by Nash B.
      Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.

      Comment


      • #4
        it's been stuck at a green screen trying to download something for the last 20 minutes when I went to http://goo.gl/yPsB
        Originally posted by Nash B.
        Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.

        Comment


        • #5
          Try this.



          Saved and Texan by the Grace of God, Redneck by choice.

          Comment


          • #6
            Originally posted by Tx Redneck View Post
            Try this.



            Saved and Texan by the Grace of God, Redneck by choice.

            Ok I downloaded that and it's scanning right now. So far 60 things detected and it keeps popping up in the corner saying it is blocking potentially malicious websites!
            Originally posted by Nash B.
            Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.

            Comment


            • #7
              SO it found 60items and I removed them and restarted the computer. However when I open the internet it still goes to a random google page? It doesn't open up another page anymore though so I think it's a little better.
              Originally posted by Nash B.
              Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.

              Comment


              • #8
                try restoring your computer to an earlier date that you know it was working fine...

                start>accessories>system tools>system restore

                Comment


                • #9
                  DL this, make sure DNS cache is checked and run it.



                  Also, post the log from mbam please.
                  Saved and Texan by the Grace of God, Redneck by choice.

                  Comment


                  • #10
                    Originally posted by Tx Redneck View Post
                    DL this, make sure DNS cache is checked and run it.



                    Also, post the log from mbam please.
                    Saved and Texan by the Grace of God, Redneck by choice.
                    Ok I did that and it deleted the temporary files I guess and this is the log from when I did the malware cleansing

                    Malwarebytes Anti-Malware (Trial) 1.65.1.1000
                    Malwarebytes offers real-time antivirus, advanced anti-malware and privacy protection for all your devices. Launched in 2004 as a free virus scan, we still offer a free basic version 20 years later. Learn more.


                    Database version: v2012.11.26.10

                    Windows XP Service Pack 3 x86 NTFS
                    Internet Explorer 8.0.6001.18702
                    Owner :: AL-AWMTR8HF9U3 [administrator]

                    Protection: Enabled

                    11/26/2012 8:38:14 PM
                    mbam-log-2012-11-26 (21-39-55).txt

                    Scan type: Full scan (C:\|)
                    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
                    Scan options disabled: P2P
                    Objects scanned: 68782
                    Time elapsed: 1 hour(s), 49 second(s) [aborted]

                    Memory Processes Detected: 0
                    (No malicious items detected)

                    Memory Modules Detected: 1
                    C:\WINDOWS\system32\fastsrch.dll (IPH.GenericBHO) -> No action taken.

                    Registry Keys Detected: 53
                    HKCR\CLSID\{E932FCCC-C424-4613-B195-BFCD4AE1C038} (IPH.GenericBHO) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{E932FCCC-C424-4613-B195-BFCD4AE1C038} (IPH.GenericBHO) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{E932FCCC-C424-4613-B195-BFCD4AE1C038} (IPH.GenericBHO) -> No action taken.
                    HKCR\CLSID\{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
                    HKCR\CLSID\{84718935-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{84718935-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{84718935-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{84718935-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> No action taken.
                    HKCR\CLSID\{05FC4875-A1F4-42d6-A733-EE1F68372D01} (Adware.ShoppingGuard) -> No action taken.
                    HKCR\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} (Adware.ShoppingGuard) -> No action taken.
                    HKCR\Interface\{2F0AB503-EF91-4F4C-A688-30F22831F1A4} (Adware.ShoppingGuard) -> No action taken.
                    HKCR\escort.escortIEPane.1 (Adware.ShoppingGuard) -> No action taken.
                    HKCR\escort.escortIEPane (Adware.ShoppingGuard) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{05FC4875-A1F4-42D6-A733-EE1F68372D01} (Adware.ShoppingGuard) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{05FC4875-A1F4-42D6-A733-EE1F68372D01} (Adware.ShoppingGuard) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{05FC4875-A1F4-42D6-A733-EE1F68372D01} (Adware.ShoppingGuard) -> No action taken.
                    HKCR\CLSID\{A3ED2449-E049-4ab9-A059-DD0F9BA1BA44} (Adware.ShoppingGuard) -> No action taken.
                    HKCR\shpngrd.hlpr.1 (Adware.ShoppingGuard) -> No action taken.
                    HKCR\shpngrd.hlpr (Adware.ShoppingGuard) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A3ED2449-E049-4AB9-A059-DD0F9BA1BA44} (Adware.ShoppingGuard) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{A3ED2449-E049-4AB9-A059-DD0F9BA1BA44} (Adware.ShoppingGuard) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{A3ED2449-E049-4AB9-A059-DD0F9BA1BA44} (Adware.ShoppingGuard) -> No action taken.
                    HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (PUP.MyWebSearch) -> No action taken.
                    HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (PUP.MyWebSearch) -> No action taken.
                    HKCR\Typelib\{CF710E35-C62E-4D48-ABA4-CA9509B28EC2} (Adware.ShoppingGuard) -> No action taken.
                    HKCR\Interface\{16493E0D-5DB5-4386-AFF9-6ACFA7490BA9} (Adware.ShoppingGuard) -> No action taken.
                    HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.MyWebSearch) -> No action taken.
                    HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.MyWebSearch) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Settings\{B67544A0-D1AC-4C74-8D28-1E3421CFFB77} (Adware.ShoppingGuard) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{B67544A0-D1AC-4C74-8D28-1E3421CFFB77} (Adware.ShoppingGuard) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B67544A0-D1AC-4C74-8D28-1E3421CFFB77} (Adware.ShoppingGuard) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{8B2C7C9D-716D-4E9E-9358-B9C80A81B7ED} (Adware.Adparatus) -> No action taken.
                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> No action taken.

                    Registry Values Detected: 2
                    HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> Data: 4‰q„*Ö*O´”k&oH± -> No action taken.
                    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{84718934-D6AD-4FA0-B494-6B266F48B108} (Adware.Mirar) -> Data: 0 -> No action taken.

                    Registry Data Items Detected: 0
                    (No malicious items detected)

                    Folders Detected: 0
                    (No malicious items detected)

                    Files Detected: 4
                    C:\WINDOWS\system32\fastsrch.dll (IPH.GenericBHO) -> No action taken.
                    C:\WINDOWS\system32\c578.dll (Adware.Mirar) -> No action taken.
                    C:\Program Files\Shoppinguard.com\shpngrd\1.3.61.1\shpngrd.dl l (Adware.ShoppingGuard) -> No action taken.
                    C:\RECYCLER\S-1-5-21-823518204-764733703-839522115-1003\$5a519532f37dabdd9a43bb956fa6e9f9\n (Trojan.0Access) -> No action taken.

                    (end)
                    Originally posted by Nash B.
                    Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.

                    Comment


                    • #11
                      OK,it did the scan but you didn't have the check box marked to remove infections. Also, do not use system restore, there is at least one restore point infected with a Trojan. Rerun mbam,full scan and have it remove everything it detects. Reboot, google eset online scanner and run it if you're able to get to it. If not, try to DL and install Avast free from avast.com If you're able to do that, run a full scan with rootkit detection enabled.

                      I'll check this in the AM.

                      Saved and Texan by the Grace of God, Redneck by choice.

                      Comment


                      • #12
                        I also had this log as I did it a second time and enabled it to detect a different type of thing DOn't know if this is the other one you asked about. I will let it do a full scan and let it run all night and try the other stuff you suggested tomorrow. I really appreciate the help as the cmputer is already 10x faster and it now goes back to my regular yahoo home page when I start the internet.



                        Malwarebytes Anti-Malware (Trial) 1.65.1.1000
                        Malwarebytes offers real-time antivirus, advanced anti-malware and privacy protection for all your devices. Launched in 2004 as a free virus scan, we still offer a free basic version 20 years later. Learn more.


                        Database version: v2012.11.26.10

                        Windows XP Service Pack 3 x86 NTFS
                        Internet Explorer 8.0.6001.18702
                        Owner :: AL-AWMTR8HF9U3 [administrator]

                        Protection: Enabled

                        11/26/2012 9:48:02 PM
                        mbam-log-2012-11-26 (21-48-02).txt

                        Scan type: Quick scan
                        Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
                        Scan options disabled:
                        Objects scanned: 51877
                        Time elapsed: 21 minute(s), 14 second(s) [aborted]

                        Memory Processes Detected: 0
                        (No malicious items detected)

                        Memory Modules Detected: 1
                        C:\RECYCLER\S-1-5-18\$5a519532f37dabdd9a43bb956fa6e9f9\n (Trojan.0Access) -> Delete on reboot.

                        Registry Keys Detected: 20
                        HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (PUP.MyWebSearch) -> No action taken.
                        HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (PUP.MyWebSearch) -> No action taken.
                        HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.MyWebSearch) -> No action taken.
                        HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.MyWebSearch) -> No action taken.
                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> No action taken.
                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
                        HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> No action taken.
                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> No action taken.
                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext \Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> No action taken.
                        HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> No action taken.
                        HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> No action taken.
                        HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> No action taken.
                        HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> No action taken.
                        HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> No action taken.
                        HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> No action taken.

                        Registry Values Detected: 0
                        (No malicious items detected)

                        Registry Data Items Detected: 0
                        (No malicious items detected)

                        Folders Detected: 0
                        (No malicious items detected)

                        Files Detected: 8
                        C:\WINDOWS\Temp\SPA240.tmp\upgrade.exe (PUP.Zwangi) -> No action taken.
                        C:\RECYCLER\S-1-5-18\$5a519532f37dabdd9a43bb956fa6e9f9\n (Trojan.0Access) -> Quarantined and deleted successfully.
                        C:\Documents and Settings\Owner\Local Settings\Temp\1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                        C:\Documents and Settings\Owner\Local Settings\Temp\3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                        C:\Documents and Settings\Owner\Local Settings\Temp\shpngrd.exe (Adware.ShoppingGuard) -> Quarantined and deleted successfully.
                        C:\Documents and Settings\Owner\Local Settings\Temp\SkypeSetupo.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                        C:\Documents and Settings\Owner\Local Settings\Temp\stub-9945.exe (Adware.Adparatus) -> Quarantined and deleted successfully.
                        C:\Documents and Settings\Owner\Local Settings\Temp\uninstall.exe (Adware.GabPath) -> Quarantined and deleted successfully.

                        (end)
                        Originally posted by Nash B.
                        Damn, man. Sorry to hear that. If it'll cheer you up, Geor swallows. And even if it doesn't cheer you up, it cheers him up.

                        Comment


                        • #13
                          I gotta save those links for a nice easier cut and paste to family members when they bug me to clean malwarez of their pc. Thanks!
                          2013 F150 STX Supercab 5.0L w/3.55 LSD
                          1990 GT Convertible

                          Comment


                          • #14
                            I wouldn't recommend that for two reasons.

                            1There will likely be updates to those programs in the near future.

                            2They're hosted from my personal dropbox and if I delete the files, the links are no good.

                            I hosted them there to reduce the probability of being blocked/redirected as it appeared he was experiencing.

                            Saved and Texan by the Grace of God, Redneck by choice.

                            Comment


                            • #15
                              ya noticed that after I looked at the links. I'll just do the same as needed with my dropbox. Still a good idea. I had to use mine to show screenshots to Dell tech support on my busted laptop to get em to replace the drive. Also a good idea to link there and naming etc as lots of malware tries to stop/avoid the common cleanup tools
                              2013 F150 STX Supercab 5.0L w/3.55 LSD
                              1990 GT Convertible

                              Comment

                              Working...
                              X