Jump to content

cleared av security virus now IE will not work


kirby2664
 Share

Recommended Posts

Hello,

I recently had the AV security virus along with all the other spyware/malware that comes with it. I ran your product along with stopzilla and my stopzilla says I have a search hijacker proxy problem. I keep removing it but it keeps showing up everytime it scans. Malwarebytes does not show anything. I also have a problem that my internet explorer does not respond. It loads but stays there with a blank page. I am unable to get to the proxy setting within internet explorer because it is grayed out. I am running windows 7 home premium.

THank you for you anticipated help.

Kirby

Link to post
Share on other sites

Hello Kirby! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/paste in your next reply.

Please follow the instructions here:

http://forums.malwarebytes.org/index.php?showtopic=99664

Let me know when you are ready.

Link to post
Share on other sites

Thank you for your help. Here are the logs. I seem to be virus and malware clear. I have no issues that pop up via virus software, malwarebytes or stopzilla anymore. I do still have a problem with IE. It opens but does not connect. If I go to the about tab on the anti-malware program there is a button that has your website. If i hit it, IE opens and connects. Then I can use it. If I try using the regular icon on the desktop or taskbar it just opens and doesnt connect. The tools/options is also grayed out when it is open so I cant get into it.

Thank you

Malwarebytes' Anti-Malware 1.51.2.1300

www.malwarebytes.org

Database version: 8178

Windows 6.1.7601 Service Pack 1

Internet Explorer 9.0.8112.16421

11/16/2011 9:33:45 PM

mbam-log-2011-11-16 (21-33-45).txt

Scan type: Quick scan

Objects scanned: 193821

Time elapsed: 13 minute(s), 44 second(s)

Memory Processes Infected: 2

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 4

Registry Data Items Infected: 1

Folders Infected: 0

Files Infected: 10

Memory Processes Infected:

c:\Users\Annette\AppData\Roaming\47788\lvvm.exe (Malware.Packer) -> 5020 -> Unloaded process successfully.

c:\Users\Annette\AppData\Roaming\microsoft\FFC0\249.exe (Malware.Packer) -> 5204 -> Unloaded process successfully.

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\249.exe (Malware.Packer) -> Value: 249.exe -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\249.exe (Malware.Packer) -> Value: 249.exe -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Backdoor.CycBot) -> Value: Load -> Delete on reboot.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell.Gen) -> Value: Shell -> Quarantined and deleted successfully.

Registry Data Items Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Malware.Packer) -> Bad: (C:\Users\Annette\AppData\Roaming\47788\lvvm.exe) Good: () -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

c:\Users\Annette\AppData\Roaming\47788\lvvm.exe (Malware.Packer) -> Quarantined and deleted successfully.

c:\Users\Annette\AppData\Roaming\microsoft\FFC0\249.exe (Malware.Packer) -> Quarantined and deleted successfully.

c:\program files (x86)\LP\FFC0\249.exe (Malware.Packer) -> Quarantined and deleted successfully.

c:\Users\Annette\AppData\Roaming\audiohd.exe (Malware.Generic.A) -> Quarantined and deleted successfully.

c:\Users\Annette\AppData\Roaming\iTunes.exe (Malware.Packer) -> Quarantined and deleted successfully.

c:\Users\Annette\AppData\Roaming\Safari.exe (Exploit.Drop) -> Quarantined and deleted successfully.

c:\Windows\System32\vs62a.com_ (Trojan.Email) -> Quarantined and deleted successfully.

c:\Windows\SysWOW64\vs62a.com_ (Trojan.Email) -> Quarantined and deleted successfully.

c:\Windows\Temp\hki406284.exe (Trojan.Email) -> Quarantined and deleted successfully.

c:\Windows\Temp\tgayux\setup.exe (Trojan.Email) -> Quarantined and deleted successfully.

and then after cleaning:

Malwarebytes' Anti-Malware 1.51.2.1300

www.malwarebytes.org

Database version: 8178

Windows 6.1.7601 Service Pack 1

Internet Explorer 9.0.8112.16421

11/16/2011 10:14:53 PM

mbam-log-2011-11-16 (22-14-53).txt

Scan type: Quick scan

Objects scanned: 193910

Time elapsed: 13 minute(s), 23 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

protection log

Malwarebytes' Anti-Malware 1.51.2.1300

www.malwarebytes.org

Database version: 8178

Windows 6.1.7601 Service Pack 1

Internet Explorer 9.0.8112.16421

11/16/2011 10:14:53 PM

mbam-log-2011-11-16 (22-14-53).txt

Scan type: Quick scan

Objects scanned: 193910

Time elapsed: 13 minute(s), 23 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

Once OTL has completed its first scan it will save notepad copies of the scans in the folder that OTL was started from. Unless set to produce an Extras log it will only produce OTL.txt in subsequent scans.

A copy of an OTL fix log is saved in a text file at

  • :\_OTL\MovedFiles
    • in most cases this will be C:\_OTL\MovedFiles

Link to post
Share on other sites

  • 2 weeks later...

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.