Help - Search - Members
Full Version: Forgive me my noobness
Piriform Community Forums > Computer Help and Discussion > Spyware Hell
NomDeKeyz
I did read the pinned post that said I should read before posting, but since I have just wiped everything, and reinstalled a new copy of windows,
I can't imagine that there is any malware/etc. left to scan/log... (then again, perhaps my imagination needs expanding?)

I wasn't sure if I should post this here, or in soft/hardware sections, because I don't know what the cause of my issue might be?

Since I decided to reformat fresh because of an infection that seemed to leave my computer scarred, I decided to ask here.
My main worry is that my computer is now permanently damaged due to an infection. Is that possible?

I expected that wiping everything, and reinstalling WindowsXP would fix my various computer issues, but it didn't quite.

Several programs were rendered non-functional after my housemate removed the Windows Antivirus Pro malware infection;
including: AVG, AdAware, MalwareBytes, Add/Remove Program and other things in Control Panel, Disk Defragmenter, CCleaner.

All of these programs/commands are functioning with my fresh install, save one very basic function. Shutdown/Restart.
(all except what I have not yet reinstalled, ofcourse... I was in the process of figuring out which protective programs to install)

It says it is shutting down, but doesn't. It lingers on the shutdown screen indefinitely. Similarly, it cannot restart.
Why won't it shutdown/restart? Did something permanently scar my computer? Do I need to get a new piece of hardware?
Do I need to do something to ensure a clean reinstall of my OS? I thought that booting off of the disk would do... does it?
See my confusion over where to post? Is it hardware? Software? The ghost of an infection? Do I need to scan it anyways?

To date, I have installed WindowsXP, My video card driver (ATI, from disk), My wireless driver (D-Link, from disk), Firefox, Adobe,
Avast! Professional 60 day trial (I am also considering G-data antivirus, but have not DL'd/tested it yet), and CCleaner (a favorite).
(Also, the only sites I have visited thus far have to do with what I have DL'd for install, G-data, AV-Comparatives, and this forum.)

I have been using CCleaner for a few years, and have loved it. When I came online to DL it, I found this forum full of great info.
I hope to become more computer savvy, and I thank in advance any help/advice that I am offered. Thanks also for this site.

P.S. This is my first time reformatting. I am learning as I go what I need to do. Any links to guidance are appreciated. I am not shy
when it comes to reading and research, I have ample time for this project. I am also very willing to reinstall/reformat as many times
as needed to get things right. Sure, I can find info sites on my own, but finding any site has proven very different to finding a good site.

P.P.S. I apologize if I did post this in the wrong section; If admin feels that it should be moved, then of course, I support the move.
Rorschach112
we best do a scan to be sure you are clean


Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean





Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
NomDeKeyz
Thankyou for your attention, Rorscach112.

I DL'd TFC and ran it. Since my computer can't completely shutdown/restart, I helped it a little (by holding the power button).
The text window between its completion and its initiation of shutdown/restart was so brief that I didn't get a chance to read it.
You didn't ask for a copy of that, so hopefully you won't need it (or hopefully you can direct me to it if I do need it after all).


I also ran MBAM Quick Scan (after updating);
here is the copy and paste of that log:

Malwarebytes' Anti-Malware 1.41
Database version: 2958
Windows 5.1.2600 Service Pack 2

10/14/2009 5:34:00 AM
mbam-log-2009-10-14 (05-34-00).txt

Scan type: Quick Scan
Objects scanned: 88058
Time elapsed: 3 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


*edit*

I went to Kaspersky's Online Scanner, but was unable to 'Accept'
I did read the Advantages and the Requirements and Limitations.
The site said that I needed to enable Java and Java Script in my
browser. After poking around, I found that they were enabled.
I unchecked then rechecked them again, to be sure; no luck...
I did disable avast! The 'Accept' button never became usable.
Is there anything else I need to do to use the 'Accept' button?

I know you didn't ask me to run an avast! scan, but I did anyhow.
(According to AV-Comparatives, avast! scored better than Kaspersky
in both detection, and number of false positives. Maybe this will do?)
I will readily run a Kaspersky scan once I figure out how to 'Accept'.

addy of the AV-comparatives pdf:
www.av-comparatives.org/images/stories/test/ondret/avc_report23.pdf
(avast!- detection: 98.0% / Kaspersky- detection: 94.7%)

Copy and paste of scan by avast! 4.8 professional:
Number of scanned files/folders: 97413/2279
Run-time of last scan: 00:16:35
Number of infected files: 0
Total size of scanned files: 8.0 GB

*end edit*

Again, thankyou for your assistance, I truly appreciate it. ~Nom
Rorschach112
Yeah its definitely not Virut, that was my first thought.


You must have run some registry cleaner or program like that, and damaged some setting. Not sure what I can do to fix that really.
NomDeKeyz
Thanks anyhow. It was worth a try. I have only used CCleaner in the past, however, my housemate used something that I think changed my computer settings. I hoped that a reinstall of everything would fix it, alas no. So, if everything was infact installed clean (as I am currently assuming), then would it be a Bios setting that I need to change (I know nothing about Bios settings)? Or would it be a piece of hardware that needs replacing (I know practically nothing about hardware)? Should I take my query to the hardware or some other section? *scampers off to your prevention topics and resumes installation of preventive measures and various updates*

Thankyou again for your assistance, your time and advice. I very much appreciate the attempt, and learning in the process.

And thankyou to this site, I am learning a lot just reading thru various posts (and giggling at some humorous ones). ~Nom
Rorschach112
I don't think a BIOS setting needs to be changed, nor hardware. Some program must be causing damage. Its impossible to say for sure.
NomDeKeyz
HooraY HooraH HiP HiP HuzzaH!!! It's fixed now! *doing a silly dance of relief*

After spending a few days reading on these forums, and theGeeks-To-Go forum,
I had compiled a list of possible causes based on past posts of similar circumstance.
I never mentioned to you that prior to my reformat, we tried to install a disk drive.
We never managed to get it working/detected, even tho it seems to be installed ok.
I was talking with my housemate about everything we did and what it might be.
When I mentioned the BIOS, he recalled that he made changes in it about that time.
(If you knew about the changes, I am sure you would have suggested undoing them)
Since that seemed the simplest thing to test, that's where we started. And Viola!

So, I guess it turned out to be a hardware issue that coincided with infection issues.

When I am done reformatting/reinstalling everything, I will return to the drive issue.

Thankyou for providing such a useful forum with fantabulous information and volunteers!

And thankyou to Rorshach112 for the offer of your time. Truly appreciated. ~NomDeKeyz
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.