Welcome to Smokey's Security Forums.
Guests have only limited access to the board and it's features, please consider registering to gain full access!
Registration is free and it only takes a few moments to complete.

Smokey's Security Forums

Please login or register.

Login with username, password and session length
Advanced search  

News:

Internet hit by wave of ransom malware.

Criminals re-used an attack from 2008 to hit the Internet with a huge wave of ransomware in recent weeks, a security company has reported.

Internet hit by wave of ransom malware

OTL Log Analysis and Malware Removal - Qualified PC Disinfection & Cleaning - Microsoft Security Info & Alert Center - Official Jetico Inc. Support Forums

Share this topic on FacebookShare this topic on MySpaceShare this topic on Del.icio.usShare this topic on DiggShare this topic on RedditShare this topic on StumbleUponShare this topic on TwitterAuthorTopic: Something seriously wrong  (Read 512 times)

0 Members and 2 Guests are viewing this topic.

Essexboy

  • OTL Team - Malware Hunters
  • Global Moderator
  • *
  • Offline Offline
  • location: Darkest Cornwall
  • Posts: 276
Re: Something seriously wrong
« Reply #4 on: March 02, 2009, 11:49:18 PM »
Yes please but if you could start with a Hijackthis log, and then PM me when posted I will see where to go from there

frustratedTopic starter

  • Full Member
  • **
  • Offline Offline
  • Posts: 33
Re: Something seriously wrong
« Reply #3 on: March 02, 2009, 11:05:32 PM »
Hi Essexboy and thanks for the reply.  I'm not sure if you wanted me to write this here or in the Malware section.  I downloaded OTScanit2 and tried to run it but it doesn't work.  After I double click on OTScanit.exe, I window pops up saying "OTScanit2 has encountered a problem and needs to close" and I have a DEBUG or CLOSE button to choose from.  When I click on the CLOSE button, an Application Error window pops up with the wording "Exception EOleSysError in module OTScanit2.exe at 00052A21. Class not registered"

Do you still want me to start a thread over in the Malware section?

Essexboy

  • OTL Team - Malware Hunters
  • Global Moderator
  • *
  • Offline Offline
  • location: Darkest Cornwall
  • Posts: 276
Re: Something seriously wrong
« Reply #2 on: March 02, 2009, 10:22:00 PM »
Hi there from the little I can find out about intelinet I feel it is dubious at the best.  Evidently there is a registry cleaning section with this and that may be where the disaster lies

Could you post the following log in its own thread in the Malware section and I will look at it there

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTScanit2  to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
         
    • File - Purity Scan
         
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on to insert the attachment into your post

frustratedTopic starter

  • Full Member
  • **
  • Offline Offline
  • Posts: 33
Something seriously wrong
« Reply #1 on: March 02, 2009, 02:53:37 PM »
Hello everyone, I'm hoping you guys will be able to help me out.

For the last few weeks, my pc has been running quite slow but what was annoying me the most was that if the computer had been unused for a while (even 10 minutes or so) and I tried to open something, the computer would basically freeze for around 5 minutes.  Anything I tried to open while it was in the "frozen" state, would ultimately all open once the computer unfroze itself.

Last night, I went looking on the net as to why my system was behaving like this.  A few sites said it was a registry related problem and after reading several reviews, I downloaded INTELINET (can you see where this is going yet?).

After downloading, I went to install it and Zonealarm said it was infected.  I stopped the install immediately but then I was fooled by the "not-a-virus" tag line and (stupidly) allowed the install to go ahead.  It was late and I was tired...

Now, everything has turned to crap!

I'm running XP with service pack 2.  All my short cuts on the toolbar at the bottom of the screen, are gone.  If I click on Start and the Start Menu scrolls up, all the shortcuts in there(Explorer, Windows Update etc) are still there but the icons are all the same, not the correct individual icon.  If I log onto the net and open an Explorer page, all my short cuts and links etc are gone.  I can't get anything to load if I manually type an address in the address bar.  I can open My Computer and go into Program Files etc but anything I try and start manually, I get an "Access Violation" message - I'm at work at the moment so I can't type the exact message in  but it's something like Access Violation, could not read 0x0858018 fail at 0x00000000 - something similar to that.  I can write it exactly later on this evening.

This morning I downloaded Malwarebytes on another computer and tried to install it on my infected machine.  I get access violation errors (and other errors) when I try to install it and ultimately, it doesn't work.  I tried installing after a Diagnostic Start and after starting in Safe Mode - still no success.  I have been able to run a virus scan with Zonealarm but it found nothing.  It flagged up a couple of low risk files when I did a adware scan but nothing changed after I deleted tme.  I tried running The Ultimate Troubleshooter but I get the Access Violation message.

So, what do I do next?  I'd really appreciate some help here if anyone knows what the hell I'm up against.  I'm a little computer savvy and I've fixed my system in the past after the occasional brush with a virus but I'm out of my league now.  I can't even find reference to not-a-virus:FraudTool.Win32.Agent.dx except on this site.

Please help...
 

* Permissions
You can't post new topics.
You can't post replies.
You can't post attachments.
You can't modify your posts.
BBCode Enabled
Smilies Enabled
[img] Enabled
HTML Disabled


Except where otherwise stated, all content Copyright © 2006 - 2010 Smokey Services™ -- All rights reserved

Surf Smokey's with confidence: all external links in posts are checked and rated by WOT - Web of Trust
Security Knowledge-, Alert- & News Center and Comprehensive Microsoft Windows Information & Download Center
Board- and databases search functions and the download of post attachments are only available to registered board members

    


==>Think your PC is infected? Click here for OTL Log Analysis and Malware Removal Assistance<==


Smokey's Security Forums provide full qualified OTL Log Analysis & Cleaning Services
OTL (formerly OTListIt2) by OldTimer is a sophisticated, comprehensive log analysis tool to clean PCs with malicious content

Microsoft Security Info & Alert Center - most recent, real-time released Microsoft Security Bulletins, Alerts, Advisories and Vulnerabilities:
<div style="background-color: none transparent;"><a href="http://www.rsspump.com/?web_widget/rss_widget" title="rss widget">Rss widget</a></div>