aarinfantasy's YAOI Collection

Results 1 to 4 of 4
  1. #1
    Yaoi Legend


    Join Date
    Sep 2007
    Location
    Нью Йорк, США
    Posts
    1,492
    Points
    108,888,644
    Savings
    530,200,000


    Shinohara Keiji (L13)Sebastian (L13)(Event) FaceBook - Yukina
    (Event) Forum - Rayflo(Event) IRC - Ritsu(Event) Forum - Morinaga
    (S036) Kaneki KenCharley (L8)(Event) Forum - Tatsumi Souichi

    Help with Antimalware Doctor effects

    Okay, apparently every other month I seem to have a problem XD.

    So yesterday 'Antimalware Doctor' downloaded itself unto one of my computers. I couldnt do much but stare for a spit second before reacting and trying to get rid of it. After about an hour I had finally gotten rid of the stupid thing, but when my computer restarted there was no tool bar or anything, on the second try it appeared. I ran Malwarebytes and it came out with this:



    I did a second scan and it came out clean. But today it seems to be crashing FF every other minute, the computer is SUPER slow, everything seems to stop working and I don't know what to do anymore. I'm already backing up all my files, but I have a nasty feeling that this isn't over for my computer. I have bank accounts etc. and am getting on to calling them in case anything should happen. What do I do now? Is there a way to fix my computer? What risks are there after getting hit by something like this? Has anyone had this happen to them before? Why does it even happen? Can I back up the last settings my computer had incase something happens to it? Please, please I really need someone to help because I have years of work here TT___TT

    EDIT:
    The computer did a CHKDSK and it came out with something like this:
    C:\Documents and settings\LocalService\Temp\Temporary Internet Files\Content.IE5\B02JNLQT\narcancl[2]
    C:\Windows\Prefetch....

    I didn't get most of the info down, but it was mostly those Temporary Internet Files.

    Spybot found:
    MTC.MAKEMESEARCH.com
    HKEY_LOCAL-MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ Uninstall\Search Toolbar

    And something called 'Buzzdock' is bothering me with ads on FF -____-; how do I get rid of that? And now I keep being redirected to 'http://www.goingonearth.com/' when i click on link in google. =__= help?
    Last edited by crisislover; 04-19-2011 at 02:44 PM. Reason: new info

  2. #2
    Yaoi Lover

    Join Date
    May 2007
    Location
    In the crashing world of Maya 2012
    Posts
    657
    Points
    1
    Savings
    13,132,642


    Steve Rogers (L9)Star 1 (Yellow)Tony Stark (L9)
    Iron Man (L9)Star 1 (Yellow)Captain America (L9)
    Spacer 1Tony Stark (L10)Spacer 1

    1. do a back up of your important files (my dicuments, back up favourites if needed)

    2. Download Hijack This, do a systemscan+log and save it
    HijackThis - Trend Micro USA

    2. read the rules and post a topic here:
    Virus, Trojan, Spyware, and Malware Removal Logs - BleepingComputer.com
    You will need to paste the following info: your OS, the malwarebytes log and the hijack this log

    The people at the forum are very good at reading logs, Hijack this can remove registry keys and entries you can read if there is a virus running in the background because it shows a process that is running in for example Taskmanager and shows you to what .dll it is linked to (and so it pretty much maps it out).

    At this point I would suggest running Combofix, but if everything is crashing it make make even more things unstable. They might suggest it if it is needed.

    Just follow their instructions.
    If you ask me you have more infection than just a fake malware scanner one, if you are being linked to other sites when clicking on google results you might have that nasty google redirect virus that is hanging about as well.

    If you do work it out somehow I would suggest when using FF to have AddBlockPlus and perhaps a shield on antivirus in the BG like Avast.
    Last edited by KarumA; 04-19-2011 at 03:08 PM.


  3. #3
    Yaoi Legend


    Join Date
    Sep 2007
    Location
    Нью Йорк, США
    Posts
    1,492
    Points
    108,888,644
    Savings
    530,200,000


    Shinohara Keiji (L13)Sebastian (L13)(Event) FaceBook - Yukina
    (Event) Forum - Rayflo(Event) IRC - Ritsu(Event) Forum - Morinaga
    (S036) Kaneki KenCharley (L8)(Event) Forum - Tatsumi Souichi

    @KarumA: Ok, it seems you're right about having more than just this problem so far. There are also these nows:



    This is what TaskManager is running now:
    http://s530.photobucket.com/albums/d...lo/rinka02.png
    http://s530.photobucket.com/albums/d...lo/rinka03.png

    EDIT: Ah, I went and posted this problem at bleepingcomputer, so thanks for that reference and hopefully all is fixed soon.
    Attached Images Attached Images
    Last edited by crisislover; 04-19-2011 at 07:26 PM.

  4. #4
    Yaoi Lover

    Join Date
    May 2007
    Location
    In the crashing world of Maya 2012
    Posts
    657
    Points
    1
    Savings
    13,132,642


    Steve Rogers (L9)Star 1 (Yellow)Tony Stark (L9)
    Iron Man (L9)Star 1 (Yellow)Captain America (L9)
    Spacer 1Tony Stark (L10)Spacer 1

    There are some suspicious processes running in the background, so yes you are still infected.
    For example look at the MDM.EXE int he taskmanager and compare it to this one:
    mdm.exe - What is mdm.exe?

    The odd thing I found is that it has capitals in both exe and name, which virusses sometimes do because they try and take over a legit process but because they cannot carry the same name they use capitals or one extra letter. I also think mdm should be run under System and not your account.

    Do not do the scan on that website, because many are fake anti malware scanners out there. There is only a select few that are really good.

 

 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •