Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
Everyone MUST read this BEFORE posting for help in this forum (New)

Reply  
Thread Tools
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,289 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
15-Aug-2010, 10:17 AM #1
Everyone MUST read this BEFORE posting for help in this forum
Before beginning the cleanup process, it's very important that you back up all of your important data, photos, music, etc. to other media such as CDs or an external hard drive. An infected computer can be highly unstable and even a healthy one can crash and become unbootable at any time for a number of reasons so you should regularly back up anything that you wouldn't want to lose.

Also, many infections these days allow hackers to take control of your computer and obtain passwords and other sensitive information it may contain. With any infection, you should immediately change all passwords for logins, especially if you use your computer for banking and/or other types of financial transactions, but you must do so from a clean computer and not use the infected one for any such purposes.

Now you are ready to begin the clean up process. Please follow the steps outlined below and post the requested logs in your initial post(s). You may have to make more than one post if the logs are too long. Please only upload logs as attachments when specifically requested to do so as copying and pasting them is much easier to read and follow in the thread.


1. Please download HijackThis:
Please go here to download HijackThis.
  • To the right of the green arrow under HijackThis downloads click on the Executable button and download the HijackThis.exe file to your desktop.
  • Double-click the HijackThis.exe file on your desktop to launch the program. If you get a security warning asking if you want to run this software because the publisher couldn't be verified click on Run to allow it.
  • Click on the Scan button. The scan will not take long and when it's finished the resulting log will open automatically in Notepad.
  • Save the log file to your desktop. Copy and paste the contents of the log in your post.
Please do not fix anything with HijackThis unless you are instructed to do so. Most of what appears in the log will be harmless and/or necessary..


2. Please download DDS by sUBs to your desktop from one of the following locations:
http://download.bleepingcomputer.com/sUBs/dds.com
http://download.bleepingcomputer.com/sUBs/dds.scr
http://www.infospyware.net/sUBs/dds/

Disable any script blocker you may have as they may interfere and then double-click the DDS.scr to run the tool.

When DDS has finished scanning, it will open two logs named as follows:

DDS.txt
Attach.txt

Save them both to your desktop and then proceed on to the next step.


3. Please download GMER (only for use on 32-bit operating systems) from: http://www.gmer.net/index.php

Click on the "Download EXE" button and save the randomly named .exe file to your desktop.

Note: You must uninstall any CD Emulation programs that you have before running GMER as they can cause conflicts and give false results.

Double click the GMER .exe file on your desktop to run the tool and it will automatically do a quick scan.

If the tool warns of rootkit activity and asks if you want to run a full scan, click on No and make sure the following are unchecked on the right-hand side:

IAT/EAT
Any drive letter other than the primary system drive (which is generally C).

Click the Scan button and when the scan is finished, click Save and save the log in Notepad with the name ark.txt to your desktop.

Note: It's important that all other windows be closed and that you don't touch the mouse or do anything with the computer during the scan as it may cause it to freeze.

If you have a 64 bit computer do not download or run Gmer as it is not designed to work on a 64 bit system (no currently available rootkit scanner is) so will not give any useful information.

Please post the requested logs/reports, as follows:

1. Copy and paste the HijackThis log.
2. Copy and paste the contents of the DDS.txt file.
3. Upload as an attachment the Attach.txt file. There is no need to zip it as suggested in the DDS instructions
4. Copy and paste the contents of the ark.txt file.

Once you've posted the requested logs please be patient and wait for assistance. Our qualified helpers are all very busy and will try to get to you as soon as possible. If you haven't received a reply within 48 hours, you can post a reply to your thread that will simply "bump" it back up to the top where it's more likely to be noticed.

Other Important Notes:

Effective October 30th, 2008 a new procedure has been implemented so that everyone can easily see if posters are receiving assistance or not, even if they've replied to their own thread. In the past, this led us to believe they were receiving assistance as helpers looked for threads with 0 replies first when looking for posters to help.

Now, when a user starts a new thread in the Malware Removal & HijackThis forum, the thread is automatically tagged "New" which appears to the left of the thread title. The tag "New" remains there even if the thread starter replies back to their own thread to add additional information. This also means that the thread starter can now post a reply to "bump" their thread back up to the top as is done in other forums. However, we do ask that posters be patient and wait at least 24 hours before doing so.

When a helper replies to a thread they will change the tag to read "In Progress" so that other helpers will know that the poster is now receiving assistance.

When the thread is solved then the thread starter should click on the "Mark Solved" button that appears on the upper left side of the first post in the thread so that it can be tagged as "Solved".

Note: Duplicate threads will be merged, deleted or closed at Moderator discretion.

Threads will automatically close after 45 days of inactivity.


IMPORTANT NOTE REGARDING CORPORATE/COMPANY OWNED COMPUTERS

Please do not request assistance for corporate/company owned computers. Many changes/deletions are made during the clean up process, some of which may involve uninstalling programs, deleting folders/files, changing settings and/or removing policies etc. As we have no way of knowing for sure if these are actually needed for company operations, malware issues in these cases should be handled by your own IT Departments in order to avoid any undesirable results.
__________________
Microsoft MVP - Consumer Security

Last edited by dvk01; 04-Nov-2011 at 07:13 AM.. Reason: update Gmer use instructions
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,223 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
07-Apr-2011, 10:18 AM #2
Do not just post a HJT log or series of logs without an explanation of what is wrong. We need to know exactly what is wrong, so we can help you. The initial logs will only show less than 50% of modern malware and it depends a lot on the symptoms experienced by you for us to know what other tools to run or how to progress with the fix.
If you have a 64 bit computer do not run Gmer as it is not designed to work on a 64 bit system (no rootkit scanner is) so will not give any useful information.

Please do not just post a HJT log and ask "is my computer clean". Any posts of that nature will be ignored and we will offer help to the user who wants help & is prepared to help themselves by giving us all the details we need to help them. Nobody can or will ever say that a computer is clean based on a HJT log. It all depends on what symptoms you tell us about

Do not edit or remove any information or user names etc, otherwise we cannot fix the problem. We need to see the full details, such as full file names & paths to be able to fix an infected computer. If you insist on editing out anything then we will refuse to offer any help, because you have made it impossible for us to attempt any fixes
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
Reply

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools


Similar Threads
Title Thread Starter Forum Replies Last Post
IE7 problems HIJACK THIS log posted for help Jostonboe Virus & Other Malware Removal 0 22-Nov-2007 08:41 AM
Please read here first BEFORE posting for help in this forum dvk01 Virus & Other Malware Removal 0 11-Sep-2007 05:36 AM
A must tool for help in trouble shooting game problems lookin4yuh Games 8 12-Dec-2004 12:39 PM
i posted adult site ? in wrong forum can i move it? notredame888 Earlier Versions of Windows 3 30-Dec-2003 07:09 PM
I tried to research this before posting Rex Kramer Virus & Other Malware Removal 21 19-Nov-2003 04:22 PM


Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 12:12 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.