![]() | |
| |||
| Jobeard has referenced me to this site, hopefully you can help me. My computer shuts off automatically at windows startup when Normal Mode is attempted. I am able to start up my computer only in Safe Mode, which limits programs/antivirus that I can install. The following is a paste from Bobbye... "Your Host Files have been hijacked- you are being taken to the Ukraine. You will need help removing the malware and resetting your router. Unfortunately, we are temporarily short of malware helpers here. I would encourage you to try and clean with system with guidance. Please see Virus and Malware Removal HERE if you would like assistance. Please follow the preliminary removal instructions. I recommend that you don't install or uninstall security programs until or unless you are directed to do so by your helper." I was a bit confused on whether or not to follow preliminary removal instructions because there are programs to install, although it was advised not to install/uninstall. If I can get clarifications on this, I would love to get started on cleaning up my computer. Thanks for you time. I have attached previous MBAM and Hijack Logs. MBAM detected files have been corrected and I have run further logs with zero detections. Avast was also run and found viruses Trojan-gen {Other}, Walivun [Trj], and Kuang2. thank you! pirrip777 |
| ||||
| welcome!! 1) using an admin login download this filethat will at least stop a lot of bad accesses. 2) you can avoid DNS highjacking by updating your TCP properties
__________________ J. O. Beard; you + tech-101.com => synergism. Secure your system now |
| ||||
| Malwarebytes has done some cleanups already did you reboot?unless you have a printer attached to your router (ie it has an IP address), you do not need O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exethis is 'questionable and unnecessary' as it can/does control site access O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll <<TROJANimo, download managers are totally unnecessary and only add bloat to your system look for it in ADD/Remove also OR check Spybot S&D for ActiveX, BDO, and LSP entries
__________________ J. O. Beard; you + tech-101.com => synergism. Secure your system now |
| |||
| I have tried to reboot several times to no avail (i.e., shutoff continually occurs) I will attempt to replace the file you suggested to download into system32 (previous post), but can you do this in safe mode? Bobbye also mentioned reseting my router. Do I do a manual reset? Is there anything I can do to my router settings to prevent this from happening again? I will remove the unecessaries as you suggested. I appreciate the expedient support! I will let you know as soon as everything is finished. pirrip777 |
| ||||
| Hi, Download avz4.zip from here
When restarted
Attach both zip files to your next post
__________________ Infected? Use the Preliminary Removal Instructions then post in the Virus and Malware Removal Forums |
| |||
| Jobeard - I have replaced the hosts file as requested and changed the TCP/IP accordingly. I also uninstalled Google Toolbar and GetGo to remove the functions that you saw were in Hijackthis. I have attached a txt of the log. Kritius - I was able to install AVZ with no problem and start the program. Update was successful, but after that it gets shady. I was able to run the initial start, but I was not able to find "Healing/Quarantine and Advanced System Analysis" as one of the scripts. Is there an alternative to this? I also looked for Healing/Quarantine by itself and could not find it. Advanced System Analysis by itself was found. I was afraid to restart to lose progress... I will await your reply before moving on. I appreciate the support from both you guys! |
| ||||
| Do the advanced system analysis then.
__________________ Infected? Use the Preliminary Removal Instructions then post in the Virus and Malware Removal Forums |
| |||
| Ran ASA via AVZ (att as before_restart) Restarted computer, still autoshuttoff on startup Restarted computer, F8 to enter Safe Mode with Networking Ran ASA via AVZ (att as after_restart) Awaiting further instructions... thanks again for all the help. Attachments are too big to send, please advise. |
| ||||
| Can you upload it to mediafire and post the link?
__________________ Infected? Use the Preliminary Removal Instructions then post in the Virus and Malware Removal Forums |
| |||
| |
![]() |
| Tags |
| host files, kualang2, shutoff, trojan-gen, walivun |
| Thread Tools | Search this Thread |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Problem files in Windows/Downloaded Program Files folder | elsemeek | Virus and Malware Removal | 15 | 07-08-2009 07:07 PM |
| my log files | crissinty | Virus and Malware Removal | 6 | 01-21-2009 12:12 PM |
| [Solved] My Log files =] | sttacos | Virus and Malware Removal | 6 | 01-13-2009 05:10 PM |
| [Solved] Log Files | LGhost | Virus and Malware Removal | 10 | 01-13-2009 04:05 PM |
Copyright © 2009 Tech-101.com. All rights reserved.