Help Please!!!!

Is there anyone here who can help me? I have never had anything this crazy happen before. When I try to get online a screen comes up that says the web page is blocked and that i have malware and has a link to buy a malware remover. It wont let me go online. When I run avast and move everything to the chest(it says i have 109 trojans) and restart my computer, my main page wont load, its there, but with no icons or start menu. Please help.

thanks
Tammy

I am using avast 4.6 home edition
I have windows xp
I use internet explorer

Not sure what else you might need


Welcome to the forums, Tammy! :slight_smile:

Could you please include some of the names of the trojans in the chest. Without knowing what infection(s) you have, it is difficult to give advice.
The malware is what is trying to get you to buy it. Can you tell what is the name of the malware remover?

Also, do you have XP Home or Pro … is it fully updated to SP2 … and IE6?


c:\windows\explorer32dbg.exe
Win32:Trojan-gen. {UPX!}
c:\windows\iexplore_dbg.exe
Win32:Trojan-gen. {UPX
win32:dialer-470
win32:adtool
win32:Trojano-2393

This is just a couple of them, it also says that my memory is infected. I cant get back to the malware that is affected my going online right now, I was able to get online for a little while, but when i log out and try to come back I probably wont be able to. Im sorry Im no help. Im not great with computers.

I am running home edition windows xp

It sounds to me as if you are infected with spyware. If you are not using Spybot you should get it from www.spybot.info and also you should download Microsoft Antispy from www.microsoft.com/downloads. If you are unable to get to the website, you should be able to get Spybot on one of those CDs included when you buy a computer mag.

They are both very good programs for removing spyware - hyjackers in your case. Good luck and don’t forget to update to the latest definitions for both programs as with Avast

Hi and welcome ,
the fact that avast has identified it means that it probably can remove it as well but it may need to be run as a boot time scan (check help files for how ) post back if your troubles continue.
good luck

In addition to the very good advice you have received I suggest that you
Download and run Ewido.

There a a great number of very good how to remove malware sites available with
detailed instructions on how to resolve any problems you may encounter

Ewido Home Page

Hijackthis Download and Web site Check
Download and Run HijackThis 1.99.1 form Meriji.org
Hijackthis Download Page

Post the Hijackthis text file to either
Hijackthis log file analysis
or
NetworkTechs log file analysis

:slight_smile: Hi joraefletch :

 Sounds like you have a serious problem; if what has been
 suggested does NOT work, I would encourage to ask the
 Microsoft Most Valuable Professionals ( MVPs ) on the 
 forums at www.aumha.net for help . Whatever you do, do
 NOT respond to whatever is popping up on your screen !!
 And "Microsoft Antispy" & Spybot would NOT be my choice
as antispyware programs to have on one's computer .

Go to this thread you possibly have spyaxe/falcon/sheriff http://forum.avast.com/index.php?topic=19483.msg164074#msg164074

this is the webpage that comes up and says that this page is blocked because you have malware. res://C:\WINDOWS\System32\shdoclc.dll/navcancl.htm

this is the website it takes you to if you click on the blocked webpage. res://xmllib.dll/HTTP_Blocked.htm

I have tried removing all of the viruses, but the computer wont load my home page when i do. Do I need to do the hijack log and post it to be analyzed? Thanks for all your help.

Go to this page and follow the instructions http://pcpitstop.invisionzone.com/index.php?s=2d7d529f86e97da8304f60360f56f8c0&showtopic=109799

Or here http://www.bleepingcomputer.com/forums/topic43659.html

For an on-line analysis - HiJackThis Log file - On-line Analysis OR HiJackThis Log file - On-line Analysis 2
Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.


this is the website it takes you to if you click on the blocked webpage. res://xmllib.dll/HTTP_Blocked.htm

The file xmllib.dll is also installed by some versions of coolwwwsearch as well as by versions of Trojan-Dropper.Win32.Small and probably a few others.

Most suggestions I saw say to use Ewido but it does not hurt to also try the other suggestions posted by others above.

I hope this helps you. :slight_smile:


Not wanting to sound harsh… however with so many problems perhaps the most efficient time saving
method would be to do a reformat and reinstall.

This lends itself to good back up procedures and even more so to the use of a good clean disk image.

I too feel that when your system is this compromised it is often quicker and possibly wisest to start from scratch after saving your data and downloading a firewall, latest version of avast and all OS Services Packs to a second HDD or CD/DVD.

That way when you next go on-line you stand a fighting chance of avoiding the exploits MS patched with the later service packs and a firewall to stop unauthorised intrusion or connection to the internet.

Without a firewall you will be fighting a loosing battle.