Virus also recording me from my video lens..Help ?

PS: I been racking my brains out trying to figure out where this virus came from and it can only be 2 places .
they also come with fake java updates

anyway we should leave you and magna86 do do the work now. :wink:

Magna

First off I want to say THANK YOU …YOU GUYS ROCK !

1- Should I run malware first then OTL.exe. ?

PS: I deleted Adaware…didn’t think it was considered a virus program…anyway it’s gone. I lso checked
http://singularlabs.com/uninstallers/security-software/
to see if it was listed to get rid of anything left over but Lavasoft (adaware) isn’t listed so hopefully it’s gone. Was a good program I must say.

I’m keepin Avast for sure and Malware which is also good.

Rainrockets,first off go with magna’s fixes and you should be fine no need to run anything else now apart from what magna says ;D

Instead of Ad-Aware which is now old and outdated I recommend Malwarebytes which free with amazing database to update and do weekly scans and Pro version is worth running beside your AV :slight_smile:

Yes I will but I thought magna said to run malware first before doing OTL…see his post.

Thanks

Hi, :slight_smile:
I understand that you have been run MalwareBytes before my post, so I just wrote to attach here mbam.txt log just to see what has been done.

If I misread, please skip mbam step ( attaching log ) and go to the OTL Fix step ; RogueKiller ; AV step… At the end, attach here fresh OTL.txt log to see current situation.

That’s OK…anyway I started malware again so it’s running as I type.

I will follow everything in order.

After malware OTL is next.

Thanks so much !

OK here is malware report (quick scan) and will report back with OTL next.

PS: I’m now up 28hrs straight since 5am NY EST and now almost 9am the next day…uh !

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Database version: v2013.03.13.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
RainerRocks :: RAINERROCKS-PC [administrator]

3/13/2013 8:25:10 AM
mbam-log-2013-03-13 (08-25-10).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 353713
Time elapsed: 9 minute(s), 20 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Problem…

I opened OTL and pasted the stuff as advise and hit Fix.

Well a DOS window popped up and nothing happened. The curser was blinking
and doing nothing.

The noticed the program OTL was saying "Not Responding " on the top .

Everything just sat still and PC froze.

I was able to hit restart toget out of it.

So was that DOS screen suppose to pop up or what ?

Thanks.

PS: Waiting to know if I should try it again.

True Indian…I can’t respond to your PM. I since uninstalled flash player so now every youtube video is saying to install it.

But I was searching for " Ozone Generators" at the time so maybe you can find it.

Magna see above post in case you missed it.

So PC started back up and I tried again.

A DOS screen popped up for sec and was gone just as fast.

Then the PC didn’t seem to be doing anything then windows popped up with a screen that said “A critical error has occured and windows will shut down in a minute”

PC shut down and upon rebooting ask me if it was ok to allowed OTL and I said yes.

Then the report popped up…see attachement. I don’t know if it’s the full report because the PC was only up for a minute before it shut down.

Ok…just in case see last 2 posts before this in case you missed them.

I ran OTL for a 3rd time and it seem to go smoothly.

Only thing I don’t like is it changed my homepage and got rid of my search engine.
It made google my homepage and bing for default search engine. I use to use BING but no more…I didn’t delete it from system tho.

I do have google mail but that’s also going soon and now some how it’smy homepage…not good.

I used “StartPage” which is very good for search engine and home page… No tracking .

See attachement for latest OTL file.

Ok, for some reason OTL has failed to run cmd in fixprogress.

Re-run OTL Fix again (RunFix button) but use this script:


:processes
killallprocesses 

:OTL
IE - HKU\S-1-5-21-1918482796-3435808618-3437081748-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://startpage.com/
IE - HKU\S-1-5-21-1918482796-3435808618-3437081748-1000\..\SearchScopes\{18092453-1A5D-443C-99D3-CDAD419B1A83}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=SPC2&o=15004&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=PW&apn_dtid=YYYYYYYYUS&apn_uid=25667EC4-F38C-4D22-8931-AE82B09C0138&apn_sauid=18DDCC39-9B0A-4A9A-B732-C3C7953AB74A
IE - HKU\S-1-5-21-1918482796-3435808618-3437081748-1000\..\SearchScopes\{7990EA36-AFD2-41C8-AFA3-A5C8589C8E70}: "URL" = https://startpage.com/do/search?query={searchTerms}&cat=web&pl=ie&language=&language=english&prfh=font_sizeEEEmediumN1Nrecent_results_filterEEE1N1Nlanguage_uiEEEenglishN1Ndisable_open_in_new_windowEEE1N1NlanguageEEEenglishN1NsslEEE1N1Nnum_of_resultsEEE10N1Npicture_privacyEEEonN1NsuggestionsEEE1N1N
IE - HKU\S-1-5-21-1918482796-3435808618-3437081748-1000\..\SearchScopes\{A3EEDFD0-1629-40A9-AF54-2BC65D448E14}: "URL" = http://www.pricestalker.net/ProductSearch.aspx?keyword={searchTerms}
IE - HKU\S-1-5-21-1918482796-3435808618-3437081748-1000\..\SearchScopes\{AEFEFC1F-EFD2-48A7-92E4-B5C96F2DCAD3}: "URL" = http://addons.alltheinternet.com/texis/open/search?q={searchTerms}
IE - HKU\S-1-5-21-1918482796-3435808618-3437081748-1000\..\SearchScopes\{BB7753FB-F0CE-418A-9849-F249F082026C}: "URL" = https://startpage.com/do/search?query={searchTerms}&cat=web&pl=ie&language=english
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1918482796-3435808618-3437081748-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.

:files
C:\ProgramData\6063536.reg
C:\ProgramData\6063536.bat
C:\ProgramData\6063536.pad
C:\install.exe

:commands
[CREATERESTOREPOINT]
[emptytemp]


Ok, just don’t panic. ;D

Re-run above script (just in case ) and attach log.
Then be free to continue with other steps. Don’t worry, your computer will be just fine. ;D

error… My apologies. Wrong thread :-[

I’m confused now…I thought the 3rd try of OTL was good but I guess not.

Now I’m not sure which one to run now…the one magna has up now or essex?

Help ?

Ok…Before seeing these last 2 posts I ran rouge Killer and did the 3 steps…here’s the files attached.

PS: Let me know what which OTL I should run again…Magna or essex…thanks so much !

Ok I tried essex OTL and pasted the file and hit fix.

It didn’t do anything that I could see then that windows window came up and said" Windows need to close due to critical error in one minute"

Well my pc shut down .

Upon rebooting OTL file showed up but I’m not sure it’s the full file because it must have ran way less than a minute.

Anyway here it is…

Ok am i screwed…i ran essex file on OTL …what now ?

Ok MY pc has been taken over by freaking google which I despise.

When opening IE my start page goes to “Acer” which is my computer maker then FN google takes over and redirects it to googles homepage and plus it added tons of tool bars and now Bing is my default search engine.

My original home page was “Startpage” and “startpage” was my search engine.

??? HELP ???

No that fix would have no affect

((deleted))
OT.

@RainerRocks
I told you not to panic!

Follow “Multiple Antivirus Programs” steps. Then re-run OTL, click on RunScan and attach here fresh OTL.txt log.