Computer infected. Cannot do anything including get into email or on internet

View previous topic View next topic Go down

Computer infected. Cannot do anything including get into email or on internet

Post by mhowell on Mon 05 Jul 2010, 10:58 pm

Hi. Whenever I try to get on the internet or check my email I get an error message that says "Application cannot be executed. The file wuauclt.exe is infected. Do you want to activate your antivirus software now? When I close the error message it just pops back up and will not allow me to do anything. When I click yes to activate the antivirus software it wants me to buy the program. Another thing that happens is that a porn website keeps popping up. My 10 year old son uses my computer as well and is pretty trustworthy and has assured me that he has not been messing around with anything like that. I do believe him because he basically just plays games on the computer. He did admit to going ahead and trying to download games that were deemed as being potentially unsafe for the computer. I am sending this email from another computer because I cannot get on my computer to access email or anything. Please Help. Thank you.


Last edited by mhowell on Mon 05 Jul 2010, 10:59 pm; edited 1 time in total (Reason for editing : Left something out)

mhowell

Unborn
Unborn

Posts : 1
Joined : 2010-07-05
Operating System : Windows Vista

View user profile

Back to top Go down

Re: Computer infected. Cannot do anything including get into email or on internet

Post by Sneakyone on Tue 06 Jul 2010, 4:46 am

Hi, Welcome to GeekPolice.net!

Please download and run RKill.

Download mirror 1 - Download mirror 2 - Download mirror 3

  • Save it to your Desktop.
  • Double click the RKill desktop icon.
  • It will quickly run and launch a log. If it does not launch a log, try another download link until it does.
  • Please post its log in your next reply.
  • After it has run successfully, delete RKill.

Note: This tool only kills the active infection, the actual infection will not be gone. Once you reboot the infection will be active again! Please do not reboot until instructed further to do so.

=========

Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    c:\$recycle.bin\*.* /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    nvstor32.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    explorer.exe
    svchost.exe
    userinit.exe
    qmgr.dll
    ws2_32.dll
    proquota.exe
    imm32.dll
    kernel32.dll
    ndis.sys
    autochk.exe
    spoolsv.exe
    xmlprov.dll
    ntmssvc.dll
    mswsock.dll
    Beep.SYS
    ntfs.sys
    termsrv.dll
    sfcfiles.dll
    st3shark.sys
    ahcix86.sys
    srsvc.dll
    nvrd32.sys
    /md5stop
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time




Sneakyone

Tech Officer
Tech Officer

Posts : 2707
Joined : 2010-01-10
Operating System : Windows 7 Ultimate 64-bit

View user profile http://twitter.com/AVerySneakyone

Back to top Go down

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum