Help!!!Everytime i open my laptop I hav virus

Solved/Closed
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012 - Feb 2, 2011 at 02:41 AM
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Feb 4, 2011 at 04:34 PM
Everytime im opening my lap top i received an error :

wOLjE has stopped working
A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available.

Then im receiving this alert from my anti-virus:

trojan:win32/AgentBypass.gen!K
so i will remove it and its fine but everytime i will restart my PC same error and virus is coming..

What to do now pls help!!!!

Thanks so much!!!
Related:

5 responses

Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Feb 2, 2011 at 04:37 AM
Greetings Baby Jane,

Nice to see you again.

Please download ATF Cleaner by Atribune & save it to your desktop.
http://www.atribune.org/ccount/click.php?id=1

*Double-click ATF-Cleaner.exe to run the program.

*Under Main "Select Files to Delete" choose: Select All.

*Click the Empty Selected button.

*If you use Firefox browser click Firefox at the top and choose: Select All

*Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.

*If you use Opera browser click Opera at the top and choose: Select All

*Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.

*Click Exit on the Main menu to close the program.
Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

Now run SAS:
Please download and scan with SUPERAntiSpyware Free
https://www.superantispyware.com/?rid=3324

*Double-click SUPERAntiSypware.exe and use the default settings for installation.

*An icon will be created on your desktop. Double-click that icon to launch the program.

*If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)

*In the Main Menu, click the Preferences... button.

*Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.

*Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
?Close browsers before scanning.

?Scan for tracking cookies.

?Terminate memory threats before quarantining.


*Click the "Close" button to leave the control center screen and exit the program.

*Do not run a scan just yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with SUPERAntiSpyware as follows:
*Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.

*On the left, make sure you check C:\Fixed Drive.

*On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".

*After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".

*Make sure everything has a checkmark next to it and click "Next".

*A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.

*If asked if you want to reboot, click "Yes" and reboot normally.

*To retrieve the removal information after reboot, launch SUPERAntispyware again.
?Click Preferences, then click the Statistics/Logs tab.

?Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

?If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.

?Please copy and paste the Scan Log results in your next reply.


*Click Close to exit the program.


good luck
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Feb 3, 2011 at 07:34 AM
here is the log, sorry it took so long for me to reply... thanks for the help...

SUPERAntiSpyware Scan Log
https://www.superantispyware.com/

Generated 02/03/2011 at 05:02 PM

Application Version : 4.48.1000

Core Rules Database Version : 6323
Trace Rules Database Version: 4135

Scan type : Complete Scan
Total Scan Time : 01:19:28

Memory items scanned : 327
Memory threats detected : 0
Registry items scanned : 8818
Registry threats detected : 3
File items scanned : 138875
File threats detected : 19

Adware.IWinGames
HKU\S-1-5-21-3649125081-1059824789-2482753333-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8CA5ED52-F3FB-4414-A105-2E3491156990}
HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}

Adware.Tracking Cookie
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\dell@ad.yieldmanager[2].txt
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\dell@ads.chikka[2].txt
cdn4.specificclick.net [ C:\Users\dell\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TJUP4WNW ]
ia.media-imdb.com [ C:\Users\dell\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TJUP4WNW ]
media.movieweb.com [ C:\Users\dell\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TJUP4WNW ]
media.mtvnservices.com [ C:\Users\dell\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TJUP4WNW ]
media.scanscout.com [ C:\Users\dell\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TJUP4WNW ]
msnbcmedia.msn.com [ C:\Users\dell\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TJUP4WNW ]
secure-us.imrworldwide.com [ C:\Users\dell\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TJUP4WNW ]
www.99counters.com [ C:\Users\dell\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TJUP4WNW ]
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\Low\dell@ad-emea.doubleclick[1].txt
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\Low\dell@ad.yieldmanager[1].txt
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\Low\dell@bs.serving-sys[2].txt
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\Low\dell@imrworldwide[2].txt
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\Low\dell@insightexpressai[2].txt
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\Low\dell@lfstmedia[1].txt
C:\Users\dell\AppData\Roaming\Microsoft\Windows\Cookies\Low\dell@serving-sys[1].txt

Adware.MyWebSearch/FunWebProducts
HKU\S-1-5-21-3649125081-1059824789-2482753333-1000\SOFTWARE\FunWebProducts
C:\USERS\DELL\APPDATA\LOCAL\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\GTVUV93I\MYWEBFACE[1].EXE

Trojan.Agent/Gen-Falcomp
C:\USERS\DELL\APPDATA\ROAMING\PPCZ.EXE
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Feb 3, 2011 at 04:04 PM
Hello Jane,

Did you run ATF-Cleaner?

Looks as if you had a Trojan Horse.

I strongly recommend you no longer surf MyWebSearch/FunWebProducts
you are sure then to get a virus which one day will cripple your system. Aside from Limewire, Fun Web products is (My Web Search) is deadly poison.

How is your system performing now.

As a last step,

Download, install and run Malwarebyte which you can find on this site:

https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/ es-anti-malware

Ensure you make an update.

Please request a FULL system scan, which may take from 20 minutes to hours. Do not interfere no matter how long in takes. The creators of Malwarebyte recommend that while the tool is running that you go do something else, such as watching a rerun of Gone with the Wind or read Tolstoy's War and Peace.

If Malwarebyte restarts your system, launch it again to finish the Full scan.

When the scan is completed, delete all items found.

Once your computer is clean and working normally just to be on the safe side
*Turn off system restore and wait 30 seconds,
*Turn it back on and create a new restore point.

This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.
It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Feb 4, 2011 at 05:05 AM
its fine now however, it is still hanging whenever im playing it girl in facebook i dont know why??

Thanks a mill....
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Feb 4, 2011 at 05:11 AM
I'm happy that you system is now clean as a whistle. As for Facebook, it's a totally different issue, I suggest you begin a new thread as me, being an exception to the rest ogf the world, I am not at all familiar with Facebook.

It was a pleasure to have helped you again. Pay to the next.

Good luck
0

Didn't find the answer you are looking for?

Ask a question
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Feb 4, 2011 at 05:28 AM
hahaha ... hope ul not charged me too much!!!
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Feb 4, 2011 at 04:34 PM
What I meant was to help someone else, anybody, like helping an old lady to cross the street, hence creating a chain across this planet.
0