Joke-Bluescreen.c antivirus xp 2008

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Deyna, Aug 4, 2008.

  1. Deyna

    Deyna Private E-2

    hello

    i've had some trouble with joke-bluescreen.c

    i did the entire "READ & RUN ME FIRST. Malware Removal Guide" although the blue background didn't go away, then i ran McAfee again and it took away joke-bluescreen.c (or so it says) although i left for holiday for a week and when i got back ( i had the computer completely unplugged no internet or cables plugged in) a little red circle with a white cross in it in the lover left corner, and if i put my marker over it it said the following:

    Your computer is infected!
    Windows has detected spyware infection!

    It is recomeneded to use special antispyware tools to prevent data loss.Windows will now download and install the most up-to-date antispyware for you.

    Click here to protect your computer from spyware!"

    and then occasionally it tries to download antivirus xp 08(or something, i don't remember really), and then McAfee warns me to say that the antivirus isn''t working and when i'm trying to fix it it just says something about an error who causes it to be unable to fix the problem, even though it's working, i took away the joke-bluescreen.c file even when it said it wasn't working!

    and after this neither superantispyware, CCleaner nor HJT is working

    the infected computer is now offline, and i'm writing this from another computer, so please i need some advise!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you ran the READ & RUN ME FIRST, you need to attach the logs that were requested if you still need help. The below is a quote from the READ & RUN ME
     
  3. Deyna

    Deyna Private E-2

    oups, seems like i missed some parts of it...sorry =/

    although i couldn't start SAS at the beginning, i just had to rename the .exe file to be able to run it. i take this as the virus prevents certain programs from being run?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes malware does try to look for certain process names so that it can block them from running.
     
  5. Deyna

    Deyna Private E-2

    Antivirus xp 08 Done "RUN AND README"

    hello

    i have removed the virus blue-jokescreen.c although i still have a program which starts when i boot my computer which says that my computer is infected and if i click on that messega it tries to download this "antivirus"

    i have removed it with Malwarebytes although when it does windows warns me about that "windows might not function correctly" when i have removed all of the files/trojans, it then also wants me to reboot the computer to complete the removal of the malware

    when it reboots it does that fine, rebooting normal and everything is working perfectly then a minute after rebooting the computer does that again when it have booted this time the same annoying warning is down at the right-bottom of my screen...

    need help please!

    P.S your site won't let me upload the MGTools zip file...i don't know why!?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Antivirus xp 08 Done "RUN AND README"

    You need to attach the log from ComboFix too.

    You need to make sure you have checked the Remember Me box when you log in and also make sure you are not using a popup blocker that is blocking you from downloading it. But I'm not sure why you say you cannot download it. I see the below in the HijackThis log

    C:\spel\MARKUS\Antiviruses(mitt)\MGtools.exe

    That is not where we asked you to save it though.

    It should be c:\MGtools.exe

    [edit] Ooops! I just realize you said UPLOAD MGtools.zip file. The file is C:\MGlogs.zip not MGtools.exe
     
  7. Deyna

    Deyna Private E-2

    oh thanks, here it is...i think o_O

    anyhow i'm sorry i saved it in the wrong folder, does it make a big difference? should i download it again and save it?

    yeah well thanks and sorry for the inconvienient i may have caused :eek:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes it will not run properly if instructions are not followed. It depends on the Windows installation (how and where it is installed). You don't need to rerun it now but please be more careful following instructions as doing the wrong thing can sometime be catastrophic.

    You still need to attach the ComboFix log I already requested. Please attach the c:\combofix.txt log you have right now before doing the below which will overwrite it.


    Uninstall the below old software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2
    Kazaa Lite K++ v2.4.4 <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Policies\Explorer\Run: [rJTv8rzAo0] C:\Documents and Settings\All Users.WINXP\Application Data\lklalmly\rwjuxwra.exe
    O21 - SSODL: ShCfgChk - {4B4CC8C4-6862-018E-7153-026D53076318} - C:\Program\baxmrqc\ShCfgChk.dll

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 9, 2008
  9. Deyna

    Deyna Private E-2

    here is the ComboFix log

    although i don't know if these are correct anymore since it looks like i've gotten infected again

    somehow after doing the run and readme the virus seems to have reinstalled itself completely

    the joke-bluescreen.c file is back and antivirus xp 2008... although seems like they were removed by SAS...

    anyhow i'm going to do EXACTLY as you say... so i won't do something like installing something in the wrong section again
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to do what I already gave you in message # 8.
     
  11. Deyna

    Deyna Private E-2

    sucess message received after double clicking on the fixme.reg

    although i'm still having the blue background and windows firewall keeps complainging about trojans, keyloggers, phising etc...

    even though i can't remember installing windows firewall!

    thanks for helping =)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You waited too long to follow the instructions in message # 8 and now have new infections because of the delay.

    It is part of Windows itself and it is not adequate as you will see when we get to final instructions.




    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now double click on the fixME.reg patch saved to your Desktop in the previous fix and allow it to be added to the registry again.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. Deyna

    Deyna Private E-2

    everything seems to be running smoothly now!

    Thank you very much!

    here are the files though if you want them to make sure every malware is gone?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds