Problems with Joke Blue Screen and XP Antivirus 2008

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bp9019, Jul 25, 2008.

  1. bp9019

    bp9019 Private E-2

    We did the whole Run and Read me file and used all of the cleaners using the instructions given. There is no longer a blue screen saying that we have spyware on the computer. The administrator's name that we are on now can have a normal desktop, but the other administrator can not, there is only a blue screen that does say that there is spyware on the computer. Both of the Limited accounts are perfectly fine and working normally. This problem began about 3 weeks ago, and we do not know how this got onto the computer. One of the limited accounts had problems with pop ups from the XP antivirus 2008. After these problems began we deleted the name and made a new limited account. This new limited account has no problems. The computer was running perfectly fine on everyone's accounts but problems began on tuesday on one of the computer administrator's accounts. The blue screen desktop with a warning of spyware on the computer came up. McAffee detected a "Joke Blue Screen" but could not completely remove it from the computer. I then called windows and had a representative take control of the computer and eliminate the XP Antivirus 2008 and 2009. Shortly after I had ran internet explorer, the warning appeared again on my desktop. I then ran spybot search and destroy 3-4 times. I also ran Rogue Remover 2-3 times. I then went to this website and followed the instructions given for removing malware. Here are the logs from all of the cleaners. They are on this post and 1 is contained on the next one. The First attachment is the combo.exe log, the second attachment is the spybot search and destroy and the third is the MGtools log.
     

    Attached Files:

  2. bp9019

    bp9019 Private E-2

    Here is the fourth and final log from Malware. One question, do I have to read the post and keep checking to see what i should do or will you email me notifying me? Thank you for all of your help. Its been very helpful.
     

    Attached Files:

  3. bp9019

    bp9019 Private E-2

    Sorry for another post but I forgot to mention something and ask a couple more questions. My internet does not show pictures only icons. But I do have an update for internet explorer and I have not done that yet. Could that possibly be the problem? And should I remove all of these malware and spyware removing programs when this is all done? Ocassionally when I am logged on my name, Spybot Search and destroy has windows popping up asking me whether I want to allow the change or deny the change.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    While you did have a lot of malware removed and we have some more to do, your problems with images may just be due to settings in your browser or other security software that need to be adjusted. Let's finish our cleanup and if you still have problems, you may need to post in the Software Forum.

    First you MUST disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 8
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. bp9019

    bp9019 Private E-2

    We followed all of the steps and still the other administrator's name has a blue backdrop without a warning. When we try to log onto the other user name, a black screen with a window having symbols showing block block Y with 2 dots on top block block block Y with an arrow on top block. Do we need to run all of the process thru the other administrators name to try to solve the problem completely? Should we install firefox now or wait until the entire process is finished? I still have no pictures on the internet on my name, theres only icons. If i right click the icon and click show picture, the picture comes up. Thanks again for all of the help. The logs from the scans we ran are attached
     

    Attached Files:

  6. bp9019

    bp9019 Private E-2

    Sorry for a second post but after I logged off of my name and had one of the limited users try to log onto their name, another box with symbols came up again. The symbols this time were block a with an up arrow block a with an up arrow block block t c with a mark over it. I then tried to bring up task manager and it didn't bring up the name this time. I then rebooted the computer trying to see if i could get the limited user's account to work and before the account choosing page even came up, another box came up with just a block and an a with a mark over it. The modem was off and we clicked ok. The names then came up and when we logged onto the limited users account it worked without any problems. Should we just press "ok" any time that this box comes up or should we do something else?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One of the first things in my last message that I said you MUST do (and I capitolized it then too) was to disable Spybot's Teatimer. You did not do this. You must do this right now.

    The second thing I asked you to do was to remove Windows Messenger which you also did not do. You must do this right now.

    You must always complete steps in the order written and only do what we ask you to do any nothing else.

    Then get another new MGlogs.zip file and attach it so that we can continue.


    All user accounts will need to be cleaned, but you must work on them one at a time to avoid confusion in the posts. Only the procedures in the below will be necessary to run on each account.

    Windows XP Cleaning Procedure

    Obviously you don't need to download and install software that has already been installed,but do check for updates before running SUPERAntiSpyware and Malwarebytes since they change frequently.

    You can do the below on all user accounts but if any are still infected, the problem may still occur.

    Fixing Locked Desktop
    • Right click on your Desktop and select Properties.
    • Then click the Desktop tab
    • then click the Customize Desktop button.
    • Now in the next window that comes up click the Web tab.
      • Make sure at the bottom that Lock desktop items is unchecked.
    • Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too.
    • Then click OK.
    • Click Apply. And click OK.



    You can install it now.
     
  8. bp9019

    bp9019 Private E-2

    I turned off Spybot's teatimer. Here's the log. When I restart the computer I still have a pop up box with symbols inside of it. I have to click "ok" to be able to use the computer and continue. I'm sorry I messed up the last step. As you can probably tell I'm not very computer literate. Thank you again.
     

    Attached Files:

  9. bp9019

    bp9019 Private E-2

    I ran the programs on the other administrator's name. Everything is fine with their account. My account on internet explorer still has no pictures. It only has icons. I downloaded Firefox and it still does not show any pictures. I have all of the logs from the other administrator. Do you need them?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be a malware issue. You need to check the configurations in your browers and also check that you are not blocking them with McAfee (like in the firewall or with any other setting). You may want to try shutting down the firewall and other components of McAfee and see what happens. Also test to see how things work in your account in safe boot mode.

    No!
     
  11. bp9019

    bp9019 Private E-2

    I found out how to fix my pictures so I can see them. Thank you very much for all of your help. And hopefully, I won't have anymore problems. I will definetly recommend you to anyone know thats having problems with their own computers.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds