blue screen that says computer infected with spyware- help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mastermind9192, Jul 10, 2008.

  1. mastermind9192

    mastermind9192 Private E-2

    i know there a few threads with the same problems but there seems to be different solutions for different ppl

    i got a blue screen that says i am infected w/ spyware and then it does not let me do anything on the computer because pretty much everything is "disabled by administrator" even tho i AM the administrator...
    so i decided to run hijackthis in SAFE mode because normal mode would not let me browse any website as it would "direct" me to pages where there are ads of antispyware and antivirus softwares.
    also, winspyware (which i didnt previously have on my computer) is somehow installed on my computer and i get a random screensaver that is a blue screen with a lot of writing which then turns into the exact screen of windows xp during start (blue bar going left to right)
    here's the hijackthis file:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:16:43 AM, on 7/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Safe mode with network support

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Jul 10, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. mastermind9192

    mastermind9192 Private E-2

    but the problem is i am not able to go on any websites as anything i go on is "redirected" to some other website that promotes installing their anti-virus softwares..what should i do ?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try safe boot mode or download the required tools using another PC and then copy to this PC using a CD, flashdrive....etc.
     
  5. mastermind9192

    mastermind9192 Private E-2

    well i tried going through the steps but after installing and scanning w/ superantispyware, none of the other softwares would install or load - i tried to do it in normal and safe mode ..also i even installed the softwares on a usb stick and tried running them from there but my computer just wouldnt let me open the programs

    so what should i do ?
    i am attaching the log file of superantispyware
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you really try to use MGtools? It does not install. It just runs.

    I suggest that you run SUPERAntispyware one more time (attach the new log) and then try running the MGtools procedure and attaching the C:\MGlogs.zip file that is requested.
     
  7. mastermind9192

    mastermind9192 Private E-2

    yeah i forgot to try that one
    but i did it now and i have attached the .zip logs from it
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As requested in my previous message please run SUPERAntispware again and attach a new log. Make sure you get the updates first since you are way out of date.

    After running SUPERAntiSpyware again with the current updates, please try Malwarebytes Anti-Malware again.

    The no matter what happens from the above, continue with the below. Your PC is very very badly infected. This is often a sign of poor surfing habits and/or too many P2P or torrent downloading.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [lphcrkkj0erbr] C:\WINDOWS\system32\lphcrkkj0erbr.exe
    O4 - HKLM\..\Run: [SMshctkkj0erbr] C:\Program Files\shctkkj0erbr\shctkkj0erbr.exe
    O4 - HKLM\..\Run: [b4bda793] rundll32.exe "C:\WINDOWS\system32\rvksyuef.dll",b
    O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    If you have USB flashdrives or external drives and if you have plugged them into other PCs, they may all be infected. You should look for all of the files list in the Avenger fix and delete them on an external devices or other PCs.
     
    Last edited: Jul 13, 2008
  9. mastermind9192

    mastermind9192 Private E-2

    i am following the steps according to ur last reply
    and i am still not able to install and run Malwarebyte but as u said i moved on to other steps - i am stuck at the point where i am supposed to uninstall J2SE 5.0 b/c i cannot access control panel from start menu or by right clicking "start" and selecting "explore" ..i tried uninstalling it from safe mode but it did not let me uninstall it but safe mode did let me uninstall viewpoint media player

    what should i do now?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on thru ALL steps.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds