Vista Antivirus 2008

Discussion in 'Malware Help (A Specialist Will Reply)' started by stackley, Aug 11, 2008.

  1. stackley

    stackley Private E-2

    Very frustrating, I have a brand new build computer with System Mechanic Pro for anti-virus and firewall. I logged in this morning and Vista Antivirus 2008 has taken over. It hijacks all my web pages. I can not get to this forum on that computer. The program shows on the control panel but it is not in add/remove programs. Help please....again !!

    Computer:
    ASUS P5E WS Pro
    Intel E8500
    Windows XP Professional
    GeForce 8800 GT
    Raptor 150g 10,000 RPM
    Seagate 500g
    2x1 gig Corsair DDR2

    Thanks,
    Steve Ackley
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    If something does not run, write down the info to explain to us later but keep on going.

    Do not assume that because one step does not work that they all will not.


    READ & RUN ME FIRST. Malware Removal Guide


    Note:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode

    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. stackley

    stackley Private E-2

    OK--you guys are great. It took about 4 hours to get it all sorted but I think I am good to go. What I dont understand is how this could have happened.
     
  4. stackley

    stackley Private E-2

    OK--you guys are great. What I dont know is how this really happened. This is a new build computer. All I did was use the file transfer wizard from my old computer which had no problems...and I dont think that moves applications. It took me the better part of 4 hours to do all the work, but it all seems alright. I could not follow everything in sequence as Spybot required access to the internet and I could not get it until I ran Malwarebytes. I have attached the various logs requested.

    Once again, thank you very much. I do not know if you accept payments/contributions, but I would be more than happy to send something, just let me know how.

    Thanks again

    Steve Ackley

    By the way--this is one hell of an program. If this did not work, I was going to call my credit card company, tell them what was going on....pay the fee to buy their program---so Icould uninstall it and then run a charge back.
     

    Attached Files:

  5. stackley

    stackley Private E-2

    OOps....one lingering problem....I can not install a desktop image....my desk top is bright white.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the MGLogs.zip --> from running the MGTools.exe.
     
  7. stackley

    stackley Private E-2

    OK...I thought when I ran the program is said it attached that log to my reply. I am at the office so I will have to send them this evening
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem ....the log is here: C:\MGLogs.zip.
     
  9. stackley

    stackley Private E-2

    Attached are the requested MGlogs
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean.

    There are a few things to tidy up:
    Use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\McAfee
    C:\Program Files\Kazaa
    C:\Program Files\McAfee
    C:\TEMP

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Download and install:
    Java Runtime 6

    And you should run SAS and MWB's on each user account.

    Did you right click the desktop / properties / desktop / customize / web...and check that no box is checked and only my current home page is showing.

    Tell me how things are running.
     
  11. stackley

    stackley Private E-2

    OK--cleared out the suggested files---they were actually empty, just carried over by the file and transfer wizard. I ran the regfix..but when I merged it.....nothing appeared to happen. Disbled Windows messenger, installed Jave runtime 6, ran SAS and MWB on all accounts and they all came up clean (well a few cookies). All seems to be running well,.....but I still have a totally screwed up desktop. I have three other accounts set on the computer and those desktops are fine. On mine...I can see the desk top when logging on and off, but I have a very annoying one when I am logged in. I tried what you suggestd and that only added the bar on the left that you see. I have attached a print screen copy.

    I appreciate all of your help, and as I mentioned in one of my earleir post, I am happy to send a donation to help you guys keep this going, just let me know how.

    Thanks again

    Steve Ackley
     
  12. stackley

    stackley Private E-2

    Well it wont let me attach the file showing my desktop--said it is too large
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. stackley

    stackley Private E-2

    Well I am happy to uninstall that program. As far as I am concerned that program was a complete waste of time. I would not get it to work at all, and just used the windows file transfer wizard to migrate to my new computer.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suspect something didn't migrate.....save your data on that account, then remove it and create a new one.
     
  16. stackley

    stackley Private E-2

    Well now I have white desktops on a couple of accounts and am getting:

    can not find file://c:/windows/privacy_danger/index.htm
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click the desltop / properties / desktop / customize / web....remove anything there and make sure no box is checked....do it on both accounts...now please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Have you run SAS and MWB's on all accounts?

    I would also like to see a new COmboFix log.
     
    Last edited: Aug 16, 2008
  18. stackley

    stackley Private E-2

    Yea---Victory is ours!! I have both of the desktops back and I have attached the requested logs. I did run SAS and MWB on all of the accounts a few days ago, but I will run them again.

    Again...thanks, and hopefully this is the last you will hear from me on this matter.

    Steve Ackley
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good....If you are not having any other malware problems, it is time to do our final steps:
     
  20. stackley

    stackley Private E-2

    All done, and thank you once again.

    Steve Ackley
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds