Annoying Antivirus XP 2008

Discussion in 'Malware Help (A Specialist Will Reply)' started by Xthralls, Aug 16, 2008.

  1. Xthralls

    Xthralls Private E-2

    Ok, I've uninstalled the Antivirus XP 2008 a couple lesss then 10 times and it keeps coming back. I ran the cleaning procedures to the T, but even when it appears to be gone, it's back just hours later (if that).

    I've attached the logs from Malwarebytes, SuperAntiSpyware, and Combo, (will post MGLogs seconds after posting this). I'm not sure if the SuperAntiSpyware log is complete or not because the system shut down to the blue error screen even after making the adjustments listed on the site.

    Everything else seems to be fine, with exception to this Antivirus XP 2008. Please, if there's anything else I can do to get rid of it let me know, every day I have it is another day fearful of the whole computer crashing or freezing up!
     

    Attached Files:

  2. Xthralls

    Xthralls Private E-2

    Here are the MGLogs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Please uninstall the below right now:
    Java(TM) 6 Update 3
    Symantec Network Drivers Update
    Viewpoint Media Player
    Winferno Registry Power Cleaner

    Then reboot your PC.

    After reboot, delete the below folders:
    C:\Program Files\Free Offers from Freeze.com
    C:\Program Files\Freeze.com

    Now please download and use the version of MGtools that was given in the READ & RUN ME. You are way out of date with what you used. Attach a new MGlogs.zip file.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not make the agreement for running HJT ....you need to do that and then let the MGTools run until it tells you it is finished.

    Please use windows explorer to find and delete:
    C:\WINDOWS\system32\6F1.tmp
    C:\WINDOWS\system32\6F0.tmp
    C:\xf9.exe

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  5. Xthralls

    Xthralls Private E-2

    Ok, so I've attached the new C:\MGLogs.zip file. I did everything you both stated to do except for one thing, deleting the Symantec Network Drivers Update. I could not find them anywhere, either in the Add/Remove Programs or through an entire search through the computer. Maybe I'm just overlooking them?

    Thanks for all your help so far!
     
  6. Xthralls

    Xthralls Private E-2

    Sorry, did not attach to last one, her's the zip file.
     

    Attached Files:

  7. Xthralls

    Xthralls Private E-2

    Ok, I would assume this has something to do with the malware you've been helping me to remove, but I thought I should mention it in case it might pinpoint any problem more directly. Everytime I walk away from my computer, when I come back almost an hour later I get a blue screen error message stating the computer was shut down to protect against an error, and I have to completely restart in order to access the internet (this page) only to have it happen again an hour or so later.

    It was doing this the last few days but I was hopeful it had stopped. Although it hasn't, I've noticed it never crashes while I'm actually using the computer, so could that mean it might be something that only occurs during an idle mode?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First thing to do is see if this is still in your add/remove program list and remove it:
    AntivirXP08

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  9. Xthralls

    Xthralls Private E-2

    I ran the programs, deleted Antivirus XP from Add/Remove programs (again), pasted the codes in notepad and run them, and now I've attached the MGLogs.zip and Avenger.txt

    The only thing was that I could not find

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    in the analyse.exe when it ran. That was the one program I could not find the other day when you mentioned to uninstall it from the Add/Remove.

    I can't tell just yet if everything's fine, I probably won't know until morning as it only seems to have a problem when the system is idle. I appreciate all your help so far, thanks.
     

    Attached Files:

  10. Xthralls

    Xthralls Private E-2

    So my computer just restarted it self and came up on the same blue screen displaying a message about an error and it was shut down to protect the system. Basically the same thing that's been going on for a week now. All it said for the reason was "Bogus_Drive". Again, I don't know exactly why it keeps doing this, it seemed to have started rebooting like this just after I installed SuperAntiVirus. When I first ran that program that's when it first crashed and has been doing so ever since. Should I just uninstall it?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First right click the desktop / properties / desktop / customize / web ...make sure the is nothing there and no boxes are checked.

    Yes you can uninstall SAS ...but first I want you to run both SAS and MWB's on each user profile. Then go to safe mode and run ComboFix again.

    Next, after attaching the logs, right click my computer / properties / advanced / startup and recovery....settings and uncheck the box for restart on errors. This will give you a BSOD when it restarts itself....now tell me exactly what the error is...
     
  12. Xthralls

    Xthralls Private E-2

    Ok, this is strange, I right clicked the desktop and clicked properties, but the box is different from how it always has been. There is no desktop tab so I cannot finish that. The only tabs there are now are Themes, Appearances, and Settings. It no longer even has a tab to change the wallpaper on the screeen. Should I just skip over this step?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes..skip it for now.
     
  14. Xthralls

    Xthralls Private E-2

    I ran everything you said to, but I could not log onto to the other users as there's a password for each and I only know my own. If that's a problem I'll go back and fix it later once I get the other passwords from my family.

    But after I ran SAS this time, I made sure to stay by the screen so the system wouldn't idle and restart, and it worked. It completed exactly like it was supposed to and once the system restarted the desktop properties was back to normal. I checked it and there were no boxes check or anything listed. Then I just finished with MWB and Combo and I get the feeling things will be running smoothly again, but will know for sure later.

    I've attached the new logs, and I want to thank you for everything if this does turn out to be it. I appreciate all of your help and the time it took you.

    Thanks,
    Sean
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are the "administrator" .....you really should have everyones passwords. Let me know what the results are from running on the other profiles. The logs you just attached show you the infections removed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds