antivirus xp 2008

Discussion in 'Malware Help (A Specialist Will Reply)' started by rcc2324, Aug 5, 2008.

  1. rcc2324

    rcc2324 Private E-2

    I'm not sure how my pc got infected with the Antivirus xp 2008. It first started with the desktop blue screen spyware detected warning.IT ALL STARTED ABOUT 7/25/08.
    I did the read and run me first, but I still have the same problems.
     

    Attached Files:

  2. rcc2324

    rcc2324 Private E-2

    here is the MGlog.zip file.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run MalwareBytes and have it fix everything it finds. No point in running it if you don't let it fix the problems.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from MalwareBytes.
     
  4. rcc2324

    rcc2324 Private E-2

    did as you requested and problem still exists.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MalwareBytes log:
    Are you having a problem removing the items it finds?
     
  6. rcc2324

    rcc2324 Private E-2

    I have not tryed removing the manually.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The program will remove them...you just have to tell it to.

     
  8. rcc2324

    rcc2324 Private E-2

    everything is checked, it ssay that those files would be removed after reboot.
    I goahead and let it reboot but it comes back. see last mbam-log
     

    Attached Files:

  9. rcc2324

    rcc2324 Private E-2

    TimW,
    Is there anybody who can help me beyond 18:30 at night?
    I work during the day and don't get home till after 17:00.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the new MGLogs.zip after running MalwareBytes.

    And no there is often not someone here after that hour at night. This would go faster if you would follow the instructions given .....I could now be looking at the MGLogs and seeing what else needed doing and giving you a possible final cleaning.
     
  11. rcc2324

    rcc2324 Private E-2

    Sorry.
    Here are the MGlogs.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not attached...try again. :)
     
  13. rcc2324

    rcc2324 Private E-2

    I get the following error message:
    Upload Errors
    MGlogs.zip:
    You have already attached this file in thread : antivirus xp 2008
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That means you are trying to attach a log that you already attached and it is not a new run of the logs ...do that by running the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  15. rcc2324

    rcc2324 Private E-2

    ok here you go
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable the guest account in user accounts.

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  17. rcc2324

    rcc2324 Private E-2

    antivirus xp 08 did not start but I still have the blu screen with warning spyware detected...
    the home page is no longer hi-jacked
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run combofix again and attach the new log.
     
  19. rcc2324

    rcc2324 Private E-2

    here you go
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet..we are getting there....

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  21. rcc2324

    rcc2324 Private E-2

    every thing is looking good.
    was able to change desktop from the blue screen warning.:)
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet ....Avenger did remove them ....I'll look at the MGLogs in the morning, though I believe they will not show any malware ..:) (Time for me to rest.....and while I do that, you can peruse this:
    How to Protect yourself from malware!)
     
  23. rcc2324

    rcc2324 Private E-2

    Thakn you for working late with me yesterday and today, I really appreciate it. again THANK YOU!!!:-D
    Iwill follow the link to "How to Protect yourselffrom malware".
    till tomorrow.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome......let's do some clean up:

    Run thisDisable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Now reboot and install:
    Java Runtime 6

    If all of the above was successful and If you are not having any other malware problems, it is time to do our final steps:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds