Antivirus XP 2008

Discussion in 'Malware Help (A Specialist Will Reply)' started by brown0619, Sep 1, 2008.

  1. brown0619

    brown0619 Private E-2

    My dad has this trojan in his computer (windows xp) and I have been trying all day to remove it with no luck. I have used your removal procedures many times before and know how to use them. The only problem is that I cannot view any webpages on the infected computer to download the tools needed. All the pages say they cannot be displayed. Can I save the tools on a disk and load them into the infected computer that way? Should I try malwarebytes first or SUPERAntiSpyware? I will post logs after I am actually able to run the tools on his computer. Thanks in advance for your help.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.

    Run as much of the Read and Run First instructions as you can and attach the logs when you are ready.
     
  3. brown0619

    brown0619 Private E-2

    I have been able to run all of the Read & Run programs. It detected several infections and removed what it could. The only thing I could not do was install the windows recovery console as directed in the combofix instructions. Another thing to note about this computer is that about a year ago the computer crashed and the "dell support guys" came and tried to repair it. The computer has never been the same and I'm sure the registry is beyond messed up. Just thought this should be mentioned.
     

    Attached Files:

  4. brown0619

    brown0619 Private E-2

    cont...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans took care of most of it...let's do this:

    If you haven't already, please disable the Guest account in User accounts.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    F:\WINDOWS\Temp
    F:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  6. brown0619

    brown0619 Private E-2

    Everything seems to be running good now. The things that you had me do seem to have fixed the problems I was having. The computer is running a little slow, but I think that has to do with another issue this computer has. Let me know how everything looks. Thanks so much!!:-D
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet......now Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then it is time to do our final steps:
    You may wish to use a Startup Manager
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds