antivirus xp 2008

Discussion in 'Malware Help (A Specialist Will Reply)' started by johnnykone, Jun 21, 2009.

  1. johnnykone

    johnnykone Private E-2

    please help me!
    have run:::
    malwarebites anti malware
    superantispyware
    one care tool(Microsoft)
    malware removal tool(microsoft)
    spybot S&D
    SmitFraudfix
    None of them have even detected this virus that is making AVG run my computer at 90% most of the time.......:cool
     
  2. johnnykone

    johnnykone Private E-2

    how do i get mgtools.exe files on here so i can send them to you??
     
  3. johnnykone

    johnnykone Private E-2

    please help me as soon as possible i cant use my puter!!
    thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should have read the email you received when you signed up. The additional posting of messages is bumping you out of the queue. In the email, you were instructed to read this: Don't Bump! It Only Hurts You!!!

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  5. johnnykone

    johnnykone Private E-2

    sorry dont know how to do attachments,,,also dont know how to send you the results from MGtools.exe,,this is my first forum so im a complete newbee and have no idea what im doing.........
    thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The cleaning procedure gave you the instructions several times where it gave you the below link:

    HOW TO: Attach Items To Your Post

    Please attach all 4 logs now. Inline logs will be trapped by the spam filters and they clutter up the thread and make it harder to work on.
     
  7. johnnykone

    johnnykone Private E-2

    thanks so much for your patience:-D
    as you will see malwarebytes did detect and remove the pesky vermin at one point but unfortunatly not permanently.......
    after almost 2 weeks of dealing with a malfunctioning computer im ready to try anything you may suggest to try to fix it....
    thanks much
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All that is being found is junk that you downloaded and save to your PC which is confusing the scanners. You need to delete all the below junk (if still found) and then empty your Recycle Bin and reboot:
    Code:
    "C:\Documents and Settings\Owner\Desktop\"
    an15fb~1.mht  Jun 21 2009      192217  "Antivirus 2008 or Antivirus2008 Info & Manual Removal Guide - ESGI Support Center.mht"
    an971c~1.mht  Jun 21 2009      125361  "Antivirus 2008 - from Wiki-Security, a source for malware detection and computer security.mht"
    antivi~1.mht  Jun 17 2009      108656  "Antivirus 2008 - how to remove.mht"
    avgand~1.url  Jun 17 2009         242  "AVG and Antivirus 2008.url"
    bitsfr~1.url  Jun 17 2009         445  "Bits from Bill Removing AntiVirus 2008-2009 The Easy Way.url"
    fighti~1.mht  Jun 17 2009     2015006  "Fighting Antivirus XP-2008-2009 Malware  Bauer-Power- Information is Power!.mht"
    howdoi~1.mht  Jun 17 2009      719851  "How do I remove Vista Antivirus 2008 from my Windows XP Pro machine  Vista Antivirus 2008.mht"
    howtog~1.mht  Jun 17 2009      774780  "How to Get Rid of the XP AntiVirus 2008 Virus  eHow_com.mht"
    howtor~1.mht  Jun 17 2009      300543  "How to remove XP Antivirus Protection - Techie Corner.mht"
    howtor~2.mht  Jun 21 2009      741638  "How to Remove Antivirus XP2008, Uninstall AntivirusXP 2008 free  Internet Security Blog.mht"
    remove~1.mht  Jun 17 2009      149374  "Remove Antivirus 2010, 2009, 360 fake Antivirus 2009 rogue spyware manual removal help, how to.mht"
    smitfr~1.mht  Jun 17 2009      274116  "SmitFraudFix Free Antivirus Download to Remove Zlob and Other Pests.mht"
    thanky~1.mht  Jun 17 2009      301499  "Thank you for downloading Spyware Doctor.mht"
    topwin~1.mht  Jun 17 2009      259636  "Top Windows Antivirus.mht"
    zulit-~1.mht  Jun 17 2009      409482  "Zulit - REMOVE ****ING ANTIVIRUS 2009-2008 for FREE.mht"
    Also delete MGtools.exe from your Desktop because it does not belong there.

    You also need to uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME.

    After deleting ALL of the above, download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the new C:\MGlogs.zip file.

    Make sure you tell me how things are working now!
     
  9. johnnykone

    johnnykone Private E-2

    got error 403 ... forbidden;;; when clicking link in email,,but no problem downloading MGtools.exe from thread.....and it ran on its own,,,
    avgrsx.exe still running up to 90% of my puter and spy sweeper is blocking redirected sites,,,,,,,,
    looks like no change;; but ill try Malwarebytes and others to see if it will now be detected...
    thanks:wave
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not uninstall Viewpoint Media Player as requested.

    You also did not delete the MHT files from your Desktop as I requested.

    If you are not going to follow instructions, I cannot help you.

    You were supposed to download the MGtools.exe file and safe it to your root folder as instructed. You did not download it. You ran it directly from the website which I can see from your log which shows MGtools running from the IE temp folder:

    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\VESFQE0U\MGtools[1].exe

    Please be sure to follow instructions properly in the future as it can sometime be the difference between success and failure. Also it could be the difference between breaking your PC and fixing it.


    Uninstall them. Reboot and reinstall them; however if you are running a full security suite progam from SpySweeper, you should not be using it while you have AVG8 installed.
     
  11. johnnykone

    johnnykone Private E-2

    I hope i got it right this time......
    deleted windows media files
    reinstalled AVG and Spy Sweeper
    Unfortunatly my puter is still behaving the same as before.......
    what shall we try now??
    thanks
     

    Attached Files:

  12. johnnykone

    johnnykone Private E-2

    sorry the text in the email was different than in the thread,,,
    uninstalled Spy Sweeper and avgrsx.com is not running hot anymore,,
    also since spy sweeper is not installed its not blocking sites anymore,,,
    is my puter fixed?
    what next?
    thanks
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most likely. Your problem was not malware. It was you. You installed multiple antivirus/security suite type programs. The first instructions in the READ & RUN ME even told you that you must not do this and to remove all but one before even doing anything else. Had you done that first, you would have save yourself a bunch of time.

    It is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. johnnykone

    johnnykone Private E-2

    Question:
    can malware jump a partiton??
    thanks in advance
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes some malware will.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds