Antivirus Xp Pro

Discussion in 'Malware Help (A Specialist Will Reply)' started by whited05, Feb 1, 2009.

  1. whited05

    whited05 Private E-2

    Looks like I am infected with Antivirus XP pro I followd the clean steps and it just poped back up again

    I am ataching logs
     

    Attached Files:

  2. whited05

    whited05 Private E-2

    here are a couple more logs. I'm not sure where my SAS log is

    Again Thanks for any help you can give
     

    Attached Files:

    Last edited: Feb 1, 2009
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    **CAUTION: Using P2P programs and torrent downloads can be dangerous,
    as they by-pass your firewall and may contain malware.



    If you haven't already, please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 2"
    J2SE Runtime Environment 5.0 Update 4"
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java 2 Runtime Environment, SE v1.4.2_05"
    Java 2 Runtime Environment, SE v1.4.2_06"
    Java(TM) 6 Update 7"
    Viewpoint Media Player

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now these files are infected:
    You need to copy them from here and put them back into the system32 folder:
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now re-run ComboFix.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and Combo.

    Be sure to tell us how things are running.
     
  4. whited05

    whited05 Private E-2

    Tim first off let me say thank you very much

    all old version of java are deleted


    I could not replace the following. I got a sharing violation
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What have you done while we are working on this? You have new infections and changes to your logs.
    And this has appeared:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now update SAS and run the scan and attach the log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  6. whited05

    whited05 Private E-2

    C:\MGtools\analyse.exe Is was not able to find the following.

    I recieve a success from adding the registry componets

    I have attached the logs from avenger and MGtools I am currently running SAS and will attach logs when done
     

    Attached Files:

  7. whited05

    whited05 Private E-2

    I ran SAS it every time I run this I do not get a log file also it seams to have reactivated the original issue. I am currently running :\MGtools\GetLogs.bat and will post a log file.

    At this point the offenders have disabled taskmanager, and I am getting a popup in the systray saying "warning security report your computer is infected it is recomended to start a spyware clenser tool" I know if I click on this is goes to the Antivirus Xp Pro website.

    Dan
     
  8. whited05

    whited05 Private E-2

    ok here is the new c :\MGtools\GetLogs.bat log zip
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  10. whited05

    whited05 Private E-2

    I followed all steps the registry fix was successful.
    here are the logs. Again Thanks for all of your support
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You never answered my question about what was done to this system between my original fix and this last round.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Run CCleaner.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Before you do anything further, go HERE and download and install:
    1 AV program
    1 Firewall program
    1 Anit-spyware program

    And reset msconfig to normal start up!
     
  13. whited05

    whited05 Private E-2

    I installed AVG and Spybot search and destroy. I tried to install outpost but it caused my computer to constantly reboot.


    my Son while I was at work went to another website, he said he ran MBAM, ATF Cleaner, SmitfraudFix and combofix
     
  14. whited05

    whited05 Private E-2

    At this point AVG has disabled my nic card by removing drivers. After installing and running an initial scan I am no longer able to connect to the internet. So I have no way of getting the logs off of my infected computer. Any help is appriciated.

    Thanks
    Dan
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to go to the AVG virus vault and put the drivers back on your system. You can also copy the logs to a cd or thumb drive and then attach them from another computer.
    You can do the same thing for your nic card drivers. Download to another computer and transfer to the infected one.

    What site did your son go to?
     
  16. whited05

    whited05 Private E-2


    Tim, I'm in the process of doing that now, I will have the logs for you in about an hour.

    I believe that he went to bleepingcomputer.com
    But won't be sure untill he gets hoe from school. When I get a few minutes I will look for a thread over there.

    Dan
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds