Big Fat Red Screen - Windows Security Alert

Discussion in 'Malware Help (A Specialist Will Reply)' started by luciano991, Aug 29, 2007.

  1. luciano991

    luciano991 Private E-2

    I've got Windows Security Alerts and a big fat red screen background that renders my desktop unusable because it's a giant link to trouble. I have followed your instructions and the fat red screen is gone and my desktop is partially back but my pest patrol alert comes up and it's blocking something. So I'm still infected and i'm posting my logs as requested. Thanks in advance for your assistance. I checked the other posts but they seemed to be specific to someone else's particular brand of misery.

    All the best,

    Luciano
     

    Attached Files:

  2. luciano991

    luciano991 Private E-2

    Here are the remaining logs

    Luciano
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the other required logs (GetRunKey, ShowNew and CounterSpy) however before attaching them, do the below:

    Uninstall any Viewpoint software (like Viewpoint Manager) as requested in step 0 of the READ ME.

    Then continue on with the below.


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.


    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    Also don't forget to attach to attach the log from CounterSpy if you have it.

    How are things working now?
     
  4. luciano991

    luciano991 Private E-2

    Hi,

    First, I'm sorry I didn't indicate that the other logs were posted in a second post. Secondly, I don't seem to be able to access a log from Counterspy in the Safe Mode so I will try when I reboot into real mode. Here is the first of two Smitfraud logs. I will post the second Smitfraud log and GetRunKey and Shownew logs in a second post. I will include the Counterspy log and HJT in a third post. Sorry for all the posts but I seem to be restricted to three attachements per post.

    Thanks,

    Mark
     
  5. luciano991

    luciano991 Private E-2

    Hi,

    Here is second Smitfraud log and GetRunKey and Shownew.

    Things working much better now. More to come.

    Mark
     

    Attached Files:

  6. luciano991

    luciano991 Private E-2

    Hi,

    Here are the last two logs.

    Mark
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks better. Just a couple other things to do and then on to my final instructions.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\Chip\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Also I recommend that you run this Disable/Remove Windows Messenger to remove Windows Messenger which can be a frequent source of popups. Don't confuse Windows Messenger with MSN Messenger. They are not the samething.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  8. luciano991

    luciano991 Private E-2

    Much belatedly I am writing to thank you for help with this problem. Everything is working great now. FYI, I eventually had to go to each profile as some profiles were not completely clean. I ran the Smitfraud cleaner on each profile and that was it. Man that is some incredible removal tool.

    All the best,

    Luciano
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.

    If you like it, you can show your appreciation to the creator by making a purely voluntary donation at:

    http://siri.urz.free.fr/Fix/SmitfraudFix_En.php#donation
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds