Blue screen, warning! spyware has been detected on your computer!

Discussion in 'Malware Help (A Specialist Will Reply)' started by jab2424, Jun 24, 2008.

  1. jab2424

    jab2424 Private E-2

    Hey,
    I have had the same problem it seems that many others have had. My desktop was changed to the blue screen with Warning! Syware has been detected on your computer! etc etc...i'm not sure exactly what it is inhibiting, but it's not good. every so often the wholething will go to a blue screen with white typeface that says a problem has been detected and windows has been shut down to prevent any damage to your computer. then under that it says something like BOGUS_DRIVER or PANIC-STACK_SWITCH and then gives you directions to restart in safe mode etc and gives you technical info and an address like smwdm.sys. i hope that makes sense to someone, because it doesnt to me. i go and search for that smwdm.sys and itll be in the system32 folder last updated in 2004 or something which confuses me. i know that i cant connect to a secured wireless network, which i guess is a good thing. So i have been running the RUN AND READ ME but i have had to save all the different programs onto a thumb drive and then download them from one laptop to mine. but i ran into a problem with spybot. i saved it to the thumb drive and then tried to download it onto my laptop from the thumb drive and it requires me to connect to the internet i think to download it. obviously i cant since i have spyware, so what do i do? and where do i save the MGtools because it confused me as to how to do that when i get it off a thumb drive. Then after that i just need to know what's next. Any help would be greatly appreciated!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Spybot updates can be performed manually by using the below, but you can just skip Spybot.

    Spybot Search and Destroy Update

    MGtools.exe should be saved to the root folder of the drive that boots up Windows. Normally this would be C:\MGtools.exe.

    What you need to do is get us the below logs if you were able to run all of these. Note the more you are able to run and the more logs you get us the better.

    • SUPERAntispyware log
    • Malwarebytes log
    • ComboFix log ( this is c:\combofix.txt )
    • MGtools log ( this is C:\MGlogs.zip)
     
  3. jab2424

    jab2424 Private E-2

    Okay I was about to run the other tests and this new thing came up--Malware Protector 2008--and it looks fishy and on other sites people have given directions to fix it but i cant access the internet from that computer...which program should i run that will get rid of it?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run all of the steps in the READ & RUN ME. The first two scans with SUPERAntispyware and Malwarebytes will help alot. If necessary, download the tools onto another PC and copy them to a CD or flashdrive. And then use this to copy to the problem PC.
     
  5. jab2424

    jab2424 Private E-2

    okay so now im having trouble with combofix. i have it saved on a flash drive and copied it into the desktop. then i renamed it and put the exact thing i was supposed to in the Run entry and it says it cant be found. so i tried just clicking on the combofix desktop shortcut and that said stuff like only 1/100 computers make it through this process are you sure you want to do this. any advice?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just let it run!
     
  7. jab2424

    jab2424 Private E-2

    here are the first three. i'm now able to change the screensaver and desktop via the control panel display settings.
     

    Attached Files:

  8. jab2424

    jab2424 Private E-2

    and here are the MG logs. sorry this took a while, it's a long process!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What did you do to your AVG8 antivirus program? It does not seem to be installed/running properly. There are multiple service/processes that are not loading. Did you disable or not allow certain features to be installed?

    We have a little more to do. Include will be instructions to remove some left overs from TrendMicro.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
    O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
    O4 - HKLM\..\Run: [SMshc5vtj0epa1] C:\Program Files\shc5vtj0epa1\shc5vtj0epa1.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -

    After clicking Fix, exit HJT.

    Now reboot and after reboot, delete the below folders if found:
    C:\Program Files\Trend Micro\Antivirus
    C:\Program Files\shc5vtj0epa1


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. jab2424

    jab2424 Private E-2

    i had AVG7.5 before, the antivirus, spyware, and root. i asked my cousin what to do for this but he's thousands of miles away so he said the only thing he could do was advise me to save an AVG update onto a thumb drive from one laptop and download it onto my laptop. and then it couldn't download properly on mine, and i had no idea why or what i did wrong. When you say exit all browser settings, how do i do that? i found on internet explorer where i can manage add ons like the toolbars and disable them, but i'm not sure if that's what you mean.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read it again. I said sessions not settings. ;) Thus that means close all of your browser windows.
     
  12. jab2424

    jab2424 Private E-2

    here are the logs. everything seems to be running good. i still cant connect to two secured wireless networks. i can connect to unsecured ones but when i try to on these two secured ones (and i assume any secured one if i tried) then it says network may be out of range, refresh page etc. except it's not out of range i still have four or five bars. what should i do about AVG now? and should i put back up all the firewalls and everything now? Sorry, it's obvious I don't know much about computers. You've been an immense help thank you vey much.
     

    Attached Files:

  13. jab2424

    jab2424 Private E-2

    it wont let me attach the combofix log...it says i already attached it to this thread
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you need to enter WEP keys. other security info or reinstall drivers. You may be better off trying to work this in the Networking Forum.

    Sorry about the combofix request. I was supposed to remove that when I asked you to delete the folders manually.

    Your logs are clean now.

    For AVG, I suggest that you do the below in the order written:
    • download AVG Free Edition so you have the installation file
    • uninstall your current copy of AVG8
    • reboot your PC
    • use the file that you just downloaded to reinstall AVG8
    • be sure to update it after installation.
    Then if you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds