Critical System Error - windows notice

Discussion in 'Malware Help (A Specialist Will Reply)' started by bsheet2, Dec 22, 2007.

  1. bsheet2

    bsheet2 Private E-2

    It appears we have some sort of add type virus or something. Have installed and run all items indcated by the "run before posting" thread.

    Here is what is happening.

    When using Windows Internet Explorer 7 and sometimes (not always) when opening the Windows Control Pannel we get he following nessage that looks like a Windows message:

    Critical System Error

    It is dangerous for your computer, sone files can be lost!
    Click ok to download antispyware program to clean your system.

    I have not downloaded this. But the download points to a file called setup1.exe 2.85 nb from files-secure.com

    I suspect this is a sales scam. I have not been able to stop the annoying message. Any ideas??

    Attached are logs.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please install:
    Java Runtime 6

    Then disable the guest account.

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Use windows explorer to delete all that is here:
    C:\WINDOWS\oggview.dll
    C:\Documents and Settings\Winnie\Local Settings\Temp\ ---> all!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. bsheet2

    bsheet2 Private E-2

    Thanks for trying to help.

    FYI, the visitor account was already turned to off.

    There was not a file >>> C:\WINDOWS\oggview.dll or loggview.dll

    All other items done. New log attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean ....but the "Guest" User account is still not disabled ...
    Users on this computer:
    Is Admin? | Username
    ------------------
    Yes | Administrator
    | Guest ---> this is a security loophole.
    | HelpAssistant (Disabled)
    | SUPPORT_388945a0 (Disabled)
    Yes | Winnie

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  5. bsheet2

    bsheet2 Private E-2

    The problem seems to be gone. Thanks!

    I will work through your final steps below in the morning. I guess I also need to figgure out how to turn the guest account off. From contol pannel I go in to user accounts and it shows it is turned to "off" and asks if I want to turnit on.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then that should be ok ...as long as it is off ( though you might check in safe mode). :)
     
  7. bsheet2

    bsheet2 Private E-2

    You guys are great.

    Geeks Rule!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds