Help Please! e-card exe resulted in WinXP not activated

Discussion in 'Malware Help (A Specialist Will Reply)' started by kskovach, Aug 19, 2008.

  1. kskovach

    kskovach Private E-2

    Hi - First awesome site! Next - I'm stupid - opened an email that was an e-card that said to go to emilimport.com/e-card.exe - I double clicked on the link and got the blue screen of death. I had saved the file and ran McAffee scan on the file prior but it didn't warn me of anything. Anyway - had to reboot and upon entering my account - McAffee was disabled, no internet (wireless router), but I fixed all that. Problem: When I boot or enter into a WinXP (SP2) account, I now get screens/windows popping up that say things like - "Since Windows was installed on this computer, the hardware has changed. Due to these changes, windows must be reactivated within 3 days. Do you want to reactivate it now?" with Y/N buttons. Also, there is a blue 5 pointed star in my system that says "This copy of windows is not activated" when you mouse over it. Occasionally a pop up near the system tray reminds me that my copy of Windows is not validated and will expire in three days. It also says to ask for "Genuine Microsoft software"
    What I did - ran MacAfee full scan - no joy
    - googled it but couldn't find a specific fix
    - found your site and ran the malware programs (Spybot, Malwarebytes, Combo-fix, Super-anti spyware (all of them)- still there - only one program found 4 small malware issues (thanks though). I will send the logs ... spybot didn't find anything - so only 3 log files
    Question - Is this nuisance or will it freeze Windows.
    Question - Should I attempt to "validate" my Windows version as requested? (I don't want to)
    What next?
    Thanks for the awesome site and useful guides/software etc. I tried searching and looking before I posted but no one seems to have this one ...
    Pretty dumb I know ... clicking on an exe ... sooo HELP!
    Thanks in advance -
    Kelly
    -
     

    Attached Files:

    Last edited by a moderator: Aug 20, 2008
  2. kskovach

    kskovach Private E-2

    Morning ... one more thing ... I couldn't get McAffee to stop or disable it while I ran the scans. Not sure how to. Right clicking provides no "exit". All of the reboots / scans were completed in normal mode (as opposed to safe mode). The computer seems to be running normally except for the reminders to validate or re-activate Windows within 3 days. I get a grey box message as Windows starts and then system tray icons and windows that slide up out of the system tray every so often. After rebooting after each scan its still there.
    Again - thanks in advance - I hope I have provided enough info and run the scans correctly.
    Kelly
     
  3. kskovach

    kskovach Private E-2

    Hi again - not sure now if I have posted this to the right forum? I have re-run all the fix programs again and will attach them. I am still getting the "Windows is not activated" screens at startup of windows and then it installs in my system tray. It now says 2 days left to activate vs. yesterday's 3.
    I clicked on the "do you want to activate now screen" and it takes you to what appears to be Microsoft's website. There it wants you to download an executable and run it!! (I didn't)
    Yesterday when this happened - I tried to restore to a system restore point for the day before - it said it was successful but the (windows not activated) screens/reminders continue.
    I know you guys are busy but I don't know where else to turn. Haven't received any replies.
    Am I in the right forum?
    The scans tonight revealed nothing ...
    I guess I will start backing up my docs/drives for a re-install?
    By the way - and I hope it goes without saying - I have a full licensed copy of WinXP Pro ... problem is that it doesn't seem to run right (its so old/scratched). I have considered just putting the numbers in to validate but I'm afraid the exe the site wants you to download will further trash my system. By the way - little is wrong from all appearances - when it happened it blue screened, gave the Windows has recovered from a serious error screen and McAfee showed disabled but appears to be good now (have updated and run full scans). The "thing" also screwed up my home network but its working again now ... so I don't know what happened - The only "presence" is the screens warning me I only have 2 days to validate my windows, etc. Not sure what happens then ...
    Anyway, I certainly don't mean to offend and am very aware that I am asking for your assistance and your time. I just haven't received any replies and am concerned I'm not in the right place or the post hasn't been seen or I don't know what.
    Will attach the latest scan reports.
    All the best.
    Kelly
     

    Attached Files:

  4. kskovach

    kskovach Private E-2

    Here is the last log requested. Please take a look ... I'm really scratching my head ... Thanks, Kelly
     

    Attached Files:

  5. kskovach

    kskovach Private E-2

    Fixed it myself.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are happy to hear you got your problem fixed. It was not a malware issue.

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. kskovach

    kskovach Private E-2

    Copy all. I beg to differ on the malware issue - it came into my computer as an invasion from an email sent by an unknown person. Perhaps it was not a malware issue as per your definition but some reply to my pleas would have been greatly reassuring and helpful. The lack of response was disappointing and as my thread shows, left me wondering if in fact I was posting in the wrong thread, etc. Not sure why as I its hard to conceive that I was the only victim of this "prank" or malware intrusion.
    All the best and thanks for the cleanup advice.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are two people providing free support in this forum and there are hundreds of new requests for help each week. We cannot answer all posts in zero time. In one single day, a new post will go from the top of page 1 to the bottom of page 5. It does not mean we are not working on the threads. We are! And we do it according to what is stated in the sticky thread:

    Don't Bump! It Only Hurts You!!!

    It does not matter whether it is an intentional bump or not. The result is the same. Each time you posted, you cost youself more delay. It was your fault for not reading the other sticky threads and for continuing to post.

    You just need to have patience until we can get to you. In many forums, it takes weeks to get answers. And some forums just don't answer many of the threads at all. In ours we answer all threads and it was normally less than 1 day (sometimes only 4 to 5 hrs); however now with many free forums closing and the fact that a massive amount of new malware has come out in the last few months, well we just cannot answer everything that quickly since we are about 10 times busier than ever.

    Due to the epidemic in malware being out of control and a losing battle, some forums are just not doing this anymore. There are hundreds of millions of PCs getting infected and there are relatively few people like us fixing them. Do you really think that free support that takes only a day or two to get a response is bad?
     
  9. kskovach

    kskovach Private E-2

    Chaslang
    Successful message on the regedit fix. Thanks.
    Copy your remarks re bumping - it was unintended - frankly, I thought bumping was from forum to forum ...
    In summary, I am / was / will be grateful to you, this site and others like it. I am more than aware that it is free and noticed that during my time of crisis, it was your birthday.
    I have already learned a lot from the site - whether you fixed my particular problem or whether it was within the definition of "malware" or not - notwithstanding.

    What did I do to fix my problem? Kept searching the net looking for similar problems - found a number of sites reporting (circa 2006) a similar but not exact match for the "windows not validated" scam distributed via e-card executables. Many fixes on that including symantec for the "trojan". That scam invalidated Windows and asked for credit card info to re-instate it.
    Mine was more innocent (despite the blue screen crash, disabling of my home network, and screwing up of McAffee - that was pretty scary as I know just enough to be scared). I ran all your read me fixes and was realizing that it wasn't permanent/critical.
    Bottom line - I found a chat site where folks were directed to magicjellybean.com that provided my (valid) key for WinXP and MSOffice - not sure but I think it simply searched my computer for the key (as the key produced matched my installation disk).
    I then went to the official Microsoft site and requested a "validation", typed in the Key fields and it was validated or revalidated and the screens, etc. wentaway and I think I'm "fixed". (Hard for a non-expert to really know). I humbly submit this might be worth a "sticky" once suitably edited - In fact it may save you and the other helpers a bunch of time. So, I agree that it wasn't malware per se. But it really did throw me for a big loop.
    As I have said throughout - thank you for your time, site and expertise, "stickies" and its free.
    Cheers
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! If you post in multiple forums or websites, that is called spamming. ;)

    Windows validation issues are always handled in our Software Forum because it is a software issue. There are many cases where the residual effects from malware could have an impact on something within the Windows Operating System. Once we have removed all malware traces, we send people with remaining problems to the appropriate other forums like Software, Hardware, Networking...etc.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds