MS Antivirus/Porn ICONS on Desktop

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hendrix149, Sep 2, 2008.

  1. Hendrix149

    Hendrix149 Private E-2

    Hello MajorGeeks.com.

    I come to you in desperation.

    A couple days ago Antivirus XP 2008 Appeared on my computer.

    After several hours of complete torture I was able to remove it with SmitFraudFix.

    Everything was running fin for the next few days, until today.

    I logged on to my computer, and noticed a "PORN DVDs" Icon on my desktop (I do not look up porn and because I share this computer with my parents I do not believe they look up porn either), and along with this Icon I notice MS Antivirus alongside it. It had the same Icon as Antivirus XP 2008, so I put the computer into "SAFE MODE" and began the process of removing it with SmitFraudFix, but after the reboot it came back.

    I followed your tutorial in this thread,

    http://forums.majorgeeks.com/showthread.php?p=1206825

    But the results did not fall in my favor. With this post I am including the log from the avenger.exe program.

    I have Nod32 Antivirus, Malewarebytes, and SUPERAntiSpyware, but none of these seem to pick this particular Virus up.

    If you can offer any help on this subject, I would forever be thankful.

    Much thanks.

    **EDIT**

    If you need them, I will post the logs from SUPERAntiSpyware, Nod32, and Malewarebytes.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    FYI: You should never run fixes that were developed for another persons computer.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Hendrix149

    Hendrix149 Private E-2

    Ok, I have completed the READ & RUN ME FIRST Tutorial.

    I will include the logs from Malwarebytes, ComboFix, and MGTools in this post.

    When I ran SUPERAntiSpyware, it did not pick up anything, but when I ran SpyBot, it showed quite a few viruses.

    Also, if this helps, Nod32, my AntiVirus program keeps blocking certain files from a specific location. But after the scans, Nod32 has not been picking up anything.

    And none of the programs I ran deleted the Icons on my Desktop, but the icons are blank and contain no data, so should I go ahead and delete them?

    I also keep getting a Windows Security Alert that says,

    Do you want to block this software from sending you data over the internet?

    Name: Trojan-Spy.Win32.GreenScreen
    Risk Level: CRITICAL
    Description: This is a spy trojan that installs itself....etc.

    Grayed Out (Unable to click): Keep Blocking
    Grayed Out (Unable to Click): Unblock
    Highlighted (Able to click): Enable Protection

    I hope the information I provided helps solve this problem faster.

    Many thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the log anyway. Especially since it appears you have run this many times in the past and it has been removing things. I expect that since you do not have the correct version of MBAM installed (which means you did not update it as requested) that you may also not have the current version of SUPERAntiSpyware installed.

    You must update to the current versions of the programs. SAS does not update the program when you update. It only updates definitions. You need to install what we have given in the READ & RUN ME and run new scans and attach new logs from both SAS and MBAM.
     
  5. Hendrix149

    Hendrix149 Private E-2

    Actually I updated SUPERAntiSpyware, SpyBot, and Malwarebytes, mostly because it prompted me to when I opened them.

    And where might the logs for Spybot and SAS be found?


    **EDIT**

    Many apologies, I only updated Spybot apparently, although it did prompt me to update and I clicked Ok.

    I am currently scanning with SAS then MBAM will follow.

    I'll have the results soon.
     
    Last edited: Sep 3, 2008
  6. Hendrix149

    Hendrix149 Private E-2

    Updated everything.

    Tried the READ AND RUN ME one more time.

    It did not rid me of the virus.

    Downloaded Comodo Firewall and updated the virus signature on Nod32...in about 45 minutes or so the virus was wiped clean along with many other nuisances. Re-scanned today to check if the virus had come back, no sign of it yet.

    Thanks for your help MajorGeeks!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but it still would have been a good idea to have attached all the new logs to make sure you are clean. But it's your PC and your decision. If you feel all is good, then you still need to do the below.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds