Plzz Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Garbageman, Aug 16, 2008.

  1. Garbageman

    Garbageman Private E-2

    Some how I have been infected with Antivirus xp 2008. I have the blue screen that reads "Warning spyware has been detected on your computer Install an antivirus or spyware remover to clean your computer" I also have an icon on my desktop for "Antivirus xp 2008" and also 2 things in my start menu one that says "Antivirus xp 2008" and one that says "register Antivirus xp 2008" I tried reading the other post but computers are so different I deceided to post mine I have done the "read me and run me" now what? I'm so lost...............
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What you do now is to attach the requested logs:

    SuperAntispyware
    MalwareBytes
    ComboFix
    MGLogs.zip --> from running the MGTools
     
  3. Garbageman

    Garbageman Private E-2

    Here are the logs you asked for I hope I am doing this correctly.
     

    Attached Files:

  4. Garbageman

    Garbageman Private E-2

    I could only do 3 so here is the last file.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did fine....and the scans took care of most of it, so let's do this:

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    If you haven't already, please disable the Guest account in User accounts.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\PROGRAM FILES\RHC1DRJ0E797

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Tell me how things are running.
     
  6. Garbageman

    Garbageman Private E-2

    Okay First after the scans the blue screen is gone thank you in start menu I still have the 2 that says "Antivirus xp 2008" and also "Register Antivirus xp 2008" but the Icons look like the computer does not reconize them if that makes any sense. Second I removed Windows messenger and went to open McAfee security center to disable and it wouldnt open so I assumed it to be disabled so I continued with your instructions. Ran MGtools\analyse.exe but there was no "O2 - BHO: (no name) - {55CA5F1E-FBAD-4DDF-A4FF-28C7335D263B} - (no file)" Only thing similar was this "02-BHO:(no name)-{89FD14D-132B-48FC-8861-0048AE113215}-C:\Programfiles\siteadvisor\6261\Siteadv.dll" I did NOT check this also could not find
    O20 - Winlogon Notify: cbxwxxy - cbxwxxy.dll (file missing)
    O20 - Winlogon Notify: gebyy - C:\WINDOWS\system32\gebyy.dll (file missing)
    then after exit of all brower sessions I clicked fix.. also could not find C:\program files\RHC1DRJOE797 and C:\doc settings\username\local setting\temp to delete. in the c windows temp folder could not delete files said error could not delete being used by another person or prgram.Total of 7 as follows"""fb_1856.lck ; mcafee_4tfdeUUaOEktOH6 ; mcmsc_mOfih5jmNPdF2kt ; Perflib_perfdata_27c.dat ; sqlite_cfeyqk2sREXm7rl ; sqlite_iOx7qnhtsNj8b3W ; sqlite_nOEJQZXRktzRTRB """ God I hope I'm doing all this right for you and not being a pain. THANK YOU THANK YOU so much for helping me also attached is the MGlogs zip u wanted. GOD I hope I sent you the right zip file.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good...."in start menu I still have the 2 that says "Antivirus xp 2008" and also "Register Antivirus xp 2008" -- right click and delete.

    Please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5"
    Java(TM) 6 Update 7

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot and install:
    Java Runtime 6

    Tell me how things are running before we do our final cleanup.
     
  8. Garbageman

    Garbageman Private E-2

    Looks good...."in start menu I still have the 2 that says "Antivirus xp 2008" and also "Register Antivirus xp 2008" -- right click and delete......would not delete just remove so thats what I did.
    before I created the next fixme.reg file I took the old fixme.reg file you had me create and moved it to a special folder I created just for this problem called logs so I would have any problems finding the new one Hope that was okay. also I think I might had ended up mergeing the new fixme.reg file twice..oops. I did what u told me to do with java. Everything seems to be fine I can even open my McAfee security center now.
    Please disable the Guest account in User accounts.......says it is already off.
    So I think I can say I am ready for final clean up......THANK YOU THANK YOU for your patience with me and helping me thus far:-D
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet.......If you are not having any other malware problems, it is time to do our final steps:
     
  10. Garbageman

    Garbageman Private E-2

    Okay eveything went great but now to be just one more pain...I still have 2 icons left on desktop 1 that says mb that looks like a computer a disk and a box and the other says windows xp with a box with a window behind it do I delete both of them?????
    God I can not tell you enough how thankful I am to have you help me..and having the patience with me...Do you Have an0 emplorer or anyone I can message to let him or her know the great job you did for me.
    :wave
    :guitar
    :celebrate
    :dood
    :dancer
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can right click both icons and click properties and see what they are / when they were created, etc. Or just right click and delete them ...

    You are most welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds