vista anti-virus 2011 keeps popping up

Discussion in 'Malware Help (A Specialist Will Reply)' started by nzodiac35, Apr 1, 2011.

  1. nzodiac35

    nzodiac35 Private E-2

    hi there, basically my sisters computer, keeps restarting.kept popping up with vista anti-virus 2011 which i originally thought was real but have found out is some sort of virus. have followed steps mentioned on your forum to do with malware removal etc. i have attached the docs that you guys were asking for. unfortunately, when i run combofix.exe, blue screen appears and restarts the computer so i was not able to perform the scan.

    it has definitely improved by doing the other scans but im pretty sure there is still someting wrong, because when computer restarts, some applications like window defender just comes up application error. trying to search for something by clicking start and then typing one letter in search bar makes the computer pause for about a minute and then allow me to type in the rest of the word

    maybe you guys could find out the problem using the results u wanted, please help.

    thanks,
     

    Attached Files:

    Last edited: Apr 1, 2011
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Messenger Plus! Live -- Should have been done first!!

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. nzodiac35

    nzodiac35 Private E-2

    hi, thanks for the quick reply, i have managed to follow what you told me to do, one thing i wasnt sure is, using ccleaner, i checked temporary files under internet explorer and system and performed the scan.

    when i restarted the computer, i stil get a window saying application error (i think it is referring to windows defender). also get another window with host process problems.

    i have attached the logs. thank you
     

    Attached Files:

    Last edited by a moderator: Apr 5, 2011
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to pursue those issues in the software forum. As it is, your logs are clean. Are you having any malware issues still?
     
  5. nzodiac35

    nzodiac35 Private E-2

    thank you very much, the malware issues seem to have gone. do i turn the UAC back on?? and regarding the problem with the windows defender application error, do i forward my messages from this section to the software?? thanks
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these files using windows explorer.
    • C:\Users\Nithy\AppData\Roaming\GetValue.vbs
    • C:\Users\Nithy\AppData\Roaming\SetValue.bat

    Unless you really like it I would suggest uninstalling this rubbish.
    • SweetIM for Messenger 3.0
    • SweetIM Toolbar for Internet Explorer 3.6

    Java(TM) 6 Update 23 <--- Outdated, uninstall.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let TimW know of any problems you may have encountered with the above instructions and also let him know how things are running now!
     
  7. nzodiac35

    nzodiac35 Private E-2

    just after i had posted the previous message, i realised that some of the links that were being directed from a google search was not the actual site of the link i clicked on, it was directing me to other random websites.

    i have now performed the tasks as you mentioned and have attached the docs you need to look at.

    whilst doing the MGtools scan, a window popped up saying "a tool to aid in developing services for windowsNT has stopped working" i clicked on close program which was the only option and the scan carried on in command prompt like window.

    thanks
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  9. nzodiac35

    nzodiac35 Private E-2

    the message that appeared was Done, press enter to exit on the black screen, i have attached the log. thanks
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MBR is now correct. What malware issues are you still having?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds