XP Anti-Spyware 2001 (HELP!!)

Discussion in 'Malware Help (A Specialist Will Reply)' started by phlebs83, Apr 2, 2011.

  1. phlebs83

    phlebs83 Private E-2

    Well, this is on my computer and can not remove it...
    I can not open anything either in normal running mode or safe mode, can not make any changes, download anything.....
    XP Spyware just keeps popping up.....
    Can not get to Restore System, Reg Keys...even tried under safe mode along with admin and nothing.....
    I have tried looking for system restore to turn it back on because this virus as turned it off and can not fins that to do so....
    If anyone has any suggestions to help me out that would be GREAT!!!

    Thanks in advance!!!

    Staci
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.



    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools



    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    NOTE:
    1. If you have problems downloading on the problem PC, download the tools and the manual updates for Malwarebytes onto another PC and then burn to a CD. Then copy them to the problem PC. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. phlebs83

    phlebs83 Private E-2

    I have tried to run the first set of Rkill and could not get any of them to run.
    I did run the as "Run as Administator" and still nothing.
    I also tried it in safe mode under Administrator......
    I saved them to my desktop under Safe Mode Admin, I think I have to remove them before I can run them in reg mode under admin, correct?
    I am sorry to be a pain but this is a huge PITA!!! LOL
    Thanlks, Staci
     
  4. phlebs83

    phlebs83 Private E-2

    ok got them to run I hope I attached them right....

    Staci
     

    Attached Files:

  5. phlebs83

    phlebs83 Private E-2

    Here is the one I forgot, hope this is right! Thanks so much!
     

    Attached Files:

  6. phlebs83

    phlebs83 Private E-2

    This came up after I selected fix problems....
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you get this PC so badly infected???? Is it because you have been running with no protection which is what it looks like?

    You have dozens of malware items trapped in MSconfig registry keys too and you were asked to not use MSconfig in the READ & RUN ME. I will ask you to disable this later.

    Since so much was found by Malwarebytes, I suggest that you run it again and first update it again and then run another scan. Fix anything it finds and attach the new log.

    Also continue with the below instructions.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    Uninstall the below old versions of software:
    Java(TM) 6 Update 20

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Mom58\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. phlebs83

    phlebs83 Private E-2

    Thank you for all the information!! I will work on it and let you know wha happens, but I know coming here was the right place...You guys are awesome at what you do!!!!

    Thanks, Staci

    :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just attach the followup logs when you finish.
     
  10. phlebs83

    phlebs83 Private E-2

    Ok here we are:


    I hope I did this right!
    thanks again and let me know how I did!

    Staci
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like you did not paste in the info properly to Avenger thus you did not fix anything. The first line of what you paste into Avenger must be the Files to delete: line. Make sure that you did not also copy in the Quote: line which is just the vBulletin heading for a Quote box. It is not part of the Avenger fix.


    Please run the complete fix again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds