YourPrivacygaurd related help needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by CssSnake6, Oct 19, 2007.

  1. CssSnake6

    CssSnake6 Private E-2

    Hi, My computer recently caught some Trojans and worms but thanks to Avast, I got past the worst part. anyways, My computer does not seem to be in any immediate danger, theres no Windows popping up or Extreme Overuse of the CPU by unseen malware. I think I particaly removed the Yourprivacygaurd.com thing, All thats happening is When I try to change my background (Which is currently white) I get this in a windows internet explorer Window:

    "Cannot Find 'file:///C:/WINDOWS/privacy_danger/index.htm'. Make shure the path or internet address is correct"

    I am actually quite worried that this may lead to a bigger problem though. And I already had to re-install windows on my computer literally 15 times in the past due to Viruses completely corrupting my system beyond repair, and cant use the windows cd's anymore.

    please let me know what I should do.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MG's!

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     
  3. CssSnake6

    CssSnake6 Private E-2

    Ok, I havent downloaded the zip file yet, but another problem has come up.

    every 5-10 min or so, Avast will Prompt me saying it found a trojan in the following files:

    C:\DOCUME~1\JASONB~1\LOCALS~1\Temp\ac8zt2\main_uninstaller.exe
    C:\DOCUME~1\JASONB~1\LOCALS~1\Temp\ac8zt2\msmdev.dll
    C:\DOCUME~1\JASONB~1\LOCALS~1\Temp\ac8zt2\nsduo.dll
    C:\DOCUME~1\JASONB~1\LOCALS~1\Temp\ac8zt2\rmv.exe

    I kept doing "move to chest" but Avast will prompt me about the exact same files I quarantined, AGAIN.

    once I do that, my computer seems to "Refresh" itself, and for a moment I can see the normal background, but then it go's white again and i get the First error message I posted.

    Whats going on? :confused
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete the instructions that BJ already gave you because those files are part of what the procedure is meant to fix.
     
  5. CssSnake6

    CssSnake6 Private E-2

    Everything looks fine, I am now able to change my background without getting the error message. I'm gonna wait to see if the problems with avast happen again.


    (8 min later)

    I'm still getting the problems with avast.
    same files, what now?
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The next step is to run our initial instructions and post the requested logs.

     
  7. CssSnake6

    CssSnake6 Private E-2

    In step 6A, it says to run the online virus scans, but the internet wont work in safe mode, should I just reboot in normal mode and do it then?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Step 6A also says
    So the answer is yes, run in normal boot mode.
     
  9. CssSnake6

    CssSnake6 Private E-2

    Ok, I have done all the scans over again, and my computer seems to be clean, And its running fine. The problems with avast and my background are gone.

    However, In the event that anything Should happen, I know where to find you guys.

    Thanks for the help, and god bless! :)
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I would recommend posting the requested logs so we can confirm you're clean. Just because you're not having obvious problems doesn't mean you're not infected.

    It's up to you but I would recommend it.
     
  11. CssSnake6

    CssSnake6 Private E-2

    Well, You're the Windows MVP here, so I'll do just that. I have all the logs except the one from Bitdefender (forgot to save it) and Panda never gave me a log or an option to save one.

    The BitDefender takes forever to scan my computer, so I'll post another reply with the logs ASAP.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay! If you can't get the online scan logs, just post what you have and we will go from there. If needed we can run alternate scans later.
     
  13. CssSnake6

    CssSnake6 Private E-2

    Attached Files:

  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please attach fresh logs from ShowNew, GetRunKey & HijackThis.
     
  15. CssSnake6

    CssSnake6 Private E-2

    Ok, here they are.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your copy of CounterSpy is the free trial from the READ & RUN ME, uninstall it now since we are finished with it now! Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\Jason Bloomer\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also locate the below file and delete it:
    C:\WINDOWS\hostctrl.dll


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_13
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME


    Make sure you reboot after uninstalling the above!

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    Make sure you tell me how things are working now!
     
  17. CssSnake6

    CssSnake6 Private E-2

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You probably just needed to empty your browser cache and then do a refresh. Then you would probably be able to attach the new logs.

    I still see CounterSpy install. Is this a paid version or the copy from the READ ME (looks like it is new to me)? If it is from the READ ME, you need to uninstall it unless you are going to buy it.

    ATF-Cleaner and CCleaner are not working properly for you. You need to manually delete all files in the below folder to cleanup a ton of old garbage:
    C:\Documents and Settings\Jason Bloomer\Local Settings\Temp\



    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  19. CssSnake6

    CssSnake6 Private E-2

    Ok, thanks for the help guys. PC is looking great again!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds