Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Help EvilFantasy please(sorta)  (Read 7263 times)

0 Members and 3 Guests are viewing this topic.

Google

    Topic Starter


    Mentor

    Thanked: 2
    • Certifications: List
    • Experience: Experienced
    • OS: Windows 7
    Help EvilFantasy please(sorta)
    « on: July 30, 2008, 07:06:03 PM »
    My friend has now had a virus on his computer for two days called Windows anti-virus 2009. I am going to try fix it myself with this guide:
    http://www.bleepingcomputer.com/malware-removal/remove-xp-antivirus-2008-2009

    But i might need some assistance. Would this guide help me do you think?

    Google

      Topic Starter


      Mentor

      Thanked: 2
      • Certifications: List
      • Experience: Experienced
      • OS: Windows 7
      Re: Help EvilFantasy please(sorta)
      « Reply #1 on: July 30, 2008, 07:08:44 PM »
      Just posting this for my self:
      Malwarebytes' Anti-Malware (MBAM)

      Download Malwarebytes Anti-Malware and save it to your desktop. Alternate download link (.exe)

          * Double-click mbam-setup.exe and follow the prompts to install the program.
          * Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
          * If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
          * If an update is found, it will download and install the latest version.
          * Once the program has loaded, select Perform Quick Scan, then click Scan.
          * When the scan is complete, click OK, then Show Results to view the results.
          * Be sure that everything is checked, and click Remove Selected.
          * When completed, a log will open in Notepad. Save it to a convenient location like the Desktop.
          * The log is also automatically saved and can be viewed later by clicking the Logs tab in MBAM.
          * Copy and Paste the contents of the report in your reply.
          * Exit MBAM.

      .
      Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

      HijackThis

      Please run HijackThis only after the above steps have been completed

      Download and rename HijackThis.exe (HJT)

      * Double-click on HJTInstall.
      * Click on the Install button.
      * It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
      * Upon install, HijackThis should open for you.

          * Close HijackThis and rename it.
          * Go to C:\Program Files\Trend Micro\HijackThis.exe
          * Right click on HijackThis.exe and select Rename.
          * Type in sniper.exe and press Enter.
          * Right-click on sniper.exe and select Send To > Desktop (create shortcut)

      .
      * From the desktop open HijackThis.
      * If using Windows Vista, Right-click and Run As Administrator.
      * Click on the Do a system scan and save a log file button
      * HijackThis will scan and then a log will open in notepad.

          * Copy and Paste the entire contents of the log in your post.
            .
            Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.

      .
      Although we have renamed HijackThis to sniper, we will still refer to it as HijackThis or HJT.

      Some more self-serve links:
      http://www.free-av.com/
      http://www.personalfirewall.comodo.com/
      « Last Edit: July 30, 2008, 08:10:42 PM by Mr. Google »

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Help EvilFantasy please(sorta)
      « Reply #2 on: July 30, 2008, 07:15:23 PM »
      Why don't you just post the MBAM log here and then post a HijackThis log. There are often times other bits of malware that need to be taken care of in addition to what is readily seen.

      Fed

      • Moderator


      • Sage
      • Thanked: 35
        • Experience: Experienced
        • OS: Windows XP
        Re: Help EvilFantasy please(sorta)
        « Reply #3 on: July 30, 2008, 07:18:07 PM »
        Self-Service Dept in full swing. :D

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Help EvilFantasy please(sorta)
        « Reply #4 on: July 30, 2008, 07:23:34 PM »
        Self-Service Dept in full swing. :D


        Google

          Topic Starter


          Mentor

          Thanked: 2
          • Certifications: List
          • Experience: Experienced
          • OS: Windows 7
          Re: Help EvilFantasy please(sorta)
          « Reply #5 on: July 30, 2008, 07:38:57 PM »
          Self-Service Dept in full swing. :D

          Lol, sure EF, I will do that tomorrow when I get the PC.

          Thanks ;) ;)

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Help EvilFantasy please(sorta)
          « Reply #6 on: July 30, 2008, 07:54:25 PM »
          MBAM just updated to a new version (1.24) so be sure to update and run a new scan.

          Google

            Topic Starter


            Mentor

            Thanked: 2
            • Certifications: List
            • Experience: Experienced
            • OS: Windows 7
            Re: Help EvilFantasy please(sorta)
            « Reply #7 on: July 30, 2008, 08:08:24 PM »
            Alrighty-O, thanks for the tip ;D

            Google

              Topic Starter


              Mentor

              Thanked: 2
              • Certifications: List
              • Experience: Experienced
              • OS: Windows 7
              Re: Help EvilFantasy please(sorta)
              « Reply #8 on: July 30, 2008, 08:13:41 PM »
              Um..Is it really necessary to have comodo firewall installed on my friends computer if I install avira anti-vir. Because He is VERY bad with computers. He has NO IDEA what to do or how to use it- and alot of alerts and requests show up with comodo. Which is good for me, but not for him...

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Help EvilFantasy please(sorta)
              « Reply #9 on: July 30, 2008, 08:17:50 PM »
              If he doesn't do anything like eBay, pay-pal or online banking then it would be OK.

              Google

                Topic Starter


                Mentor

                Thanked: 2
                • Certifications: List
                • Experience: Experienced
                • OS: Windows 7
                Re: Help EvilFantasy please(sorta)
                « Reply #10 on: July 30, 2008, 08:26:00 PM »
                If he doesn't do anything like eBay, pay-pal or online banking then it would be OK.

                He's too dumb to even know what that is so yea...

                Google

                  Topic Starter


                  Mentor

                  Thanked: 2
                  • Certifications: List
                  • Experience: Experienced
                  • OS: Windows 7
                  Re: Help EvilFantasy please(sorta)
                  « Reply #11 on: July 31, 2008, 08:45:08 AM »
                  Ahh, geez, he actually does sometimes buy stuff online....I didn't even know. And I think that he has shaw AV. Is that any good? Should I uninstall it and install avira instead?? And also, can they use threatfire as a firewall?? And not have comodo? Or would it be better to have both? BTW. Does training mode on comodo help show less messages??

                  Google

                    Topic Starter


                    Mentor

                    Thanked: 2
                    • Certifications: List
                    • Experience: Experienced
                    • OS: Windows 7
                    Re: Help EvilFantasy please(sorta)
                    « Reply #12 on: July 31, 2008, 11:21:03 AM »
                    Ok, I have completed mbam scan and HJT here are the logs. Please help as soon as possible, because I don't have much time (wrk).

                    [recovering disk space -- attachment deleted by admin]

                    Google

                      Topic Starter


                      Mentor

                      Thanked: 2
                      • Certifications: List
                      • Experience: Experienced
                      • OS: Windows 7
                      Re: Help EvilFantasy please(sorta)
                      « Reply #13 on: July 31, 2008, 11:21:53 AM »
                      I'm guessing to remove these but I need to be sure:
                      Code: [Select]
                      O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-dcf7-f96da086b434} - (no file)
                      O2 - BHO: (no name) - {6C6B8C69-9285-4D94-8492-9E920C8C2B65} - (no file)
                      O2 - BHO: (no name) - {74f25a2c-22b3-4023-8f1a-ca616c30a8b5} - (no file)
                      O2 - BHO: (no name) - {9a19966f-ae0e-4699-8cce-9b6f5f1c352c} - (no file)
                      O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - (no file)
                      O4 - HKLM\..\Run: [System] C:\WINDOWS\krln32.exe
                      O4 - HKLM\..\Run: [Windows Framework] C:\WINDOWS\system32\scvh0st.exe
                      O4 - HKLM\..\Run: [mmnext06] C:\Program Files\Common Files\trjdwnl.dll
                      O4 - HKLM\..\Run: [shellbn] C:\WINDOWS\shlext32.exe
                      O4 - HKCU\..\Run: [XP Antivirus] C:\Program Files\XPAntivirus\XPAntivirus.exe
                      O4 - HKCU\..\Run: [10181281926292389167514053783761] C:\Program Files\XP Antivirus\xpa.exe

                      Google

                        Topic Starter


                        Mentor

                        Thanked: 2
                        • Certifications: List
                        • Experience: Experienced
                        • OS: Windows 7
                        Re: Help EvilFantasy please(sorta)
                        « Reply #14 on: July 31, 2008, 11:29:30 AM »
                        Ok, I'm going to remove them because I need to hurry...