Computer Hope

Software => Computer viruses and spyware => Topic started by: zoe on April 29, 2008, 05:37:15 AM

Title: system error dangerous virus message
Post by: zoe on April 29, 2008, 05:37:15 AM
A "system error dangerous virus message" keeps popping up every few seconds.  I'm sure it is some type of virus.  It asks if I want to install anti-spyware.  I continue to answer "Cancel."  Does anyone know how to get rid of this annoying message? :'(
Title: Re: system error dangerous virus message
Post by: street1 (RIP) on April 29, 2008, 05:47:50 AM
Go to the below 2 links download and use both programs.They
are free. AVG is really great freeware software.

http://majorgeeks.com/download886.html

http://www.majorgeeks.com/AVG_Anti-Spyware_d5287.html
Title: Re: system error dangerous virus message
Post by: zoe on April 29, 2008, 09:54:40 AM
I downloaded and ran both programs but neither picked up a virus.  I also had installed Norton 360, but it did not find one either.  I don't understand why these programs can miss it.  Any suggestions would be greatly appreciated.
Title: Re: system error dangerous virus message
Post by: Dias de verano on April 29, 2008, 10:42:32 AM
The answer is that you have probably picked some malware which is an "anti-spyware" scam. It warns you that you have a "dangerous virus" when you actually do not have one, so that you are induced to install their fake software which will pop up warnings, probably for "viruses" that need their paid-for version! Or else your PC will become full of adware.
Title: Re: system error dangerous virus message
Post by: Spoiler on April 29, 2008, 11:10:53 AM
Take a look though this....it will help you get started with a fix....

http://www.computerhope.com/forum/index.php/topic,46313.0.html

Title: Re: system error dangerous virus message
Post by: patio on April 29, 2008, 02:17:55 PM
You're infected....i'm moving this to the appropiate Forum.
Follow the instructions posted and post back with the logs....
Title: Re: system error dangerous virus message
Post by: zoe on April 29, 2008, 09:01:27 PM
 :-*
Thank you so very much!  I followed the instructions and when I did the scan with Malwarebytes' Anti-Malware, the trojan virus was found!  I can't thank you enough for your help!  You guys are truly heros in a land of creeps who launch nasty viruses!   :-*
Title: Re: system error dangerous virus message
Post by: Broni on April 29, 2008, 09:33:59 PM
That's not all.
You need to post all three logs for us to see, IF your computer is clean.
Title: Re: system error dangerous virus message
Post by: zoe on April 30, 2008, 12:57:29 PM
Here are the 3 logs that you requested.  I deleted the trojan virus from the malware scan which fixed my pop-up message problem.  Thanks again for all your help.   :)

[recovering space - attachment deleted by admin]
Title: Re: system error dangerous virus message
Post by: evilfantasy on April 30, 2008, 03:53:53 PM
Open Hijackthis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-AA8C-E56FA49CA83A} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)


Important: Close all windows except for Hijackthis and then click Fix checked.

Exit Hijackthis.

----------

Download SDFix.exe (http://downloads.andymanchesta.com/RemovalTools/SDFix.exe) and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following:

Title: Re: system error dangerous virus message
Post by: zoe on April 30, 2008, 06:19:46 PM
OK!  Please see attached files.

[recovering space - attachment deleted by admin]
Title: Re: system error dangerous virus message
Post by: evilfantasy on April 30, 2008, 06:48:13 PM
That got on eof them, the next one will need a more powerful tool.

Please download Combofix by sUBs from one of the below links.
(Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall.
Please add the combofix log in the next reply.
Title: Re: system error dangerous virus message
Post by: zoe on May 01, 2008, 04:01:42 AM
See attached.  Thanks!

[recovering space - attachment deleted by admin]
Title: Re: system error dangerous virus message
Post by: evilfantasy on May 01, 2008, 11:26:58 AM
Looks good. We need to scan a file, hopefully it will come back clean.

Scan Suspicious File(s)

Please visit Virustotal (http://www.virustotal.com/en/indexf.html)
(If more than one file needs scanned they must be done separately and logs posted for each one)
Code: [Select]
C:\WINDOWS\C:\WINDOWS\System32\svchost.exe
Title: Re: system error dangerous virus message
Post by: zoe on May 01, 2008, 07:16:05 PM
I visited the Virustotal site as instructed.  After copying the Code in box (C:\Windows\C:\Windows\System32\schost.exe)  and sending the file, I get this message:  0 bytes size received / Se ha recibido un archivo vacio

Did I do something wrong?  Thanks for your patience.
Title: Re: system error dangerous virus message
Post by: evilfantasy on May 02, 2008, 10:18:58 AM
You didn't do anything wrong, it won't scan 0 byte files.

Go to Start > Run and copy then paste this line into the box and hit enter:

sc stop wscsvc

Now again Start > Run and paste this line and hit enter:

sc delete wscsvc

How is everything now?
Title: Re: system error dangerous virus message
Post by: zoe on May 02, 2008, 01:54:01 PM
Did it!  My computer is running great with no more annoying pop-ups.  Thank you so very, very much for your help.  People like you make the world a much better place!  May God Bless you!
Title: Re: system error dangerous virus message
Post by: evilfantasy on May 02, 2008, 02:01:16 PM
Still a few more fianl steps.

Let's clear out the programs we've been using to clean up your computer, they are not suitable for
general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
.
.
(http://i154.photobucket.com/albums/s258/evilfantasy69/combofixu-1.jpg)
.
The above procedure will:.
Download OTMoveIt2 by OldTimer  OTMoveIt2.exe (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) and place it on your desktop. (unless you already have it installed)

1. Double click OTMoveIt2.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. Once complete exit out of OTMoveIt2

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
.
Use the  Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.
.
Here are some great tools to help you keep from getting infected again.

To prevent unknown applications from being installed on your computer install WinPatrol 2007 (http://"http://www.winpatrol.com/winpatrol.html")

Another thing I would suggest installing SiteAdvisor (http://www.siteadvisor.com/). SiteAdvisor rates sites on business practices and spam.

 Spybot Search & Destroy (http://fileforum.betanews.com/detail/Spybot_Search_and_Destroy/1043809773/1) - A safe and effective spyware scanner.
*  (http://www.safer-networking.org/en/tutorial/index.html)Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers (http://www.bleepingcomputer.com/forums/tutorial43.html)

 AVG Anti-Spyware Free Edition (http://free.grisoft.com/doc/download-free-anti-spyware/us/frt/0) - Very reliable with a high detection rate.
*  AVG Anti-Spyware User Manual (http://free.grisoft.com/doc/5390/us/frt/0?prd=asf)

 SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html) - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
*  (http://www.bleepingcomputer.com/tutorials/tutorial49.html)Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/forums/tutorial49.html)

 Comodo BOClean (http://www.comodo.com/boclean/CBO_download.html) - Stops trojans and many more malicious attacks.

Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
*  Click here (http://www.freebyte.com/antivirus/#freefirewalls) for a list of free firewalls.
*  Why would I consider a third party firewall? (http://www.microsoft.com/windowsxp/using/security/learnmore/atkin_firewall.mspx#EGF)
* Understanding and Using Firewalls (http://www.bleepingcomputer.com/forums/tutorial60.html)

 UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com[/b]]http://www.windowsupdate.com (http://[b) regularly. This will ensure your computer has always the latest security updates available installed on your computer.
*  Help with Windows updates (http://support.microsoft.com/?scid=ph;en-us;6527)

Learn more about how to protect yourself while on the internet read this article by Tony Klien:  So how did I get infected in the first place? (http://www.castlecops.com/postlite7736-.html)

Let us know if anything else comes up.