This thread's last reply is from August 8, 2008, 5:24 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
My PC is infected and I am getting pop-ups which offer to sell me something called "Antivirus XP 2008".
Also, my wallpaper has changed to solid blue with a permanent message box in the middle which reads:
-------------------------------------------------------------------
| "Warning! |
| Spyware detected on your computer! |
| Install an antivirus or spyware remover to clean your computer." |
-------------------------------------------------------------------
Please help me with this!
Thanks!
--Fuzzy
*******************************************************
Logfile of HijackThis v1.99.1
Scan saved at 6:24:03 AM, on 7/30/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Here is the scan with the later version of HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:18 AM, on 7/31/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Double-click mbam-setup.exe and follow the prompts to install the program.
Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform full scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Post back with the Malwarebytes' Anti-Malware log and a new HijackThis log.
Here is what I have done in response to your last reply:
1st, I downloaded AVG-8.0, performed a system scan, and let AVG deal with the issues that turned up.
2nd, I downloaded Malwarebytes' Anti-Malware sw, formed a scan, and let it deal with the issues that it discovered (approx 63 turned up).
3rd, I had the Hijack-This perform another scan.
The scan results for 2 and 3 are posted here:
---------------------start of Malwarebytes' Anti-Malware Log file -----------------------
Malwarebytes' Anti-Malware 1.24
Database version: 1017
Windows 6.0.6001 Service Pack 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{62960d20-6d0d-1ab4-4bf1-95b0b5b8783a} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{62960d20-6d0d-1ab4-4bf1-95b0b5b8783a} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\cpbrkpie.coupon6ctrl.1 (Adware.Coupons) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a85a5e6a-de2c-4f4e-99dc-f469df5a0eec} (Adware.Coupons) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{6e780f0b-bcd6-40cb-b2db-7af47ab4d4a4} (Adware.Coupons) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a750a6d862d4} (Adware.Coupons) -> No action taken.
HKEY_CLASSES_ROOT\codecbho.codecplugin (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{84562fca-ee8b-4585-a1d1-eae97b23370e} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{48e92754-2daf-4de4-8385-34f631580e9b} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{a1c23ba2-8f20-4c01-b663-7ff2b3421194} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{098716a9-0310-4cbe-bd64-b790a9761158} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{098716a9-0310-4cbe-bd64-b790a9761158} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d37d6c1a-7ba4-47f4-9bf2-75031e257df6} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\codecbho.codecplugin.1 (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{f4406238-983a-4845-9053-f1d0007fd135} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\codecbho.xmldomdocumenteventssink (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\codecbho.xmldomdocumenteventssink.1 (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhc3t9j0et6b (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\rhc3t9j0et6b (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> No action taken.
HKEY_CLASSES_ROOT\AppID\CodecBHO.DLL (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\RichVideoCodec (Trojan.FakeAlert) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\CouponPrinter.ocx (Adware.Coupons) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> No action taken.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
C:\Program Files\RichVideoCodec (Trojan.FakeAlert) -> No action taken.
C:\Program Files\rhc3t9j0et6b (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\Autorun (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\Autorun\HKCU (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\Autorun\HKLM (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\BrowserObjects (Rogue.Multiple) -> No action taken.
C:\Users\Mark\AppData\Roaming\rhc3t9j0et6b\Quarantine\Packages (Rogue.Multiple) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008 (Rogue.AntivirusXP2008) -> No action taken.
Files Infected:
C:\Users\Mark\AppData\Local\Temp\low\COUPON~1.DLL (Trojan.BHO) -> No action taken.
C:\WINDOWS\CouponPrinter.ocx (Adware.Coupons) -> No action taken.
C:\WINDOWS\System32\RichVideoCodec.dll (Trojan.FakeAlert) -> No action taken.
C:\Program Files\rhc3t9j0et6b\database.dat (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc3t9j0et6b\license.txt (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc3t9j0et6b\MFC71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc3t9j0et6b\MFC71ENU.DLL (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc3t9j0et6b\msvcp71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc3t9j0et6b\msvcr71.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc3t9j0et6b\rhc3t9j0et6b.exe.local (Rogue.Multiple) -> No action taken.
C:\Program Files\rhc3t9j0et6b\Uninstall.exe (Rogue.Multiple) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk (Rogue.AntivirusXP2008) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk (Rogue.AntivirusXP2008) -> No action taken.
C:\WINDOWS\System32\blphc7t9j0et6b.scr (Trojan.FakeAlert) -> No action taken.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus XP 2008.lnk (Rogue.AntivirusXP) -> No action taken.
C:\Users\Public\Desktop\Antivirus XP 2008.lnk (Rogue.Antivirus) -> No action taken.
C:\Users\Mary\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Users\IUSR_NMPR\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> No action taken.
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> No action taken.
--------------------- end of Malwarebytes' Anti-Malware Log file -----------------------
--------------------- start of the HiJack This! Log file -----------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:29:10 PM, on 8/2/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Everything seems to run fine now. Here are the two, requested log files.
Thanks!
Kapersky:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, August 5, 2008
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, August 04, 2008 04:58:57
Records in database: 1050986
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
Scan statistics:
Files scanned: 253587
Threat name: 1
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 10:16:35
File name / Threat name / Threats count
C:\$Recycle.Bin\S-1-5-21-1939100313-1889649021-3630652394-1001\$RFBAYIU\Online Services\PRODIGY\pisetup.exe Infected: Trojan.Win32.Dialer.mv 1
K:\Old_Pc\Program Files\Online Services\PRODIGY\pisetup.exe Infected: Trojan.Win32.Dialer.mv 1
The selected area was scanned.
Hijack This:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:58:55 AM, on 8/5/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you need to be registered to post as unfortunately we were hit with too many spam posting to allow guest posting to continue just find your country room and register your complaint.
Below are some steps to follow in order to dramatically lower the chances of reinfection
You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented
Follow the instructions here for Windows Vista to disable and then reenable system restore in order to clear old restore points: http://www.pchell.com/virus/systemrestore.shtml Note: only do this once, and not on a regular basis
Make sure that you keep your antivirus updated
New viruses come out every minute, so it is essential that you have the latest signatures for your antivirus program to provide you with the best possible protection from malicious software Note: You should only have one antivirus installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as impairing the performance of your PC.
Make sure you install all the security updates for Windows, Internet explorer & Microsoft Office
Whenever a security problem in its software is found, Microsoft will usually create a patch for it to that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC, so keeping up with these patches will help to prevent malicious software being installed on your PC
Go here to check for & install updates to Microsoft applications Note: The update process uses activex, so you will need to use internet explorer for it, and allow the activex control that it wants to install
Keep your non-Microsoft applications updated as well
Microsoft isn't the only company whose products can contain security vulnerabilities, to check for other vulnerable programs running on your PC that are in need of an update, you can use the Secunia Software Inspector - I suggest that you run it at least once a month
Make Internet Explorer more secure
Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.
Install SpywareBlaster & make sure to update it regularly
SpywareBlaster sets killbits in the registry to prevent known malicious activex controls from installing themselves on your computer.
If you don't know what activex controls are, see here
You can download SpywareBlaster from here
Install and use Spybot Search & Destroy
Instructions are located here
Make sure you update, reimmunize & scan regularly
Make use of the HOSTS file included with Spybot Search & Destroy
Every version of windows includes a hosts file as part of them. A hosts file is a bit like a phone book, it points to the actual numeric address (i.e. the IP address) from the human friendly name of a website. This feature can be used to block malicious websites
Spybot Search & Destroy has a good HOSTS file built in, to enable the HOSTS file in Spybot Search & Destroy
Run Spybot Search & Destroy
Click on Mode, and then place a tick next to Advanced mode
Click Yes
In the left hand pane of Spybot Search & Destroy, click on Tools, and then on Hosts File
Click on Add Spybot-S&D hosts list
Note: On some PCs, having a custom HOSTS file installed can cause a significant slowdown. Following these instructions should resolve the issue
Click Start > Run
Type services.msc & click OK
In the list, find the service called DNS Client & double click on it.
On the dropdown box, change the setting from automatic to manual.
Click OK & then close the Services window
For a more detailed explanation of the HOSTS file, click here
Finally I am trying to make one point very clear. It is absolutely essential to keep all of your security programs up to date
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.