Flux rss
Search : in
By : Relevance Date Username
Statut : Not resolved

Joke-bluescreen.c and Antivirus XP 2008

LeeAnn, on Tuesday 12 August 2008 à 02:00:27
Hello,
My mother in law has now been infected on two seperate computers with the Antivirus XP 2008 virus. One computer we've unplugged and basically scrapped - the other one I installed Avast on it as soon as I got it up and running so I don't know how anything got through but first today she got joke-bluescreen.c and then right after I had her click the green download button for Malwarebytes' Anti-Malware 1.24 from your site she got the message that viruses were detected with Antivirus XP 2008 and it (the Antivirus XP 2008) is telling her she's got zillions of infected files.... but the Malwarebytes Anti-Malware 1.2 has been scanning for over 15 minutes and so far hasn't detected ANY infected files. I'm ready to cry (she's so new to computers that I'm the one trying to help her but I'm so frustrated I could KILL whoever is making these stupid viruses- do they not have anything better to do that mess with people???) Sorry - you understand this frustration...

Could you please help me help her? Why isn't this program we downloaded from Kioske finding and getting rid of these viruses or whatever they are?

Thanks,
LeeAnn O'Neil
Configuration: Windows XP
Internet Explorer 7.0
Reply to LeeAnn  Report this message to moderators Go to last message

1


  • 1
    This message seems useful, vote!
  • Ce message ne vous semble pas utile, votez !
  • Report this message to moderators
truste1, on Tuesday 12 August 2008 à 11:15:34
hi there,

have you tried another antivirus scan on your pc ? if not i would recommend you to use zonealarm its a trial version but will help you for the time being to get rid of those viruses? but im asking myself if its not registry problems also ?
you can download a res=gistry fix have it install and then repair the registry try the two solutions ive given you and if its not good then rewrite here.

thank you
Reply to truste1

2


  • This message seems useful, vote!
  • Report this message to moderators
jovax, on Wednesday 13 August 2008 à 19:50:14
Hi! leeann i am experiences that kind of issue just try to remove ur anti-virus and replace kaspersky but it takes time to scan coz your PC is infected trojan.downloader and make sure disconnect your internet after that re scan on malware-bytes anti-malware in definitely remove malicious code on the registry....


regards,
jovax
Reply to jovax

3


  • This message seems useful, vote!
  • Report this message to moderators
mlpace, on Thursday 14 August 2008 à 21:26:58
I use Avast. I sent an email to support@avast.com asking them to tell me how to remove AntiVirus XP 2008. They replied and below is the gist of it. It was not hard to do. I recommend you contact them.

This is what I did as per instructions from Avast:
1. Turn off system restore: Start/Control Panel/System/System Restore and check "Turn off System Restore."
2. Schedule a boot time scan in Avast with the advanced option to move infected items to the chest:
start Avast, right-click in the main window, select Schedule Boot-time Scan, select advanced options and choose "Move to Chest."
3. Restart the computer when prompted. Avast will restart and do a boot-time scan.

After the scan has finished and moved any viruses to the chest, do the following:
4. Turn system restore back on.
5. Download and run the lastest version of AdAware (www.lavasoft.com).
6. Remove any threat it finds.
6. When prompted to create a restore point in AdAware do so.

This should fix your computer. This virus is everywhere. I have picked it up twice in the last week. The people at Avast saved me.</souligne></ital>
Reply to mlpace

4


  • This message seems useful, vote!
  • Report this message to moderators
tomalex1, on Monday 18 August 2008 à 02:08:42
Hi LeeAnn,

In case you haven't found a workable a solution, here's another one. My son gave me a program called reanimator that can be downloaded from "http://www.greatis.com/security/download.htm" for free. It worked for me!
Best Wishes, Tom
Reply to tomalex1

5


  • This message seems useful, vote!
  • Report this message to moderators
CrimsonKissaki, on Wednesday 27 August 2008 à 21:02:23
I'm the lead help desk tech for a nationwide advertising magazine, and we just had our entire Exchange Server network hit with the darn AVXP2k8 bug. Here is the fix we use to get it off the computer, and it only takes about 10 mins if you have a clue about what you're doing.

What the virus does:
- It places its core file in C:\Program Files\#randomname# - easy to spot. Usually something like rhcgsbj0elj0
- It removes access to the Desktop and Screen Saver tabs in the Desktop Properties window through registry changes.
- It places a .bmp and a .scr file in C:\Windows\system32 - easy to spot. Once you bring back the Desktop and Screensaver tabs you will see their names and can delete them if antivirus does not catch them first.



To fix quickly:

Use the registry fix I wrote to correct several changes that it makes.

- Brings back the Desktop and Screensaver tabs to desktop properties
- Fixes changes made to wallpaper and screensaver settings (allows the virus to re-propagate if not fixed asap)

Save the following text as a .reg file (you pick the name) and run it.
=--------------------=
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion­\Policies\System]
"NoDispBackgroundPage"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispBackgroundPage"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispScrSavPage"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispScrSavPage"=dword:00000000
[HKEY_CURRENT_USER\Control Panel\Desktop]
"ConvertedWallpaper"="C:\\Windows\\Zapotec.bmp"
"OriginalWallpaper"="C:\\Windows\\Zapotec.bmp"
"SCRNSAVE.EXE"="C:\\WINDOWS\\system32\\sspipes.scr"
"Wallpaper"="C:\\Windows\\Zapotec.bmp"
=--------------------=

Now for some minor hunting ...

Navigate in regedit to HKEY_LOCAL_MACHINE\SOFTWARE\ and look for a random folder name, e.g. rhcgsbj0elj0, and delete the whole thing. The registry keys it holds all show links to the .bmp and .scr and other .exe nasties that the virus tossed out.

Navigate in regedit to --HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-- and look for several random items in there. They have nonsensical names and should be easy to spot. There are usually 3-4.
Examples: SMrhcgsbj0elj0, zjyacadj, lphclsbj0elj0

Once the registry is cleaned out removing the virus is made much easier.

Run Task Manager and find the random named .exe files that are running.

Open --C:\Program Files-- and look for the random folder name that holds the virus, e.g. --rhcgsbj0elj0--. There are 2 files you can delete from it immediately, a .dat and a --license-- file. Make note of the name of the .exe file in the folder so you know which application to end task on first. You will have to end task on the random .exe file in Task Manager, then QUICKLY switch over to the other window to delete the virus file before it can toss out another thread and you get those lovely --cannot delete file because it is already in use-- errors. Once the .exe part of the virus is gone, the folder the rest of it is in can be removed easily and you can end task on the remaining virus files. This usually keeps the virus off permanently.

Once this is done it is highly recommended that you update your anti-virus software and perform a full scan on the computer. If you don't have any try AVG Free from Grisoft. It's pretty good and we use it on folks who have personal computers used for business purposes.
Reply to CrimsonKissaki

9


  • This message seems useful, vote!
  • Report this message to moderators
Sansmayhem, on Sunday 21 September 2008 à 18:42:51
thank you so much for this post - I had used ad/spyware apps and my virus app to hunt down this nasty bit of work and been minimally successful in killing it. I just couldnt get rid of the blasted tweaks it did to the control panel etc. Your reg-edit fixes were perfect and while I was in there looking I found a few other darlings like WinIFixer that I had gotten rid of with the tools but kept coming back.

Thanks again - this was a great post and now I have a functional laptop again - woohoo.

Gigi
Reply to Sansmayhem

6


  • This message seems useful, vote!
  • Report this message to moderators
Dave, on Sunday 7 September 2008 à 13:34:27
You may want to try setting up your anti-virus software to check the root kit of the PC. I've caught 16 virus' and spyware hidding out thanks to webroot anti-virus/spysweeper. Sure it coast 29 bucks a year for virus updates but usually on one or two traces of virus or adware will make it on to my PC...where it meets up with my friend mr quarantine. :).
Reply to Dave

7


  • This message seems useful, vote!
  • Report this message to moderators
K B, on Wednesday 17 September 2008 à 21:15:21
use the latest version of maleware bytes... it got rid of 2008 and 2009 that infected my computer after that install and run spybot search and destroy and run that it should get any thing left over... make sure you update them both first.. run full scan with both start with malewarebytes then use spybot... hope this helps!!!
Reply to K B

8


  • This message seems useful, vote!
  • Report this message to moderators
mike, on Thursday 18 September 2008 à 02:45:22
http://www.freepchelp.co.uk/...


this link will clear up problem it worked for me scroll down and follow the instructions
Reply to mike

10


  • This message seems useful, vote!
  • Report this message to moderators
rohit, on Wednesday 8 October 2008 à 15:51:36
thnx crimsonkissaki....ur comment was really imo for me
Reply to rohit

11


  • This message seems useful, vote!
  • Report this message to moderators
X_Spec, on Monday 20 October 2008 à 17:17:12
The fake blue screen log on is not a virus thus rendering your Anti-Virus inept
try using combofix to get rid of this problem and in future be wary of what you download
or even the sites you visit i recommend using kaspersky internet security 2009!

Visit combofix's home here>

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Its free.

X_Spec
Reply to X_Spec

12


  • This message seems useful, vote!
  • Report this message to moderators
Angela, on Wednesday 22 October 2008 à 06:29:14
Installing more free 'antivirus' software is only going to aggravate your problem.

I'd suggest putting all of your files onto a USB (you said her computer was new, so probably not too much trouble)

Reinstall OS and drivers (It should get rid of all the viruses, even the ones lurking in the system files)

Install Norton or McAfee- stick to the well known.

Always update!!

Hope this helps!
Reply to Angela

13


  • This message seems useful, vote!
  • Report this message to moderators
 Tim, on Friday 31 October 2008 à 19:03:48
Hi,
I can help you. Antivirus 2008 is actually spyware. It is not a real antivirus program. Malwarebytes Antimalware should get rid of it and if id does not, then you may need some other tools I use antimalware and it gets rid of it. I have a business in computers. Let me know if that does not work.
Reply to Tim

Résultats pour joke bluescreen.c and Antivirus XP 2008

Antivirus xp 2008 Hello, I have Vista OS and suddenly go this crazy antivirus xp 2008. How do I delete this nasty thing? I need help. Thank you in advane for all your help en.kioskea.net/forum/affich-25061-antivirus-xp-2008
Antivirus XP 2008 Hello, I am not able to uninstall antivirus xp 2008 from my add remove programe. Can you tell me what can i Do ? By mistake i have removed anivirus xp 2008 folder from Programe file. Please urgent Thanks & Regards Sunil Prasad India. en.kioskea.net/forum/affich-26142-antivirus-xp-2008
Antivirus XP 2008 removal Hello, Can someone help me remove Antivirus XP 2008 for free??????????? en.kioskea.net/forum/affich-18707-antivirus-xp-2008-removal

Résultats pour joke bluescreen.c and Antivirus XP 2008

Use your scanner without restarting your computer (Windows XP)Use your scanner without restarting your computer (Windows XP) Windows XP users might have faced the same problem while trying to use their scanner just after having switched on their computer. The scanner will not respond to any of the... en.kioskea.net/faq/sujet-362-use-your-scanner-without-restarting-your-computer-windows-xp
Corrupted or missing filesCorrupted or mising files Sometimes while installing a software or due to a problem on the hard disk , a part of the system file can be damaged. The system or the particular software can refuse to start. System file checker Windows XP possesses a... en.kioskea.net/faq/sujet-703-corrupted-or-missing-files
What is WebFldrs?What is WebFldrs? It may happen that you came across an application called Webfldrs XP in your control panel. Do not panic, this is only the functionality of 2000/XP Web Folders, consider it as an implementation of the WebDAV protocol... en.kioskea.net/faq/sujet-854-what-is-webfldrs

Résultats pour joke bluescreen.c and Antivirus XP 2008

Antivirus XP 2008Hello, Can i find a antivirus which delete Antivirus XP 2008? Because i have AVG antivirus but he doesn't delete antivirus XP 2008. When AVG find a virus he says " Do you want to force the threat removal?" Forced removal can cause system... en.kioskea.net/forum/affich-23342-antivirus-xp-2008
Search result redirecting to another siteHello, I am really frustrted.Can someone plz help? I got infected with the Antivirus XP 2008 today. I removed it. But now having a problem. When i search using google and i try to click on a search result i am not able to open it.instead it is... en.kioskea.net/forum/affich-24363-search-result-redirecting-to-another-site
How to remove malwareMy system in infected with Antivirus XP 2008 which gives message that ur system is infected and prompts u to by the licensed version of the removal software.How can i remove this malware. en.kioskea.net/forum/affich-14967-how-to-remove-malware

Résultats pour joke bluescreen.c and Antivirus XP 2008

Download CD Burner XPCD Burner XP is a complete burning software which possesses the following features: - Burn any media types, apart from DVD with double layer. - Burn audio CD without gaps between tracks. - Burn on-the-fly (Burn-proof). - Support most of... en.kioskea.net/telecharger/telecharger-1204-cd-burner-xp
Download FreeRAM XP ProThe hard disk is not the only component of the computer which it is necessary to defrag. The random access memory or RAM also is to defrag to guarantee performances and stability of your computer. FreeRAM Xp allows to defrag your random access memory... en.kioskea.net/telecharger/telecharger-404-freeram-xp-pro
Download PortableApps SuitePortableApps.com Suite is a complete collection of portable apps including a web browser, email client, office suite, calendar/scheduler, instant messaging client, antivirus, audio player, sudoku game, password manager, PDF reader, minesweeper clone,... en.kioskea.net/telecharger/telecharger-108-portableapps-suite

Résultats pour joke bluescreen.c and Antivirus XP 2008

Wikileaks champions whistle blowing after US court triumphA man tries to access a website at an internet cafe in January 2008. Wikileaks was championing nameless whistle blowers with renewed vigor Monday after a US judge ruled efforts to shut down the website violated Constitutional rights to free speech.... en.kioskea.net/actualites/wikileaks-champions-whistle-blowing-after-us-court-triumph-10175-actualite.php3
One Internet cut explained, but four others still a mysteryAn Egyptian man tries to access a website at an Internet cafe during disruption of the Internet service in Cairo in January 2008. A ship's anchor severed one undersea Internet cable damaged last week, it was revealed on Thursday amid ongoing... en.kioskea.net/actualites/one-internet-cut-explained-but-four-others-still-a-mystery-10071-actualite.php3
Make way Ronaldo, here come the robotsSo-called "AIBO" four-leg robots representing Germany (blue) and Japan (red) vie for the ball during the 2006 RoboCup World Championship. After Euro 2008, now Austria is preparing to host RoboCup, where 500 robots take to the football field hoping to... en.kioskea.net/actualites/make-way-ronaldo-here-come-the-robots-10553-actualite.php3

Résultats pour joke bluescreen.c and Antivirus XP 2008

Processes - ntoskrnl - ntoskrnl.exe ntoskrnl.exe (ntoskrnl stands for Windows Boot-Up Kernel) is a critical Windows XP process used when Microsoft Windows boots up. This process may not be terminated and does not normally appear in the task manager. Its presence in the task manager may... en.kioskea.net/processus/ntoskrnl-exe.php3