Help, pc with "System Alert Popup" (Zlob, other spyware)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by craigcomputer, Apr 25, 2007.

  1. craigcomputer

    craigcomputer Private E-2

    Hi, I have found this windows xp machine in a bad state - first clue to problem was icons on the desktop labeled "Online Security Guide" and "Security Troubleshooting". They pointed to an obscure website, "asecureguide.com" and also mimicked the windows security center symbols.
    There were also listings of:
    -Internet Security Add-On,
    -Video Access ActiveX object
    -System Alert Popup


    I then began the "Read & run me first" procedure provided by this forum
    Went to uninstall the recommended items in the list:

    First "Internet security add-on." It displayed a dialogue "you need to reboot before uninstalling. reboot now? OK/Cancel." I knew either could be a trick and instead closed out with the red x at top right of the window.
    Then when I clicked it again it said "an error occured, program may have already been uninstalled, do you wish to remove from add/remove programs list?" I selected yes

    Next System Alert popup and Video Access ActiveX Object. they gave the same "reboot" dialogue and i clicked out with the red x every time.

    Emptied Yahoo Antivirus Quarantine (it had picked up a ByteVerify exploit back in october)
    Yahoo Antispy quarantine showed it was empty (later found out this was false)

    The rest of malware cleaning went normally (except Bitdefender and Panda online scans had to be run in normal boot mode. no web sites at all would load under safe mode w/networking, which is odd as it worked before)

    After looking over the panda activescan logs I found most everything except the cookies were in the yahoo antispy quarantine. Y! antispy showed no items so it wouldn't let me purge. I wound up uninstalling Y! antispy as it is pitiful anyway.

    checking add/remove programs, I see Video Access... has happily vanished!
    System Alert Popup, when I clicked change/remove, displayed the "already uninstalled dialogue" and I selected to remove it from the list

    here are the logs, including hijackthis!
     

    Attached Files:

    Last edited: Apr 25, 2007
  2. craigcomputer

    craigcomputer Private E-2

    note: i could only get a log in counterspy by viewing scan history and going to "print" then printing as pdf. the help files say there is a log folder under programfiles/sunbelt/counterspy, but it does not display any such folder.

    also getrunkeys gave the error : system unable to find specified registry key or value
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach one of the critical logs! Please attach the log from GetRunKey.
     
  4. craigcomputer

    craigcomputer Private E-2

    I keep getting the same error I did before, "unable to find specified registry key or value"
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must always give exact error messages! Do you mean this:

    Error: The system was unable to find the specified registry key or value


    That is not an a real error and it does not stop the program from running! It is just telling you that a key that is being looked for does not exist which is not a problem. You could get several of these. Let the program run (i.e. don't close the command prompt window) and wait for the log to pop up.
     
  6. craigcomputer

    craigcomputer Private E-2

    here ya go :) now I've learned
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I look at your logs, empty your C:\Program Files\Yahoo!\YPSR\Quarantine as requested in step 1 of the READ ME. Or delete these folders if you did not do that after uninstalling.

    Also delete the below file:
    C:\WINDOWS\brix6ie.ocx
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not seeing any malware other than what was in the CounterSpy log. It is not clear from that log whether you Quarantine or Deleted what it found. Did you fix them. In addition please do not attach PDF logs. PDF files can carry infections and we really want text files logs which can easily be created with CounterSpy.

    One item you do need to fix is the fact that you are running Mozilla Firefox (1.5) which is way out of date.

    Are you currently having malware problems?
     
  9. craigcomputer

    craigcomputer Private E-2

    1. I replaced the security apps on this pc with Kaspersky Internet Security. Its scan removed that brix6ie file.
    2.Uninstalling Yahoo antivirus got rid of that quarantine
    3. Updated Firefox to latest
    4. no more malware problems. I will now toggle System restore. thank you!!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds