Impossible Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cjjohn11, Dec 4, 2008.

  1. cjjohn11

    cjjohn11 Private E-2

    Hello everybody. I have tried everything to rid my computer of this malware. I am getting a fake firewall security alert and my internet explorer has been "hijacked" and all it will display is another fake security alert. The fake firewall alert says something about "I.Spywarenow" or something like that. Internet explorer tells me windows has put browsing "on hold". This has been going on for two days now. I have run all the malware removal programs listed on this helpful website and followed the detailed instructions. The "antispyware" programs no longer find any infected files, but I still get the fake alerts. I am left at the last step of giving you my "logs" to let you analyze. Please help....
     

    Attached Files:

  2. cjjohn11

    cjjohn11 Private E-2

    Here's the fourth set of logs...
     

    Attached Files:

  3. cjjohn11

    cjjohn11 Private E-2

    Sorry to waste anybody's time but I got this figured out. For others who had/will have this problem, here is what I did: I downloaded hijackthis(hijackthis.com) and ran a scan, then I had hijackthis.de analyze the log. Then I had hijackthis remove/repair anything the analyzer deemed suspicious. And its FIXED!! This worked after no other malware/spyware remover would work.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Actually the only reason this helped you was that you had already run our cleaning procedure. You were basically almost finished except for one item. Didn't you notice all the malware problems that were found and removed? All you did with HijackThis was remove a leftover registry entry for a startup item. The below was the only item in HJT that was malware:

    O4 - HKCU\..\Run: [winhpdrv] "C:\Documents and Settings\James\Application Data\Google\xtgoj6119471.exe"

    If you had only used HJT and nothing else from our cleaning procedure, you would still be very badly infected.

    Now let's finish your cleanup so we can get to final instructions.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 7
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 9, 2008
  5. cjjohn11

    cjjohn11 Private E-2

    Everything is working well!

    Thank you for all your help. This is a great website!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds