Malware: PC Total Defender & Trojan.Fakealert

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Topspeed, Jul 8, 2008.

  1. Topspeed

    Topspeed Private E-2

    Problems:
    Free virus scanner could not be closed and rogue files and program were executed and installed on 7/7/08. Frequent “PCTotalDefender” popups and system warnings. Constant “Insecure Internet Activity” C:\windows\warning.html ActiveX blocking and thus difficulties accessing web pages and unable to download files directly or run free live antivirus scans.

    Possible related malware: A while back prior to this recent PC Total Defender malware attack, there were two incidences where two different folders with large numbers of folders and files in My Document directory went missing.

    Actions taken:
    1. No malware identification and detection from Free Avira Antivirus, Symantec, Ad-aware, AVG, Spybot & Search, and Superantispyware.
    2. ActiveX blocking and unable to run live free Trendmicro housecall antivirus scan.
    3. Panda Active Scan identifies 3 malware.
    4. Ran Windows XP cleaning tools as per Majorgeeks.com. Only Malwarebytes identified and quarantined Trojan.Fakealert and Rogue. Winantivirus, but the fix did not remove the resident files at startup and the registry, so the malware repopulated.
    5. After Combo-fix rebooted, I got: 1 error message, 1 Avira detection, and the PCTotalDefender popups

    “Windows cannot find “C:\Docum~1\Owner\Locals~1\temp\temp.exe. Make sure you type the name correctly, and then try again. To search for a file, click the Start button, and then click Search.

    Avira AntiVir window: “Unwanted Program was Found!” C:\combo-fix\pv.cfexe SPR/Tool.pvprogram. “Deny Access”. OK.

    The PCTotalDefender popups​

    Guidance for malware removal appreciated. Five files attached.

    Topspeed
     

    Attached Files:

  2. Topspeed

    Topspeed Private E-2

    last two files
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Java(TM) SE Runtime Environment 6

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: rmd - {DE5F80FD-8A16-4E53-A670-25EDD1152274} - C:\WINDOWS\system32\rmd.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [pctdf.exe] C:\WINDOWS\pctdf.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Topspeed

    Topspeed Private E-2

    Dear chaslang,

    Thank you very much for the fix. The tools and your instructions made this to be the quickest and most efficient fix I ever done. I had to deal with several time-sensitive emergencies in addition to the computer problem and couldn’t write earlier as the computer seems to have been restored.

    Attached are the last combofix.txt and Mglogs.zip after running the tools as requested. The previous false Internet security warning and blocking pages have stopped. Is there anything else I need to do?

    I have a few related follow-up questions after the fix:

    1. What is the safest and best way to close a rogue program in the future since by clicking on the usual upper “X” to exit the PCTotal Defender popup, I seemed to have executed the malware.
    2. Should I reinstall Java updates now?
    3. What needs to be done to modify and restore the desktop Date-Time since the Windows xp Date-Time is still on European and military formats after running Combo-Fix?
    4. Can I delete Combo-Fix, QooBox, and all its related folders now because it is being detected by Avira Antivirus daily screen?

    Thanks very much for your time and expertise.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have one more file to delete. Please delete the below:
    C:\WINDOWS\warning.html

    Then your logs will be clean.

    With a good firewall in place, you would first have it lock the internet so nothing can go in or out. Then shutdown all other open browser windows except this popup. Do not click anywhere at all on the popup as the result is almost always the same and that is to install. Then open up Task Manager and kill this popup window.

    First uninstall the last one we left in place which was Java(TM) 6 Update 5 then reboot and install the current one. See the link in the READ & RUN ME.

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.


    All part of our final instructions below.




    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds