trojan.fake alert removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mocone, Jan 28, 2010.

  1. mocone

    mocone Private E-2

    hi major geeks,

    it has fortunately been awhile since you have had to help me repair my computer. unfortunately though, malwarebytes has found trojan.fakealert in my HKEY_USERS\s-1-5-21-1390067357-725345543-1003\software\xml as of yesterday and it cannot be removed. i have followed your steps and hope i have completed them all correctly. i was not able to run combofix. i couldn't figure out how to disable mcafee and complete the download for it. i did do the other steps and hope they are right. definitely don't want to waste your time. i'll attach the logs i have.

    thanks for your time
    mocone
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please refer to the below:

    How to temporarily disable your anti virus
    and follow the steps for mcafee.

    I would like for you to then run combofix and also MGTools. Attach logs from each into your next reply and let us know of any problems you may have encountered. I can then start to build you a fix.

    When you say MBAM doesn't remove the trojan, do you then re scan with it and have it reappear?
     
  3. mocone

    mocone Private E-2

    thanks for the quick reply. here are the logs you asked for. mcafee virus scan was actually disabled but is listed as on. in response to your question about rerunning malwarebytes, yes the trojan reappears everytime. i've tried safe mode with system restore off as well with no luck. it only shows up in xml after cleaning but if i go back online and then run a new scan it shows up in a couple of other locations also. the binary for the location i listed in the original post shows as 0000(hkey software xml). don't know if that helps. thanks again.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please go to Add/Remove programs and uninstall the following software:

    • Java 2 Runtime Environment, SE v1.4.2_06
    • Java(TM) 6 Update 7
    • Java(TM) SE Runtime Environment 6 Update 1
    • Java(TM) SE Runtime Environment 6

    2. Disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    4. Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\system32\icm32T.dll
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.


    5. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Driver::
    Dptsrtevas
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    6. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    7. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    8. Now Re scan with Malware Bytes. fix all it finds and attach the log.

    9. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. TDSSKiller and MBAM.

    10. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. mocone

    mocone Private E-2

    hey kestrel13!

    it appears that everything is working fine now. attached are my logs. if there are no more fixes to be done should i remove all tools and super antispyware?
    thanks again for your time. oh yeah, when i ran jotti's malware scan on the posted path it said it was empty. also when i ran tdsskiller i was not given any prompts to delete. however it looks as though there was nothing to be fixed in that scan. thanks again.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are not quite finished yet so do not uninstall the tools until the final steps say to do so. Your logs appear to be clean, however there is one file which I am unsure of, which makes me hesitatnt to give you all clean just yet. It's the one you said jotti had a problem with, but I do not see why it did so. Hmmm...

    Let's do this please:

    Could you please get this: icm32T.dll
    into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip
     
  7. mocone

    mocone Private E-2

    thanks again for all your help. i'm sending the log you asked for. it was pretty strange, i tried the scan several times and it said the location was empty everytime. however i may have done something wrong. don't think so, but maybe.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well that didn't appear to work either. Can you use Windows Explorer to locate it:

    c:\windows\system32\icm32T.dll

    and re-name it to icm32T.dll.old

    See how your machine behaves after a few reboots and give it a full 24 hours or so, then report back and let me know how things are running. :) Apart from this issue, I am seeing nothing else to fret about.
     
  9. mocone

    mocone Private E-2

    so i looked through window explorer and found nothing. i also did a search through the start menu and came up with nothing again. my pc seems to be ok, old but ok. is that critical to the performance of my computer? it has gotten slower with time. thanks
     
  10. mocone

    mocone Private E-2

    so i located the folder icm32t.dll in the system32 folder but it is transparent, not sure what that would indicate...empty, missing location?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you rename it? Is it possible?
     
  12. mocone

    mocone Private E-2

    was not able to. what should i do next?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\icm32T.dll
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.
     
  14. mocone

    mocone Private E-2

    here are the new logs.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. mocone

    mocone Private E-2

    hey kestrel13!

    so i started removing tools as listed and upon removal of combofix a pop up window by a company named vibrant came back. it had been there during the problem. i just ran malwarebytes again and the scan was clean. do you have any ideas what that may be or what i should do?

    thanks
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you use Firefox use this handy plug in for the browser which will prevent almost all pop up's, pop unders and other forms of unwanted advertisement.

    AdBlockerPlus
     
  18. mocone

    mocone Private E-2

    hey kestrel13!

    i have one last question. as i was going through and cleaning up tools, logs, etc. i found the viewpoint mediaplayer folder in program files. it is not in the control panel though. can/should i remove this? i made an attempt and it said "program performance could be effected". can i remove anyway?

    thanks again
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes remove the viewpoint Media Player folder :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds