Ultimate Defender

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Eternalfire, Aug 11, 2007.

  1. Eternalfire

    Eternalfire Private E-2

    Ok, so i know this problem has been seen many times before. and now...i have it. I've followed the "read and run me" steps and it doesn't seem to work. I've also read some other posts with people with the same issue and tried to figure it out. I don't know why it's not working :/

    And if you don't know what I'm referring to by Ultimate Defender, basically it creates false security messages and tries to get you to buy their "AV Software" which is a bunch of horse doo-doo. >oh and most annoying of all the big red link to their site image on your desktop.
     

    Attached Files:

  2. Eternalfire

    Eternalfire Private E-2

    more
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. Eternalfire

    Eternalfire Private E-2

    heres the first. working on the next.

    (and thankyou very much btw :D )
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rename HJT as directed in the instructions.

    Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Attach new logs for:
    ShowNew
    GetRun
    HJT
    ComboFix
     
  6. Eternalfire

    Eternalfire Private E-2

    ummm still have it all. log files are all the same.heres the rapport

    moving on to tims.
     

    Attached Files:

  7. Eternalfire

    Eternalfire Private E-2

    still got issues ;?
     

    Attached Files:

  8. Eternalfire

    Eternalfire Private E-2

    hjt and new combo

    now when i did combo again things look better. but im not positive. if i restart if it'l just come back
     

    Attached Files:

  9. Eternalfire

    Eternalfire Private E-2

    nvm. i still get the false security. but no more red background ... :S
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still have not renamed HJT!!
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe ----->
    Should be:
    C:\Program Files\Trend Micro\Hijackthis\analyse

    Now turn off all anti-virus software and anti-spyware and then do the following after closing all browsers.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    HJT - renamed!
    ShowNew
    GetRun
    Avenger
     
  11. Eternalfire

    Eternalfire Private E-2

    ... first 3
     

    Attached Files:

  12. Eternalfire

    Eternalfire Private E-2

    and bam. sorry i went mia yesterday it was my b-day and friends put a party together so i went off to that :/
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Happy Birthday!!:)


    Please find and delete:
    C:\Documents and Settings\~Jarvis~\Desktop\Spyware&Malware Protection.url
    YOu may also uninstall Counterspy as we are finished with it.

    Now turn off all anti-virus software and anti-spyware and then do the following after closing all browsers.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    HJT - renamed!
    ShowNew
    Avenger

    When we are certain you are malware free ..you will need to download and install Service Pack 2!!!
     
  14. Eternalfire

    Eternalfire Private E-2

    looks good to me.

    the avenger log file is completely blank. idk if thats good or what.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Find and delete:
    C:\WINDOWS\dat.txt

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT.

    To Reset Web Settings:

    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Your logs look clean. You may uninstall any programs we had you download (including Counterspy).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  16. Eternalfire

    Eternalfire Private E-2

    thanks! XD i appreciate the help alot. if it weren't for my problems i probly wouldn't of found this site. but i think ill use it for other stuff as well. :)

    much respect
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome ....safe surfing and don't be a stranger to the forums...a lot of good information to be had!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds