Infected w/ anything???

Discussion in 'Malware Help (A Specialist Will Reply)' started by dell1705user, Sep 6, 2007.

  1. dell1705user

    dell1705user Corporal

    I just want some reassurance with this computer. A popup window has been seen several times a day. The URL begins with www.creative1.com..... normally followed by a string of characters and numbers. Thanks as always.
     

    Attached Files:

  2. dell1705user

    dell1705user Corporal

    ....
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These logs do not really show any malware.
    Are you sure these popups are still occurring?
    Which browser do they appear in?
    Do they only occur when a browser is already opened?
    Do they occur in safe mode.


    You can uninstall the CounterSpy trial now!

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Install a real firewall (see step 3 in the below link) and see if they still occur.
    How to Protect yourself from malware!
     
  4. dell1705user

    dell1705user Corporal

    I uninstalled CounterSpy.

    I downloaded Avenger, but when I click the traffic light to perform the action I receive an Error message saying "Error: selected file does not appear to be a valid script." I click OK. Then another box appears saying "Click OK to log error and continue or Cancel to abort." I click OK and receive another box that says "Error code: 0" I click OK and then I'm right back to the Avenger interface.

    Having received this, I haven't moved on to the next step as I know there is importance in sequence with these matters.

    Any ideas?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you copy the who quote box properly? Did you include the line that says Files to delete:


    You need to answer my questions too.
     
  6. dell1705user

    dell1705user Corporal

    My mistake, I didn't realize I needed to include "Files to delete:"

    Yes the popups are still occuring, the last instance was last night, I just turned the computer on about an hour ago and I have yet to receive one yet. They are appearing in IE7 and they pop up WITH and WITHOUT the browser window open. They have not occurred in Safe Mode, but I haven't been in safe mode long enough to know if that is completely accurate or not.

    I will complete the previous steps now and post when I have completed them. Thanks.
     
  7. dell1705user

    dell1705user Corporal

    I've completed steps for Avenger and ATF.

    As to the firewall. I am currently using the default firewall that comes with XP. If I were to use another firewall software from the list provided in Step 3 of that link, is there anyway to get rid of all remains of the windows firewall so that it's not useless space being wasted?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Installing one of those firewalls will automatically disable the Windows builtin firewall. Get one of those installed now before continuing.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Also now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.



    Are you still seeing popups? If so, how often? Then also try running in safe mode long enough to determine if you get them in safe mode. I assume you can connect to the internet in safe mode. Is that a valid assumption?
     
  9. dell1705user

    dell1705user Corporal

    Which of the free firewalls offered there is recommended most? By you?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We used to recommend ZoneAlarm the most however the have gotten a little to large and resouces hungry over the last year or so which can cause significant slow downs on some PCs. Right now I would have to say use the first one listed which is Comodo.
     
  11. dell1705user

    dell1705user Corporal

    Ok, Comodo is installed. Question though, is it going to be popping up in the system tray asking me to allow/deny things every 10 seconds all the time?

    Secondly, what options should I be checking in the Windows Messenger uninstalling program?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only for each new item you run after it is installed. You need to do this for any firewall. It makes you aware of things you run and makes you better able to supervise your own security. Make sure for things that you want to allow to run that you also check the box the says to always allow it so it does not ask you again. It may take you a couple days to actually cycle thru the various things that you run and to approve or disallow access to the internet. It depends on which tools you run, how many, and how often.

    Use the option to Uninstall it.
     
  13. dell1705user

    dell1705user Corporal

    Windows Messenger uninstalled and attaching the Blacklight log...
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Blacklight found nothing! Are you still having problems?
     
  15. dell1705user

    dell1705user Corporal

    I have yet to see another popup. Musta been some of your handy work here.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Popups of like you were mentioning (especially when no browser is opened) are frequently cause by Windows Messenger.
     
  17. dell1705user

    dell1705user Corporal

    Interesting. Is Windows Messenger something that is isntalled with the other software and bloatware on new computers? If it is, I have never had that problem before now.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    WIndows Messenger is installed with Windows. And it does not matter whether you had the problem in the past or not. Once the hackers find out about your PC, they take advantage of any security holes. In this case, Windows Messenger.
     
  19. dell1705user

    dell1705user Corporal

    Last edited: Sep 9, 2007
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Who is your ISP?

    Do you have a service contract with Dell that you make use of?

    Where did you get your copy
     
  21. dell1705user

    dell1705user Corporal

    Comcast

    As far as service contract, do you mean, one of the many warranty options they offer at extra charge when I purchased the laptop? If that's what you mean, then Yes, I have one extending 3 years from Jan 2007.

    I'm not sure what you mean by this question. My copy of what?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look at the link you posted! It is an advertisement from ComCast. Speak to them.


    Ignore this! I forgot to delete it.
     
  23. dell1705user

    dell1705user Corporal

    How do you figure it's Comcast? Upon a Google search, the very first hit is Viewpoint Media Server.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on the link you posted and then hold your mouse over the animation while it plays. When it finishes you will see Comcast Digital Voice.
     
  25. dell1705user

    dell1705user Corporal

    Interesting. So, why wouldn't my popup-blocker or Comodo stop that automatically?

    As far as the rest of the previously posted logs am I looking clean and can begin uninstalling and removing the programs we used this time around?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would expect because the address is something that you have allow to pass thru.

    Do you ever get these popups when your cable to the internet is physically unplugged?

    Yes as stated in my first message, you have no malware.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can try blocking the below IP Address:
    209.107.94.106 or this URL: CREATIVEBY1.UNICAST.COM
     
  28. dell1705user

    dell1705user Corporal

    Thank you.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds