Windows Security Alert

Discussion in 'Malware Help (A Specialist Will Reply)' started by ashuping, Sep 13, 2007.

  1. ashuping

    ashuping Private E-2

    I recently picked up a bug with the pop up about a windows security alert, spyware is running on my computer and to click yes to be taken to the spyware removal software. After a little research I found out this is tied to the winantivirus problem. I performed all the steps in the malware removal guide with the exception of panda scan which never would load properly. I ran some of the alternate scans and TrojanScan found the Trojan.False Alert files and removed them but it didn't help. One interesting thing that has happened is that my control panel icon was removed and whenever I try to get into add/remove programs through other routes, I get a message that the operation has been blocked and to contact my administrator. I have no administrator other than myself. I've attached the first three log files and will attach the others in subsequent posts. Thanks!
     

    Attached Files:

  2. ashuping

    ashuping Private E-2

    WSA additional logs

    These are the logs from the other scan programs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I know you said you ran the READ ME but you did not follow the directions given. HijackThis is not renamed and you did not attach all of the logs that were requested. You need to properly install HJT and then you need to attach the below logs and I will leave off Panda since you could not run it).

      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis - a new log after being properly renamed
    Also please stay in one thread. I merged your posts back into one thread.
     
  4. ashuping

    ashuping Private E-2

    Thanks for the welcome. I've been a lurker until now.

    Sorry about the screw-ups. I got in a hurry and misread some of the instructions. I ran counterspy but it didn't find anything. I've attached the other logs. Thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2
    Sunbelt CounterSpy <-- we are finished with this trial program now.


    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: Shell=
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - Startup: system.exe
    O4 - Global Startup: autorun.exe
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O18 - Protocol: brx - {9C160F90-74D1-11D3-AB60-0060977C1F29} - (no file)
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. ashuping

    ashuping Private E-2

    Pop-up is gone and control panel icon is back. Everything seems to be back to normal. I've attached logs. You guys rock
     

    Attached Files:

  7. ashuping

    ashuping Private E-2

    Last log. Thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In my very first step I asked you to uninstall the old Sun Java version and CounterSpy! Why didn't you do this? Steps must be followed in the order written as it can often affect the outcome of the procedures.
     
  9. ashuping

    ashuping Private E-2

    I couldn't because I didn't have access to the add/remove program because the virus had blocked me out and I couldn't get to it through any other mechanism. Do I need to go through the process again now that I can get to the add/remove program?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you don't have to start over again! Just see if you can get both of them to uninstall right now. You "could" have an issue with CounterSpy. Tell me what happens.

    You logs are clean otherwise.
     
  11. ashuping

    ashuping Private E-2

    Counterspy came off OK. I get a fatal run error when I try to remove Java saying it can't read a file in the installer folder in Windows. Should I just remove manually?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know how to do this? You must be very careful playing in the registry.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  13. ashuping

    ashuping Private E-2

    Ran through step 8 and everything is great. Thank you, Thank you, Thank you!

    To be honest I forgot about having to mess around in the registry to get rid of everything for the Java. What would you recommend?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Complete up to step 11 ASAP.

    Run the below and attach the log:

    Getting Uninstall Programs List From The Registry
     
  15. ashuping

    ashuping Private E-2

    I've completed all the steps but the log is too large to attach according to the attachment manager. I already like Firefox much better than Explorer.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Compress it into a ZIP file and attach it or split it into two parts and attach the parts.
     
  17. ashuping

    ashuping Private E-2

    It's been a long day. I should have thought of that.
     

    Attached Files:

    • log.zip
      File size:
      28 KB
      Views:
      3
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now it should no longer appear in Add/Remove programs! Take a look.
     
  19. ashuping

    ashuping Private E-2

    Sorry, been gone for a couple days. Tried it and checked in add/remove. The item is still there, but the change and remove buttons don't show when I highlight it. Does this mean it's gone? Thanks
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you get a success message when you double click on the fixME.reg patch? Try it again and tell me what happens. Make sure your antivirus or antispyware is not blocking you from adding the registry patch into the registry.
     
  21. ashuping

    ashuping Private E-2

    Yes I do get the success message. I tried a couple more times and the entry is still there. As best I can tell I'm not getting blocked by any spyware or virus blockers.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay which entry exactly is it that you are saying is still there. Get me an new log from GetUnKey.bat (note:not GetRunKey.bat).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds