Help! Ultimate Defender & other spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by gravityforsaken, Mar 28, 2008.

  1. gravityforsaken

    gravityforsaken Private E-2

    Hi this is my first post, I've recently got some spyware that I can't get off my computer. I've read through tons of forums but nothing helps. I think one is Ultimate Defender, because it gives popups and a security center balloon to try to get me to buy their product. I also have seen popups saying I have the Abebot threat, trojandownloader.xs, and gomyhit.com spyware.

    I've run SmitRem, SmitFraudFix, ComboFix, Ewido online scan, XoftSpy SE anti-spyware, STOPZilla! anti-spyware, RogueRemover, CCleaner, SDFix, SUPERanti-spyware free edition, AVG anti-spyware...but nothing seems to get the pop-ups/balloons from stopping.

    Any help would be greatly appreciated, I can post the HijackThis log whenever you want me to.
     
  2. Lev

    Lev MajorGeek

  3. gravityforsaken

    gravityforsaken Private E-2

    Hi, thanks for the quick reply. I followed the link and instructions and attached the logs.
     

    Attached Files:

  4. gravityforsaken

    gravityforsaken Private E-2

    I forgot to mention I'm still having some trouble. For example at startup the Ultimate Defender popup still happens (as a windows security window), and I get other pop-ups as well, and google has trouble opening links (it takes me to ad pages).

    Thanks.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run this Trojan.Win32.Agent.akk (aka IEDefender) Removal Procedure and attach the requested log from FixIEFDef.



    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {3685DE5A-D4E5-436A-9080-09F318447B7B} - C:\WINDOWS\system32\anvvsgif.dll
    O2 - BHO: iSecurity - {A8311E8F-E459-4D22-89B4-CB9DCF10A425} - C:\WINDOWS\system32\ISECUR~1.CPL
    O4 - HKLM\..\Run: [fpuurblz] C:\WINDOWS\system32\fpuurblz.exe
    O4 - HKLM\..\Run: [iSecurity applet] rundll32.exe iSecurity.cpl,SecurityMonitor
    O20 - AppInit_DLLs: iSecurity.cpl
    O21 - SSODL: iSecurity - {A8311E8F-E459-4D22-89B4-CB9DCF10A425} - C:\WINDOWS\system32\ISECUR~1.CPL

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Brandon S\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger. And don't forget the log from FixIEDef.

    Make sure you tell me how things are working now!
     
  6. gravityforsaken

    gravityforsaken Private E-2

    No need to post the logs, the script for Avenger completely got rid of the rest of the malware. You guys rock, I'll recommend this site.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should still attach the logs even if Avenger found and deleted everything. Malware often creates additional files that may still need to be removed. It is better to be safe than sorry.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds