Spyware.Possible_website_Hijack

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by szeto, Apr 10, 2012.

  1. szeto

    szeto Private E-2

    Hi,
    Have seen that this virus has been around.
    However, I am using Pctools with Antivirus and it can not fix or remove the virus.
    It was detected and I am yet to get help from them in removing it.
    Any help will be appreciated.
    Do not know which product works best now.
    Thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We can not help you with your website if it is compromised. Problems like this are really more of a vulnerability issue and not truly malware. How people write their website code, how old/unupdated the software they write it with, and how secure the servers that host it are really the areas to look at. Issues here are commonly referred to as code injection ( see: http://en.wikipedia.org/wiki/Code_injection ) The things we do in this forum are not going to find problems in your code. None of these malware scanners will since they are not design for this purpose.

    You are going to need to have a very good webpage developer check the code for security issues and you need to verify that all software being used has been updated to include all security patches. In addition, you need to make sure that the server hosting the website also has been fully updated.

    If you are concerned that your PC is infected, please follow these instructions:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. szeto

    szeto Private E-2

    ok
    Will go through the Read and Run me First.
    There are other virus issues.
    But will follow your instructions after going through the link below.
    Thanks
     
  4. szeto

    szeto Private E-2

    No I do not have a web site.
    This is the message that the PCtools spy doctor scan came up with.
    When I click on the + sign it gives me host which refers to www.google
    and www.bing
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Get me the requested logs as soon as you can and we will see if we can't get you clean. ;)
     
  6. szeto

    szeto Private E-2

    Thanks.
    Started working on it.
     
  7. szeto

    szeto Private E-2

    Hi,
    Just created one log which is attached.
    No logs saved with the super Antivirus spyware.
    Was able to restore my pc to an earlier date 3/20/12.
    This did remove the initial virus before I did the scan with this two programs.
    I did not run the combofix program.
    I have the updated pctools spydoctor with antivirus ready.
    Thanks
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller
     
  9. szeto

    szeto Private E-2

    Just run it.
    Attached is the logs.
    Thanks for the quick response.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to re-run TDSSKiller and have it fix this:
    Then come back and tell me how things are running.
     
  11. szeto

    szeto Private E-2

    Hi
    There is no indication for fixing it.
    They have cancel, skip and copy to quaratine in the drop folder for all the information.
    The malaware information indicates that we should wait fro instruction when there is no action for fix it.
    Run it again and the same in all the drop down.
    They all have skip.
    Seth
     
  12. szeto

    szeto Private E-2

    Hi
    Clarification.
    There is also a delete option.
    In all I have 5 items. 4 are unsigned file and the last is
    the TDSS File system with the Device\Harddisk|DRO
    As mentioned the three selection on the drop down are
    Skip
    Copy to Quarantine
    Delete
    Standing by for further instructions.
    Thanks
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy to Quarantine
     
  14. szeto

    szeto Private E-2

    Hi Copied all 5 to the quarantine.
    Attached is the log file
    Thanks a lot for the continued help and support.

    You will not believe pctools just sent me an e-mail with another fix called pctfixTDSS to use.
    Have not used it though since I am working with you now.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. What malware issues are you still having, if any?
     
  16. szeto

    szeto Private E-2

    Hi
    At the moment no issues to report.
    I have not activated my pctools spydoctor yet.

    Quick question though.
    When we complete the reset and I activate my virus protection do I need to enable the windows firewall with my pctools spyware doctor with antivirus.
    Thanks
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome. Yes, reactivate your firewall and let me know how things are running.

    If all is good:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  18. szeto

    szeto Private E-2

    Have done most of the malware tools removal excerpt for the TDSSKilller.
    Do I just delete the file on the desktop and then delete the quarantine folder?
    Will do the system restore next?
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can do that. ;)
     
  20. szeto

    szeto Private E-2

    Thanks all done.
    This not a malware question.
    But what causes BSOD.
    Started having it in December. Gets it about twice a month.
    I looked at some threads and have noticed the dump folder in windows directly.
    Just got it yesterday and today.
    Any suggesting?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There are numerous reasons for BSOD's. Set your computer to not restart on BSODs and post the error message in the software forum. They should be able to help you with that issue.
     
  22. szeto

    szeto Private E-2

    All issues taken care off.
    Thanks for all the support from you and the rest of the various forum administrators.
    I guess we can not thank you enough.
    Great place to visit even if not having any issues.
    Again Thanks
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds