Continuation of "Spysheriff -Flashing Wallpaper"

Discussion in 'Malware Help (A Specialist Will Reply)' started by Helper, Dec 15, 2005.

  1. Helper

    Helper Private E-2

    When I run Panda it detects and disinfects "secure32". None of my other programs detect "secure32". (Spysweeper, Norton, Spybot, Adaware, Microsoft)

    However, "secure32" returns and is detected and disinfected by Panda only.

    Another symptom is: Webroot Spysweeper has been selected to turn on automatically with windows. Sometimes the "Load at windows start-up" function is disabled by itself.

    Otherwise the computer runs fine.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Run the panda scan once more and attach the log.
     
  3. Helper

    Helper Private E-2

    Ok, I believe that I have attached the Panda scan file correctly...

    Thank you for your help....
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    (Don't run it yet)

    Please download HOSTER and then follow the below steps.
    • Unzip HOSTER to a convenient folder such as C:\Hoster

    • Run Hoster.exe, click Restore Original Hosts and then click OK.

    • Click the X to exit the program.
    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\system32\ldr408.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.
     
  5. Helper

    Helper Private E-2

    I followed your directions. I ran Panda again and attached the log....
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, open Spy Sweeper and uncheck the HOSTS file in Shields. After you have unchecked it run HOSTER as previously requested again.

    Then delete the directory "C:\!KillBox". Afterwards reboot and run another Panda scan to confirm they are gone.
     
  7. Helper

    Helper Private E-2

    Spysweeper is fixed; it now will automatically start with windows. There seems to be no other functional problems with the computer. However, I ran Panda and "secure32" came back again. I have attached the Panda log.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HOSTS file is locked by SS, if you didnt purchase Spy Sweeper uninstall it and run HOSTER again. If you did purchase it you must uncheck the HOSTS file shield in order to remove this.

    Navigate to the following folder, attach the file HOSTS to your next post as a ZIP file.

    C:\WINDOWS\system32\drivers\etc
     
  9. Helper

    Helper Private E-2

    It looks like you nailed it!

    Yes, I have a legal copy of WebRoot SpySweeper installed.

    It appears that the "Common Ad Sites" shield of Spysweeper loads the host file with references to the local host as a blocking tactic.

    I was able to remove the virus indicated by Panda, as you suggested, by disabling the "Common Ad Sites" shield of SpySweeper. As a test, I was able to reverse the process by enabling the "Common Ad Sites Shield".

    Presently, I left the "Common Ad Site" shield on. (Zip file of Host attached)

    I believe that this OK even though Panda reports the host file as infected?
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Does it still show in the Panda log?
     
  11. Helper

    Helper Private E-2

    Panda indicates an infection when I activate the "Common Ad Sites Shield" in SpySweeper. (Panda Logfile attached)

    Panda shows no infection if I turn off the "Common Ad Shield" in SpySweeper" and run Hoster. Hoster removes all the files with the SpySweeper reference. I also rebooted the computer to make sure the Host file remained the same.

    The attached Host file is with the SpySweeper "Common Ads Shield" activated.
     
  12. Helper

    Helper Private E-2

    I don't think the files from the previous note were attached....

    I am getting this error when I try to attach the files,"You have already attached this file in thread ". (I even renamed the files) Since it is a small file here they are:

    Panda
    Adware:adware/secure32 Not disinfected C:\WINDOWS\system32\drivers\etc\hosts

    The host file looks like the one I previously attached.
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Exit Spy Sweeper completely, then run HOSTER as requested in post #4. This will take care of the Panda detection. Spy Sweeper is locking the HOSTS file not allowing anything to be written or modified in any way.

    After you exit Spy Sweeper and then run HOSTER it will take care of this Panda detection.
     
  14. Helper

    Helper Private E-2

    Yes, what you said is true. I have already tried this experiment. Turning off Spysweeper unlocks the Host file and allows Hoster to change the file. At this point Panda shows no infections. (Problem solved)

    If you look at the present Host file (SpySweeper on) it appears that SpySweeper inserts commonly known Hijacked IP addresses and diverts them to the local host file (127.0.0.1) so that they are ignored. In my uninformed opinion, it appears that Panda is giving a false positive when SpySweeper alters the Host file.

    Thanks again for sticking with this. This is a very informative site; I've learned a lot reading the sticky's. You guys are doing a great service....
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    What version of Spy Sweeper do you have? Spy Sweeper does not alter the HOSTS file, it protects it from being modified in any way. Under the HOSTS file shield, you should only have "Hosts File Shiled" enabled, nothing else.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have already covered this a few times BJ. Yes Spy Sweeper is modifying the HOSTS file and yes Panda and some others are declaring false positives on the locked hosts files.
     
  17. Helper

    Helper Private E-2

    I have version 4.5.7 (Build 656)

    Under the heading of Host File Shield in Spysweeper. I have 3 boxes to check, (i) Common Ads Shield, (ii) Hosts File Shield, and (iii) Edit Hosts File. The box (ii) Common Ads Shield is the culprit. When this box is checked, Panda shows an infection in the Host file.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because as I said in the below message Spy Sweeper adds info like the below to the hosts file.

    127.0.0.1 1.httpdads.com #SpySweeperCASS
    127.0.0.1 207-87-18-203.wsmg.digex.net #SpySweeperCASS
    127.0.0.1 a.mktw.net #SpySweeperCASS
    127.0.0.1 a.tribalfusion.com #SpySweeperCASS
     
  19. Helper

    Helper Private E-2

    Ok, it sounds like I'm all set.

    Thank you BJ and Chaslang for all of your help and sticking with this.

    I'm am now much more knowledgeable on the subject of Spyware.....
     
  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds