Fake Spyware Warnings

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by charley, Sep 7, 2008.

  1. charley

    charley Private E-2

    I'm getting the Fake Spyware Warnings that claim to be coming from the windows firewall which I don't use. I use AVG8.0. I did a stupid thing. I accidentally allowed some site to update my Flash player.
    The spyware it claims to have detected varies:

    Trojan-Spy.win32.KeyLogger.aa
    or:
    Trojan-Spy.HTML.Bankfraud.dg
    and others.

    If I click on the enable protection button in the pop-up it takes me to:

    www.antispyware-review.info/pwmid

    I have run all the windows XP cleaning scans. Logs are attached.
     

    Attached Files:

  2. charley

    charley Private E-2

    And the MGlogs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have multiple antivirus and antispyware protection programs installed and you must not do this as stated in the READ & RUN ME. You need either uninstall AVG8 or CounterSpy immediately. AVG8 also already contains AVG's antispyware program so you also no longer need AVG AntiSpyware 7.5.


    You also have leftovers from Symantec. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [InfoApl] C:\WINDOWS\system32\sjwbknwn.exe
    O4 - HKCU\..\Run: [infowin] C:\WINDOWS\system32\ixubyxkn.exe
    O4 - HKCU\..\Run: [msgui] C:\WINDOWS\system32\jsxyrqzg.exe
    O4 - HKLM\..\Policies\Explorer\Run: [snJCzsQSj9] C:\Documents and Settings\All Users\Application Data\arqlclmr\gduvanmh.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. charley

    charley Private E-2

    Thanks for all the help!

    Even though I had counterspy installed, I had it's active protection disabled and was doing a weekly scan with it just to check for anything that was getting past AVG. I went ahead and uninstalled it anyway.

    I performed all the steps as you directed. All appeared to be successful. I'm still getting the fake spyware popups. I'm also now now getting a new popup that says "navagation to webpage was canceled" or something like that. I'll try to get a screen capture of it.

    The requested logs are attached.
     

    Attached Files:

  5. charley

    charley Private E-2

    I don't know how to capture the new popup I'm getting. In the title bar it says "Windows Security Alert" then in the body of the popup it says:

    i Navagation to the webpage was canceled

    What you can try:

    Refresh the page.

    This pops up even when I don't have a Browser open.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not quite work like you think. All of the services and registry entries were still in place and present problems for the other program. It is simple, never install more than one period. ;)

    That's because the infection spread before running my last fix. Hopefully you have not rebooted since last attaching the current logs as reboots can cause malware to mutate and/or spread. Let's see if we can get the rest of it this time.



    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now doubleclick the fixme.reg file same to your desktop last time and allow it to be added to your registry again.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. charley

    charley Private E-2

    OOPS! An automatic update came in last night and did a reboot. I'm changing the settings to the "download and let me install" option so that won't happen again.

    I did everything as you instructed. When combofix reboots it hangs in the normal "windows is shutting down" screen. After about 20 min. I went ahead and hit the restart button and it appeared to complete OK. Everything else appeared to run ok. Shortly after the reboot AVG resident shield picked up a Trojan of some sort and I instructed it to move it to the vault. I've also gotten a couple more of the fake spyware popups.

    I'm sure we'll have to do this another time because of last nights reboot.

    The logs are attached.

    Thanks for the help.

    Charley
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure about this? Your logs are all clean. Make sure that you are not getting fooled by AVG pointing to things in quarantine folders, or to ComboFix or to things in System Volume Information which is just System Restore.
     
  9. charley

    charley Private E-2

    I'm pretty sure it was after I ran combofix. but maybe not the rest. I haven't gotten any tonight

    I got those too but I knew they were okay. My AVG is acting up now. If I bring up the UI screen, it just hangs and won't respond. I have to stop the process with the task manager. AVG appears to be running OK but since the UI won't respond I can't change any settings. The firewall popups seem to be working and responding properly. A system reboot will probably fix it ,but I didn't want to do one till we're sure my system is clean. I guess it's okay to do one now.

    I'm not to happy with the AVG firewall user interface, it's too confusing and complicated. I'm thinking of dumping it and getting Outpost or comodo.

    Should I reset my system restore now?

    Thanks for all the help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems with AVG may or may not be fixed by uninstalling, rebooting and then reinstalling. You would be better off continuing any discussion about problems with it in the Software Forum or at Grisoft's Forum.


    Since your logs are clean, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds