Fake Virus Alerts

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bruce1981, Aug 7, 2008.

  1. Bruce1981

    Bruce1981 Private E-2

    Hi,

    My laptop got infected with various fake alert type trojans two nights ago. The problems caused were various pop ups saying I was infected and to download removal software. It also changed the start menu settings by removing a lot of the icons, added a toolbar to internet explorer and had a virus alert beside the time.

    I've run the read and run me guide and attached the logs. It seems to have removed everything and returned the settings back to normal.

    Please can you review the logs to confirm everything has been removed.

    Thanks,

    Bruce.
     

    Attached Files:

  2. Bruce1981

    Bruce1981 Private E-2

    MGlog
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. You just need to do the below to finish things off.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. Bruce1981

    Bruce1981 Private E-2

    The fixme.reg ran fine and came up with a success message and i've carried out the other steps.

    Thanks for your help.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  6. Bruce1981

    Bruce1981 Private E-2

    Hi,

    Thought everything was ok but I'm having a problem with yahoo being redirected to a google search page with "Sorry, we couldn't find http://ad.yieldmanager.com/st%3Fad_type"

    Is there any sign of this in the logs I posted previously or should I run the scans again?

    Thanks,

    Bruce.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall this URL Assistant and then reboot your PC. Tell me if you are still having problems.
     
  8. Bruce1981

    Bruce1981 Private E-2

    Hi,

    That seems to have solved the problem. Some of the adds on yahoo don't come up now but thats ok.

    Is there anything else connected with ad.yieldmanager that I should check for or is that it?

    Thanks,

    Bruce.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that's because you are blocking them. ;)

    No. It is not malware. It is just ads on websites you are accessing and cookies related to them. When you block them, the URL Assistant program that Dell forced on you, redirected you to another location because the ads were being blocked. If you want to see the ads, you will have to stop blocking the ads.yieldmanager.com site.
     
  10. Bruce1981

    Bruce1981 Private E-2

    lol didn't know I was now blocking them!

    Thanks again for your help.

    Bruce.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds