Internet Security 2010, is it a virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by happycmpr46, Dec 16, 2009.

  1. happycmpr46

    happycmpr46 Private E-2

    I was minding my own business yesterday as I was playing on my computer then, wham!, this popup came up, it said Internet Security 2010 you have a virus, it showed all these files that it had found, I never downloaded a virus program so I know its not mine, I think the kids were using my computer! Damn I hate when this happens, well anyways it put this annoying wallpaper on my computer stating that it has shut down all major programs until I get rid of the virus or use the internet security 2010 scan, I cant even change my wallpaper with the Display Properties, can anyone tell me if this is a virus? what a dumb question huh? I know its a virus, so I guess I am going to have to go through all the steps, DAMN DAMN DAMN i havent had to do this in a longgggggggg time and im rusty, well can anyone tell me if they have had the same virus? and was it hard to get rid of? Happy Holidays Everyone!!!!
     
  2. happycmpr46

    happycmpr46 Private E-2

    My computer is going wacky!

    Ok I posted a thread a couple of days ago regarding internet security 2010 and was wondering if it was a virus, I received no replies, so I am guessing now that it was a virus because I can't open some of my programs, and when I triy to view a website, like nzb o matic, it totally directs me to an off the wall website like yellowpages, or a diet site ect.


    has anyone else had this problem? OMG how in the hell did I get it?
     
  3. happycmpr46

    happycmpr46 Private E-2

    Re: My computer is going wacky!

    I scanned my computer and I am posting the results hopefully someone can tell me whats going on. I did notice that my superantispyware didnt find anything so I didnt post a log for that.

    thank you
     

    Attached Files:

  4. happycmpr46

    happycmpr46 Private E-2

    Please Help Me!!!!!

    :cry
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to read the sticky threads. Like this: Don't Bump! It Only Hurts You!!! Everytime you add another message, you bump your thread and lose your place in the cue. This last post cost you 2 to 3 days more waiting time.

    You need to always attach the logs from each program whether anything is found or not. This was stated in the instructions. It is how we know you are using the current versions of programs.

    ComboFix is back online now. Please run it and attach the log.

    Your Malwarebytes log shows you took no action. Did you fix what it found? You need to fix before saving the log.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And note that recent scans from SUPERAntiSpyware did find something. The below logs need to be attached.
    Code:
    "C:\Documents and Settings\cheryl carney\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Dec 16 2009        2326  "SUPERAntiSpyware Scan Log - 12-16-2009 - 15-59-19.log"
    Dec 18 2009        1675  "SUPERAntiSpyware Scan Log - 12-18-2009 - 09-37-49.log"
    Also do the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the two SUPERAntiSpyware logs
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 21, 2009
  7. happycmpr46

    happycmpr46 Private E-2

    Ok did everything that you suggested, and I am attaching the necessary files, I ran the MGTools last so I hope thats what you wanted me to do. Please let me know if anything is wrong, you guys are great!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay ComboFix found and remove a rootkit type infection. What problems are you still having?
     
  9. happycmpr46

    happycmpr46 Private E-2

    Everything seems to be working fine now, did it look like anything was left on computer after my final scan with MGTools? and how do you get a rootkit infection? can you get it from a website like myspace? Just curious because i noticed that my daughters laptop seems to be having the same problem and she uses my computer and her computer to go on myspace. Looks like I will be scanning her computer also. Thank you for all you do and Merry Christmas to you and your family!!!!!!



    cheryl
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Merry Christmas to you to.

    Thre are many possible ways to get these infections so it is not easy to say how or where it came from. The easiest thing to say is that some one using the PC downloaded or installed something or access a webpage that really should not be accessed. Yes MySpace, FaceBook.....etc can all be problems but that does not mean the infection came from there. Many people use these sites without getting infected, but many people do get infected. I had to fix my daughters laptop use for college studies a few weeks back because she simply downloaded some pictures from FaceBook or MySpace (...I forget which one).

    We have a little more to do.

    You really need to stop using MSconfig to control startups as explained in step 4 of the READ & RUN ME.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O8 - Extra context menu item: &Search - ?p=ZCman000
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MT...ngCode=&subcatId=2277&pers=&tm=969&expId=6204

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. happycmpr46

    happycmpr46 Private E-2

    Ok I did all the necessary steps u requested but I have a question before I post the attachments. First off should I have had the startup set as normal before I did all the scans? and second I had MGTools loaded before and I just used the previous program, should I have done that? well if I did anything wrong let me know and I will start all over, so now I will post the scan results. Oh and the MGlogs zip I hope is updated to 2days scan I noticed that when I right click on the zip and go to properties it shows a 2005 created date and an 2009 accessed date. did I do that right? man I feel so incompetent LOL


    Oh and things seem to be running fine. Let me know if you find anything else, now that I know what to do I can do my daughters computer. Thank you again!!!!!
     

    Attached Files:

    Last edited: Dec 27, 2009
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should ALWAYS be in normal startup mode unless you are debugging a particular problem. This was stated in the READ & RUN ME when you first ran it (see step 4). You still were not in normal startup mode when you ran GetLogs.bat meaning you did not complete instructions in the order given.

    Howerer your logs are clean. You just need to stop using MSconfig.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds