Malware Problems - Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by rangeno, Sep 4, 2007.

  1. rangeno

    rangeno Private First Class

    I started having problems with my computer yesterday. Getting popup trying to redirect me to some funky website. Also, running slow, and occasionaly crashing.

    I followed the instructions per The Malware Removal Guide and have attached the files. I could not run CounterSpy as I kept getting the message "The system administrator has set policies to prevent this installation". I tried it under my user name as well as the admin username. In any event I was able to get AVG to do the scan.

    Any help would be greatly appreciated.
     

    Attached Files:

  2. rangeno

    rangeno Private First Class

    Here are the rest of the files you requested.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs do not show any signs of malware.
    • Exactly when do you get these popups?
      • Is it only when a browser is opened?
      • Is it only when connected to certain websites?
    • What exactly do they say? What site is it?
    Slow PCs and crashes are more often due to software that you are running and problems with in the OS. However just to be on the safe side, let's do two scans for rootkits:

    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.


    The run this Using Sophos Anti-Rootkit and attach the log.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note you should uninstall the below old version of Sun Java since you already have the current version installed:

    Java(TM) SE Runtime Environment 6 Update 1
     
  5. rangeno

    rangeno Private First Class

    I get the popups randomly but when it happens I'm usually in Yahoo either receiving or composing mail. I believe the the message has the word Akamai first and then it mentions another website and that one is just random letters it's not a word and doesn't make sense. Also, I din't mention that my computer won't shutdown normally. I try the start turn off computer and it just hangs. If I want to shut it off I have to hold down the power button. Here are the logs you asked for.
     

    Attached Files:

  6. rangeno

    rangeno Private First Class

    Also, just a little while ago I was checking out other posts here and i clicked on the one "Purityscan Removal" and a picture of an HP Printer came up.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This too is more than likely not related to malware.

    Those other two logs were also clean.

    As far as the popups are concerned!
    1. You are saying that they only occur only when connected to the internet and when browsing is that correct? Do they ever occur when no browser is opened?
    2. Which broswer are you using?
    3. Do you get popups if you boot in safe mode and connect to the internet (assuming you can connect in safe mode)?
    Now let's try a few additional things to see if they help with the popups.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger.


    Let's Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Also try this, Go to Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Are popup's still occurring? If so how often and track what sites you are connected to when they occur.
     
  8. rangeno

    rangeno Private First Class

    They do only come up when connected to the internet and I'm browsing. They do not occur if there is not an open browser. I didn't get them when I was in safe mode with networking during the malware removal procedures. I haven't had opoups in a while but I will keep track of them. Thanks.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer which browser you are using.

    Also did you complete the other steps I gave you?
     
  10. rangeno

    rangeno Private First Class

    I use Firefox and Explorer. I only use Explorer to access a Seibel application. I did use explorer for the malware removal. I did complete the other steps.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: Explorer is not the same as Internet Explorer. Explorer ,means Windows Explorer.

    But my question is what browser are you using when the popups occur? Or do they occur when either browser is open? When the popup comes up, which browser opens?

    Are you still getting popups? If so, how often?
     
  12. rangeno

    rangeno Private First Class

    Sorry. I meant Internet Explorer. I got the message that was trying to redirect me to Akamai/Other site on both Internet Explorer and Firefox. The other popups happened only with Firefox. I haven't gotten any in few hours now.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure this is a browser popup? Can you post a snapshot of this when it occurs again?
     
  14. rangeno

    rangeno Private First Class

    There have been different kinds of popups...some have been things like "your computer is infected and you need to download X" and they only come up on Firefox but the redirect one Akamai (view certificate) redirect comes up on Internet Explorer and Firefox.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please only tell me about ones that are still occurring. Also attach a snapshot.
     
  16. rangeno

    rangeno Private First Class

    I will. Nothing has happened now for sometime. Thank you.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then in the meantime I suggest you get started on the below. You need to do all steps and make sure you get a firewall installed.
     
  18. rangeno

    rangeno Private First Class

    Would you recommend I download Version 2.1 or the Beta Version 3.0? Also, I have a wireless router (Linksys) and I was told that has a Firewall.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I forgot to post the link I wanted you to get started on. Here it is: How to Protect yourself from malware!

    For what program?

    Yes that is a hardware firewall. You still need a software firewall as mentioned in the above link.
     
  20. rangeno

    rangeno Private First Class

    There was an ad at the bottom of your previous post for a free firewall. Good thing I asked what version.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is! ;) Adding the software firewall could even help prevent some of these popups if the are coming from the internet towards you.
     
  22. rangeno

    rangeno Private First Class

    I haven't gotten this in a while but here is a word document that has the weird popup I've was getting.
     
    Last edited: Sep 11, 2007
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are better off taking screen snapshots and saving them in JPG form. You can compress and/or crop these images to make them small enough to upload. Word docs will always be way too large. To do this, I use utilities like: FastStone Capture 5.6 and FastStone Photo Resizer 2.4, you can find them here: http://www.faststone.org/

    We do have the second program on Major Geeks too: FastStone Photo Resizer
     
  24. rangeno

    rangeno Private First Class

    I don't have the screen capture and all I have is the word document. Here's what the popup says:

    Security Error: Domain Name Mismatch


    You have attempted to establish a connection with "rmd.atdmt.com". However, the security certificate presented belongs to "a248.e.akamai.net". It is possible, though unlikely, that someone may be trying to intercept your communication with this web site.

    If you suspect the certificate shown does not belong to "rmd.atdmt.com", please cancel the connection and notify the site administrator.

    View Certificate OK Cancel
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  26. rangeno

    rangeno Private First Class

    Thank you for your help!
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds