Malware - windows security alerts?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jpellitt, Jul 4, 2008.

  1. Jpellitt

    Jpellitt Private E-2

    Hi - I hope I'm posting in the right place, there is so much information that it's easy to get confused. I apologize if I'm missing a bright red 16 point title saying "Don't Do..." exactly what I'm doing, but here goes.

    Have got some nasty malware - started by hijacking my browser, and now is sitting on my toolbar and annoyingly popping up the "want to get rid of spyware" message every few minutes. It's titled "windows security alerts".

    I've worked my way through the "how to clean Windows XP" - SuperAntispyware, spybot, malwarebytes, combofix, mgtols. I did the regular PC maintainence as well. It looks like the spyware is hamstrung, in that it isn't changing my home page and I have my task manager back, but it still lives on my tool bar.

    I'm attaching all the logs I think I'm supposed to.

    Thanks for any help!
    John
     

    Attached Files:

  2. thesmokingun

    thesmokingun MajorGeek

    there should be 4 logs...but you should also post in the malware forum so those pros can get to this message and help ya, but maybe an admin will move this thread...good luck. and welcome!
     
  3. AbbySue

    AbbySue MajorGeeks Administrator

    Wecome to MajorGeeks Jpellitt!:cool

    Moved your thread to the Malware forum so you can get some help.

    Good luck getting it resolved!

    AbbySue
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Do you have the log from running Malwarebytes Anti-Malware? Please attach it.

    Then uninstall the below as requested in step 1 of the READ & RUN ME.
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player

    Your logs are pretty clean now. I just have some minor things to I will give further down. Are you still having problems?

    I do see that you have no protection software installed which is not a good idea.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Jpellitt

    Jpellitt Private E-2

    Sorry for the delay - had some trouble with my internet connection, and then a short trip. I can't seem to find the Malwarebytes anti-malware log...I get a "you already uploaded" message if I try to upload Mclogs.zip.

    Where are we talking about insofar as the "Read and Run Me"?

    I don't seem to be having any more trouble at this time, so I think I'm good. I've made myself a "Virus Cleaning Notebook" of printouts of all the things to do, so I'll follow all that next time.

    Thanks for your help! Antyhing else I can do to make the comp run better? I've run the malwarebytes....it's telling me I'm clean...
    John
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means you are trying to upload the same log as previously uploaded which means you did not follow my instructions and run C:\MGtools\GetLogs.bat first.

    What are you referring to? The line where I was saying to remove the uninstall those programs. If yes, that was all in Step 1 of the READ & RUN ME. There as a link to uninstall malware and also a set of instructions on uninstalling all old Java versions and updating to the current version.

    If you have uninstalled all of those, then we are finished.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. Jpellitt

    Jpellitt Private E-2

    >>Chaslang said:
    "That means you are trying to upload the same log as previously uploaded which means you did not follow my instructions and run C:\MGtools\GetLogs.bat first."<<

    No, what it means is that I didn't understand what your instructions were. I certainly appreciate the help with all of this; please remember that for someone who deals with this only sporadically that the bold, Colored, and other text can be overwhelming.

    >>Chaslang said:
    What are you referring to? The line where I was saying to remove the uninstall those programs. If yes, that was all in Step 1 of the READ & RUN ME. There as a link to uninstall malware and also a set of instructions on uninstalling all old Java versions and updating to the current version.<<

    I am referring to your direction to

    "Then uninstall the below as requested in step 1 of the READ & RUN ME."

    Step 1 of Read & Run Me...is...a step in WHICH of the 7 or 8 processes I've gone through? I've worked through probably 30 "Steps" so telling me to go to step 1 is useless. You might be thinking that it is so obvious it doesn't need to be stated? It's not.

    You say "There as a link to uninstall malware" - you mean "is" right? I will go back to the original forum thread under malware and look for uninstalling Java versions...maybe that's where you mean.

    I'll re-read all your posts and see if I can catch up to where you are at.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry that you are having a problem with this but then I need to ask what is it about the below that you have a problem understanding or doing.
    Do you require more detailed instructions on exactly how to find the GetLogs.bat file so that you can double click on it>


    by READ & RUN ME, I'm referring to this link: READ & RUN ME FIRST. Malware Removal Guide which is the main body and start of the instructions for removing malware. It was where you were to begin and what we assume you had started with since your first message below attach logs which are the result of working thru the above link and then on to the actual specific cleaning instructions for your version of Windows. Is this or is this not where you began?




    If you click the above blue underlined link, you will see that step 1 is the below:
    The first bullet list item contains the uninstall link.
    The second bullet list item contains the instructions on uninstalling old Sun Java versions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds