Please help with malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by mole3691, Nov 29, 2008.

  1. mole3691

    mole3691 Private E-2

    I have a pop up notification that comes up every 15 minutes from Windows XP Security Center asking if I wanted to block a suspicious malware called Spyware.ISpynow. When I open up Mozilla Firefox, I was directed to a homepage stating "insecure connection, threat of virus attack" with two options, one to continue unsecured in which I would get to google (my start page) and the other would direct me to website for perfect defender 2009 which is obviously not a legit Microsoft website. I have looked around other forums and I see other people with similar problems, but no solutions. Can anyone help?

    Here are my logs from Malware removal guide:
     

    Attached Files:

  2. mole3691

    mole3691 Private E-2

    and the last one...
     

    Attached Files:

  3. mole3691

    mole3691 Private E-2

    SandraS: Insecure Internet Activity

    I tried to respond to the post by SandraS but for some reason i wasn't able to because I don't have permission or something. I have the same problem and I navigated through folders and found the same files that showed up on SandraS's Malwarebytes log. I tried to delete them but it says access denied. How can I work around that and delete the files?
     
  4. mole3691

    mole3691 Private E-2

    Re: SandraS: Insecure Internet Activity

    SandraS, thanks for the reply to my post. Luckily I saw your post, too.:) It is pretty weird that you can't reply to any threads in this forum, but whatever.

    I did run the "Sticky: READ & RUN ME FIRST. Malware Removal Guide" like I have in the past (unfortunately this is not my first time using this guide). It did detect some of the malware on my computer, but not the Trojan.FakeAlert that you had, too. I ran Malwarebytes again and it did find more malware, but the Trojan.FakeAlert did not show up. I know the exact location of the problem, but for some reason I cannot delete the files because it says "access denied" whenever I try to do so. I think I'm going to run the scans a few more times and see what happens. What scans did you try a few times and what settings did you change (if you can remember)?

    I'll post again if I can finally get rid of this thing, and thanks for all of your help.
     
  5. mole3691

    mole3691 Private E-2

    Re: SandraS: Insecure Internet Activity

    FINALLY, I got it. :celebrate I guess I didn't have the updated version of Malwarebytes. I thought i updated last night, but i guess not. Here's my log:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of date with your MBAM version. Please update and scan again and attach the new log.

    The same is true for SUPERAntiSpyware but for it you will need to uninstall it. Then download and install the version given in the READ & RUN ME. Then update it once installed and run a new scan. Attach the new log.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh I see you started a new thread here: http://forums.majorgeeks.com/showthread.php?t=175413

    I will merge this thread back here with your first thread in a minute. You don't need to run MBAM again since you already updated it and attach the log in the other thread.

    You really need to remain in one thread for your problems. You cannot post in another users threads and they cannot post in yours.
     
  8. mole3691

    mole3691 Private E-2

    Sorry about that I thought that I updated it last night, but I guess not. I'll attach the log from earlier today, using the updated version. I think the new version got it, but I just want to make sure everything is alright. Thanks for all of your help. I really appreciate it.

    I also have another log from last night using the out of date version for the second time. I'll attach that too just in case.
     

    Attached Files:

  9. mole3691

    mole3691 Private E-2

    Oh and sorry about the 2 threads. I didn't want to bump this one to the top and have to wait longer.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I merged your other thread here now. The messages will seem out of order. They are messages # 3,4 & 5 in this thread.

    You need to do what I requested with SUPERAntiSpyware.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would have to wait just as long if not longer for the new one to be answered. ;)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java(TM) 6 Update 6
    Java(TM) 6 Update 7

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [HPseti] "C:\Documents and Settings\Mike\Application Data\Google\runhh6110411.exe"

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    • and don't forget the new SUPERAntiSpyware log requested in my other message.
    Make sure you tell me how things are working now!
     
  13. mole3691

    mole3691 Private E-2

    I'll follow through with your last post and post back when I'm done. Here's the SuperAntiSpyware log that you requested:

    It said that no threats were found.
     

    Attached Files:

  14. mole3691

    mole3691 Private E-2

    Ok, I'm back and I completed all of your directions and the logs are attached. The only line I couldn't find while running C:\MGtools\analyse.exe was O4 - HKCU\..\Run: [HPseti] "C:\Documents and Settings\Mike\Application Data\Google\runhh6110411.exe". I'm guessing this was apart of the Trojan.FakeAlert that was found and removed by Malwarebyes, but I'm not sure.:confused I'll let you answer that since you're the expert. ;)

    Overall, everything seems to be working well. Thanks for everything and I'll definitely be back here if I have anymore problems in the future.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your logs are clean, but now you need to do final steps and get your PC properly protected as you have none.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds