Security Toolbar 7.1 - help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by bodders, Apr 14, 2008.

  1. bodders

    bodders Private E-2

    Hallo peeps! Unfortunately last week my elderly father somehow installed the security toolbar 7.1. This resulted in the toolbar appearing in IE, a flashing yellow triangle in the task bar and lots of links to Security Sites appearing on the computer. NIGHTMARE!!! :confused I found and followed the instructions found for XP in the thread http://forums.majorgeeks.com/showthread.php?t=35407 and this seems to have sorted all visible problems of the infection, CHEERS GUYS! :major I would appreciate it if someone could check out the log files which were created during this procedure just to make sure all is well. Thank you!!

    (Can only attach 3 at a time - fourth in next post! Cheers)
     

    Attached Files:

  2. bodders

    bodders Private E-2

    Heres the last log file .....
     

    Attached Files:

  3. abri

    abri MajorGeek

    Hi bodders,
    Welcome to Major Geeks!


    I don't see anything further in your logs. You should let your system run for a few days before you uninstall all the tools and logs we had you install. If you find the infection starting up again, you will need to run the following tool, but don't run it unless you need to. In the process of removing the malware it also removes any desktop settings you may have set up, so it's useful to only use it when needed.

    Removing Zlob aka SmitFraud, SpySheriff, Infections.


    I'll post the final removal instructions in a box below for you to come back to in a few days if your computer is working as it should, but before I do there are a couple of neatnick things you can do:

    1) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger

    2) Next go to the C:\MGTools folder and find the file called analyse.exe. Double click on this and when it opens click on the button to have it Run a System Scan. It will show you all the HijackThis entries in a window. Click on the following entries and after you close all your browser windows, click on FIX.

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

    After you click fix, just close hijackthis.

    3) After youi finish browsing, run CCleaner at the default setting with the Windows tab as the top one. Try to use this regularly as many forms of malware keep a wakeup file in the temp files and this helps to get rid of them.

    abri
     
  4. bodders

    bodders Private E-2

    Hi Abri

    Wow thanks for such a quick and informative response! Thanks for checking through everything, really appreciated! :) I ran through everything you suggested and also used the SmitFraudFix method just to be sure. System seems fine now, cant thank you or the major geek guides enough!!!
     
  5. abri

    abri MajorGeek

    Hi bodders,

    Thanks for your praise. Glad things went well.
    All the best to you.

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds