System Security Warning

Discussion in 'Malware Help (A Specialist Will Reply)' started by afstcklnd, Apr 12, 2008.

  1. afstcklnd

    afstcklnd Private E-2

    Got what seems to be a common issue at the moment - "Blue" or "Red" security warnings with warning triangles popping up in the task bar.

    Anyway, had a link which seemed to come from a friend and McAfee seemed to deal with the virus threat but obviously has a hole as I now have these warnings appearing. Tried to clean with Uniblue, PC Tools and Kaspsersky but not sorted. Then ran ComboFix which cleared up a lot but still an ongoing issue - attached is last ComboFix log (sorry, overwrote the others).

    BTW: had the 'cannot rename' issue but got around this by saving the file as a new name on the download rather than after :)

    Any ideas?

    :drool
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. Since you already ran ComboFix (even though out of order) you can skip running it, but you need to do the rest of the instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. afstcklnd

    afstcklnd Private E-2

    Hi,

    Thanks for that - picked up quite a few things that other scans had missed. I'm not sure if I'm clean though.

    The pop ups seem to have stopped but having reactivated Spyware Doctor, it's finding three infections (which it calls)...

    Application.TrackingCookies - inane
    Application.NirCmd - may be OK but don't know why it's there
    Tojan.Generic - low risk but surely should not be there after all those scans

    Anyway, felt it best to attach the logs and have an expert check - please :)

    NB: Attachments playing up so will upload MGTools.zip on another post.

    Thanks
    Andrew
     

    Attached Files:

  4. afstcklnd

    afstcklnd Private E-2

    Interesting, I can't upload the MGLogs.zip from either the previously (or still) infected computer nor a different one. The forum site times out - any suggestions? Do you want the logs individually?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the Malwarebytes log too! Also try attach the C:\MGlogs.zip file again. If still having a problem, try a different browser. Spyware Doctor is not finding valid problems. Cookies are not problems and nircmd is a valid program used by many tools including ComboFix. Not sure what Trojan.Generic is supposed to be. That is insufficient info to go on. Is your copy of Spyware Doctor a paid version? Or the free version that does not fix anything? If free, uninstall it as it is a waste of resources.
     
  6. afstcklnd

    afstcklnd Private E-2

    OK, the zip file won't load from IE or Firefox - both 'time out'. So, attached are a couple of the individual logs - others to follow.
     

    Attached Files:

  7. afstcklnd

    afstcklnd Private E-2

    and here's the last ones
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs it appears that the scanners have removed your malware problems.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Are you still having malware problems?
     
  9. afstcklnd

    afstcklnd Private E-2

    Success!

    There are a few strange things still happening but I suspicious of a faulty graphics system on some of them.

    1. Sometimes, the screen dows not draw properly, or parts of a particular program GUI are missing.

    2. RTHDCPL (RealTek Control Panel) keeps starting up seperate instances.

    Thanks for your help!!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry, but none of the above are malware problems. You need to post these in the Software or Hardware Forums (whichever seems more appropriate).


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  11. afstcklnd

    afstcklnd Private E-2

    Hi,

    Thanks for all the help - looking good :)

    One final thing...

    While removing ComboFix, Spyware Doctor intercepted and blocked a couple of executables (pv... & nircmd...) and reported a trojan (which I did not manage to catch the name of). I'm assuming that these are actually valid parts of ComboFix. However, it means that the uninstall didn't run properly - and now the install module has been removed.

    Do I need to reinstall and remove again?

    All the best
    Andrew
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes they are part of ComboFix and are legit. Spyware Doctor is incorrect.

    Spyware Doctor may or may not have removed the files on the fly or ComboFix may have still remove them. I would not worry about it as it does not hurt if they are left behind and if they were left behind, a full scan by Spyware Doctor may again falsely say they are problems.
     
  13. afstcklnd

    afstcklnd Private E-2

    Hi,

    Thanks again - one final (maybe) question...

    Whilst it is better to err on the side of caution, does the fact that Spyware Doctor is picking up these items give cause for concern? It is one of your 'recomended' tools but if it's inaccurate should I be using it?

    All the best
    Andrew
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many scanners have false positive issues. Sometimes it is a matter of how you interprete the results of the scans. Sometimes they are not telling you that a progam or a setting is malware. They may just be telling you that it is a potentially unwanted or undesirable program or setting and that you need to check if you are the one who installed the program or made the setting. This happpens due to the nature of what certain programs can be used for. For example programs like WinVNC can often be flagged as a potential problem but it is not malware. You just have to know whether a user knowingly installed the program and uses it or was it installed by someone else with malicious intent.
     
  15. afstcklnd

    afstcklnd Private E-2

    Hi,

    Yes, I understand that reports are often warnings of potentially unwanted but in this instance these were actively blocked.

    In any case, I feel you have answered the underlying question and I'll stick with what I've got.

    Thanks
    Andrew
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes sometimes the tools do decide automatically for you too and they are not always correct.


    You're welcome. Surf Safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds