The Computer Security Tool ?

Discussion in 'Malware Help (A Specialist Will Reply)' started by crimsnkentucky, Dec 17, 2005.

  1. crimsnkentucky

    crimsnkentucky Private E-2

    I have The Computer Security Tool downloaded from this site on my computer and it is showing that I have 22 securtiy risk that are high or medium risk. I have used Counter Spy, Smart Fix, Prevex, AVG, Zonelab, Keiro, and McAffe and they find nothing. Has anyone used this software and do you think these are real risk. The freeware version will not correct medium to high risk and I don't want to pay if the problems are not real. Anyone with info that can help would be appreciated. It does not tell you what the risk are so that you can make a decision.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Can you provide any information on the found risk?
     
  3. crimsnkentucky

    crimsnkentucky Private E-2

    No, It just says high risk two, moderate 20. It gives no other information.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just to be sure you have no infection...

    Please see the below thread on how to install and run Spy Sweeper.

    Running Spy Sweeper...
     
  5. crimsnkentucky

    crimsnkentucky Private E-2

    I can not load Spy Sweeper because I have tested demoed it before and the trial period has expired. Attached is my High Jack This file.

    Thanks!
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  7. crimsnkentucky

    crimsnkentucky Private E-2

    Holy Smoke Batman, that program found like 600 infections that nothing else found. I had to break it down into two seccions because my wife wanted me to turn off the computer for bed. Anyway, here are the Ewido reports and the HighJAck THis report.

    Thanks!
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Ewido

    Spy Sweeper

    SmartFix


    Kerio Personal Firewall OR ZoneAlarm
    (Running more than one will cause conflicts)

    AVG AntiVirus OR McAfee AntiVirus

    (Running more than one will cause conflicts)

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.

    Now, look in Task Manager (Ctrl-Alt-Del) for the following running processes and, if you see any of them, try to END them:

    firewall.exe

    FIREFOX.EXE


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaults/*http://my.yahoo.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:4001
    (Keep this if you need it)

    O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINDOWS\Downloaded Program Files\SbCIe02a.dll (file missing)

    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
    O3 - Toolbar: UCmore - The Search Accelerator Toolbar - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [FireWall] "C:\Program Files\SmartFix\firewall.exe"

    O13 - WWW Prefix: http://www.anonymization.net/http://

    O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
    O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
    O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
    O16 - DPF: {7B656808-A402-4108-9CDC-0E08E26A2A24} (ContentCleanup2X Control) - http://a840.g.akamai.net/7/840/5805/v1000/www.contentwatch.com/cleanup/includes/ ContentCleanup2Proj1.cab
    O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs1b.instantservice.com/jars/customerxsigned33.cab
    O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/v1000/www.contentwatch.com/audit/includes/Co ntentAuditControl.cab

    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe (file missing)
    O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\Prevx Home\PXAgent.exe" -f (file missing)

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    C:\Program Files\SmartFix ←–– Delete this whole folder if it exist!

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds