www.perfectedsecurity.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ghartman, Apr 17, 2006.

  1. Ghartman

    Ghartman Private E-2

    Hello guys.I read through your MALWARE READ & RUN ME FIRST sticky and followed your whole thread to the letter (except for Panda ActiveScan which kept telling me there was an Activex problem).I too have been infected with the www.perfectedsecurity.com virus/trojan.I got it last Thursday while downloading a file.I searched the net for fixes and found yours to be the most comprehensive.Please find attached my Bitdefender and Hijackthis files and please see if you can help.As you know it has hijacked my browser and seems particularly agressive.P.S Sorry for re-posting but I tried to make this a reply in a similar thread but was told I would not be able to.Thank you.
     

    Attached Files:

  2. Ghartman

    Ghartman Private E-2

    Just to add,I run Spybot and it keeps coming up with Vcodec located in the Windows/System32 as ncompat.tlb .I don't know if this is related to the problem but I located the file,temporarily sent it to the recycle bin and ran the scan again but the same problem came up again.Thanks.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please run all steps in the below (ignore the fact that you may not find all items mentioned and just complete all steps):

    SpywareQuake Removal Procedure

    Attach the smitfiles.txt log when finished and tell me your current status.

    Do you know what the below is?

    O23 - Service: PSPShuffleIndexer - - c:\program files\psp shuffle\pspshuffleindexer.exe

    Also attach a new HJT log.
     
  4. Ghartman

    Ghartman Private E-2

    Good afternoon.Thanks a lot for your quick response to my problem chaslang.My homepage has been restored to Google and I am delighted,but I still have a nagging feeling that there still may be a problem so I would prefer to still carry out all preventative measures as a precaution.In answer to your question pspshuffle is a program I have that is the equivalent to Ipod shuffle but for the PSP (arranging random pictures,film and music for PSP installation).Please find attached the Smitfile and new HJT log file.Thanks.P.S Smitrem did not work in safe mode so I had to run it in normal boot mode.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
    R3 - URLSearchHook: (no name) - - (no file)
    O2 - BHO: Nothing - {8d83b16e-0de1-452b-ac52-96ec0b34aa4b} - C:\WINDOWS\system32\hpD181.tmp (file missing)
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. Ghartman

    Ghartman Private E-2

    Thanks again for your response chaslang as I am sure you are a busy man.Everything seems to be working fine now.I enabled the viewing of hidden files and followed all of your instructions and here is the updated HJT logfile.I won't disable and re-enable the system restore until I receive the all clear from you.Thanks;) .
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you did not fix any of the items from my previous message. You must make sure you click Fix checked and all browsers must be closed before clicking fix. Also it would be a good idea to exit Windows Defender first before trying to run the fixes as it could have block the changes.

    So try the last fix again after shutting down Windows Defender. Then post a new HJT log.
     
  8. Ghartman

    Ghartman Private E-2

    Sorry about that chaslang.I fixed what you told me to but must not have saved the log file.How about this?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  10. Ghartman

    Ghartman Private E-2

    Good man.Thank you very much.;)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds