BleepingComputer.com: Malware/Adware Sypware problems

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

Malware/Adware Sypware problems Redirect, Audion adverts, post scrip windows vista total security 2011

#16 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 21 May 2011 - 09:13 AM

Hi,

Click start -> type regedit and press enter (agree permission prompt). On the tree navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services branch and see if WinDefend exists there. Report back your findings.
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#17 User is offline   RJ8080 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 01-May 11

Posted 22 May 2011 - 12:32 PM

looks like its missing

RJ

#18 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 22 May 2011 - 02:32 PM

Hi,

Download the attached fix.zip file and extract its contents to your desktop. Double-click the extracted .reg file and allow merging when prompted. Reboot and see if Windows Defender works any better.
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#19 User is offline   RJ8080 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 01-May 11

Posted 22 May 2011 - 03:03 PM

Hi

Windows defender working. Anything else i should do now?

RJ

#20 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 22 May 2011 - 11:45 PM

Good. Are there any issues remaining?
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#21 User is offline   RJ8080 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 01-May 11

Posted 23 May 2011 - 11:24 AM

Not really. The mediaget program i removed using Revo still has a folder in my programs menu. However i believe everything relating to it has been removed.

No virus/malware issues as far as i can tell.

RJ

#22 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 23 May 2011 - 11:30 AM

Hi,

Quote

The mediaget program i removed using Revo still has a folder in my programs menu.

Right click on the folder and select delete. Should take care of that.


If no other issues, it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

A To disable the System Restore feature:

1. Click on the Start button.
2. Hover over the Computer option, right click on it and then click Properties.
3. On the left hand side, click Advanced Settings.
4. If asked to permit the action, click on Allow.
5. Click on the System Protection tab.
6. Uncheck any checkboxes listed for your hard drives.
7. Press OK.


B. Reboot.

C Turn ON System Restore.
Follow the steps like you did when disabling system restore but on step 6. check any checkboxes listed for your hard drives.



Now lets uninstall ComboFix:
  • Click START then RUN
  • Now copy-paste Combofix /uninstall in the runbox and click OK



UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


Download and run Secunia Personal Software Inspector (PSI) and fix its findings.


Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade B)
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#23 User is offline   RJ8080 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 01-May 11

Posted 23 May 2011 - 01:02 PM

Ok all done,

Anything else to finish off. I seem to remember some of the initial steps taken needed to be reversed on completion?

Blade you truly have been amazing help.

RJ

#24 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 23 May 2011 - 02:02 PM

You're welcome :)

Quote

Anything else to finish off. I seem to remember some of the initial steps taken needed to be reversed on completion?

That should be all. If DDS and GMER tool are still on your desktop then you may delete those.
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#25 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 24 May 2011 - 10:44 AM

posted to wrong topic. please ignore.

This post has been edited by Blade81: 24 May 2011 - 10:45 AM
Reason for edit: posted to wrong topic *oops*

Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#26 User is offline   RJ8080 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 01-May 11

Posted 24 May 2011 - 12:49 PM

Should i go ahead and install microsoft security essentials?

Should i enable the cd emulation driver stuff. Not sure if i had any in the first place???

I have removed symantec and the mcafee i have now expired years ago though i update the free software.


Other than that i think i'm all done and you can close the loop if you want.

Many thanks for all your efforts.

RJ

#27 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 24 May 2011 - 02:07 PM

Hi,

Quote

Should i go ahead and install microsoft security essentials?

That would be a good option :)

Some other good free antivirus programs are:
Antivir and
Avast!

Good commercial ones are from:
Kaspersky and
ESET


Quote

Should i enable the cd emulation driver stuff. Not sure if i had any in the first place???

Yes, if you ran the tool earlier to disable that.
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#28 User is offline   RJ8080 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 01-May 11

Posted 27 May 2011 - 12:01 PM

cool, all done

thanks again

#29 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 27 May 2011 - 12:22 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users