Posted 05 December 2008 - 08:50 PM
My computer has been infected with the "Adware.Mirar" malware with possibly other nasty spyware things too.
This occurred on December 2 around the evening.
Immediately upon receiving these my Norton starts going crazy and starts to stop a bunch of things, one of them was from the Mirar spyware. Freaking out, (Naturally), I stopped what I was doing and immediately starting throwing everything at it.
Every now and then a pop-up would appear saying "You have a security problem!" ,that and along with other messages that have misspelled words such as "Unathorised". It looked legit at first, with the red shield symbol having a white "X" in the middle.
Googling this up, (and finding your website in the process), I was glad to know I was not alone.
I have ran Norton, MBAM, AVIRA scans in both normal and Safe mode. And it did seem to get rid of 90% of the problem, (the internet browser now does not spontaneously launch to some advertising website).
Ran more scans, and nothing was detected after that.
But I still had those irritating "You have a security problem!" pop ups appearing exactly after the 20 minute mark. (I have timed this.) Looking in my task manager, there was a process named "EE4C8E92". Seeing that it was strange, I killed the process tree and there were No more popups.
I went to the System Configuration Utility tool, just to see if anything was there and sure enough, there were two start up items:
I have no idea what they are, I googled them both but they came up with nothing. It also helped me see where they were located and the "EE" one was located in the Application Data on my C drive. Looked it up, and lo and behold, the Icon of the "red shield with the "X" " was right there, sitting there like it owned the place. I deleted it immediately.
I looked up where this "tornew.exe" was located, and it was in my TEMP file and it also stated the website name where it came from. Deleted it too. ( I dont want to post the website right here fearing that others may get infected.)
I also found what appeared to be the Mirar installation application in the TEMP folder as well:
M I R A R
mir12g (Installation application?)
(with those spaces)
I pretty much deleted any .TMP files for that day, as well as any cookies.
I've been looking around the forums and it seems that people also are getting the same things I have, but have also contracted them within this same week.
I'm restarting the computer now with those deletions, but something inside me is saying they will probably regenerate when it starts up again. If thats the case, then I'm going to start searching for more answers and possibly delete some Registry Keys.
Thanks for taking the time to read this, and I want to say thank you to BleepingComputer.com for all your help so far. If any mods deem it necessary to delete or move any part of this post, my apologies for that, I'll try to post in the correct area.