service pack 2
It's been ages since I got infected like this :S
Ok, I'll start from when it all began.
1-The infection process started at the moment I pressed "Allow" taskmgr.exe after having multile pop-ups
making it impossible to close because closing one was opening another and just closing the browser did
the same thing. So I pressed CTRL ALT DELETE to end the process, now I'm unsure due to the stress I had
if my memory is good, but it closed without a problem. Then I re-open Firefox and it kept my windows so
I had to do the same again though this time ctrl alt delete took longer to appear and so my computer
was asking me If I wanted to launch taskmgr.exe ( unindentified source ) but I felt like it was me
trigering it right ? So I clicked yes and there you go, Sphere security 2012 launched and started
making false virus scans and saying anything I tried to launch was infected. I managed to suppress it
following theses steps "Alertane Security Sphere 2012 removal instructions:" (Note the mistype *Alternate*)
In their 4th step they ask you to "download exe_fix.reg and run it. Click "Yes" to safe the changes."
I did that but the program told me "not all could be written since some are in use"
I skipped it thinking it was normal and I went with step 5, download malwarebytes and run it.
Problem was, it wasn't updated. Somehow, I don't have issues with sphere security 2012 because I
also went where the file was and renamed it so I could run the anti-malware, though I also took no
risk and manually put it in the trash can. The scan is finished and asks to reboot. I reboot.
2-Everything seems fine, I run spybot - search and destroy 18.104.22.168 because that program saved me
alot of trouble in the past. I also run malwarebytes and microsoft security essentials. I realised
I couldn't update my definitions on any of my anti-malware programs. So I go and launch firefox.
I couldn't search anything on the web since " proxy server unavailable" or something close to that.
I felt as much as my computer wasn't safe yet, now I lost a bit of what went wrong though I tried
many times to search and I even physically disconnected from internet, unplugging everything and
replugging, Not if If I restarted after that, but once internet came back to normal
( probably after unchecking Proxy server in internet options ) Along Came Privacy Protection a.k.a
"privacy.exe" I had a bigger problem shutting this one up. I had to go in safe mode again and try
and manually delete the hiddenfile that was in programmdata "privacy.exe" and had to download
TDSSkiller and Rkill on my GF laptop and transfer it on my computer in safe mode. Doing that
seemed like it helped me go back in normal mode, launch Rkill and somehow I didn't have privacy.exe
blocking me. I AM UNSURE if it is because I manually deleted it or because I run the program Rkill.
Now that was done, i was able to update my definitions with my anti-malicious programs programs
Now My spybot have found 2 entries TrojansC-02 "Win32.Palevo that has two different reg keys that lead
to two different paths
Malwarebytes' Anti-malware (update 5th of november )had found 5 so far but is not finished
So I am here waiting for my other programs to finish scanning and wondering If I should FIX the ones
my spybot found or wait that the other finish ? I am also here to ask anyone if they can help me by
reading logs that they will ask me to make so I'll get a " Your computer is ok" from someone who Knows
what's he talking about. Cause I still feel insecure After all thoses scans and well scarred.
I hope my long and descriptive post wasn't a burden to read, because I wrote all that for the sake of
helping you guys understand what happened and how it went. Sorry If I put to many useless information.
I thank you for you time. Looking forward to fight the programs with official help from someone.
Edit : Nov 6th 2011
I rebooted my computer after quarantine and removal. But I would really love assistance and run some tests
to check if everything as been taken care of without any flaws.
Edited by lienko11, 06 November 2011 - 02:55 PM.