Activity Stream
48,167 MEMBERS
64874 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1.     
    #1
    Respected Member

    Default Virus/spyware help needed

    Ok I went to a site yesterturd-day and got a fake antivirus pop up. i've seen these several times before on people's computers and removed them successfully but this one will not leave. I got the fake anti-virus removed and does not pop up anymore, but i'm still being redirected to web pages when i try to open them sometimes.

    I use microsoft security essentials, malwarebytes, and hijackthis.

    Help.....
    barcodenation Reviewed by barcodenation on . Virus/spyware help needed Ok I went to a site yesterturd-day and got a fake antivirus pop up. i've seen these several times before on people's computers and removed them successfully but this one will not leave. I got the fake anti-virus removed and does not pop up anymore, but i'm still being redirected to web pages when i try to open them sometimes. I use microsoft security essentials, malwarebytes, and hijackthis. Help..... Rating: 5

  2.   Sponsored Links

  3.     
    #2
    Member
    Please download the current version of HijackThis from HERE
    • Double click and run the installer.
    • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
    • After installing, you should get the user agreement, press accept and Hijack This will run.
    • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.


  4.     
    #3
    Respected Member
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 4:52:07 PM, on 5/1/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.17023)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/m/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://reg.knowledgeadventure.com/j...20Kindergarten
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=127.0.0.1:5555
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\s wg.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [FG_Monitor] C:\Program Files\Folder Guard Pro\FGKey.exe /Start
    O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.ex e" -quiet
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6 FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --
    End of file - 5944 bytes

  5.     
    #4
    Member
    Website's:
    pspgoonz.com extremeddl.info
    uninstall all browsers then reinstall worked on a friends computer that had the redirect problem make sure you download the install package first lmao

  6.     
    #5
    Member
    • Open HijackThis.
    • Choose "Do a system scan only"
    • Check the boxes in front of these lines:


      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=127.0.0.1:5555


    • Press "Fix Checked"
    • Close Hijack This.





    Please download and run this tool.

    Download Malwarebytes' Anti-Malware from Here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

    Note:
    If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
    Click OK to either and let MBAM proceed with the disinfection process.
    If asked to restart the computer, please do so immediately.


    Post the contents of the MBAM Log.


  7.     
    #6
    Respected Member
    What about the one right above that one?

  8.     
    #7
    Member
    No please just tick the ones I mentioned.


  9.     
    #8
    Member
    Website's:
    wrzc.eu watchfreemoviez.eu

    Respect: SMLMATS, M-R-T, Elio, exel, SLiM, UltimA, Hx, Rick

    MechoDDL - All Your Needs

  10.     
    #9
    Respected Member
    K i'm going to try what myth? posted, but malwarebytes came up with nothing on the full system scan... Still getting redirected. It's redirecting firefox not sure if that matters...

  11.     
    #10
    Member
    Hmm well lets bring out the big guns, I think you may have a Rootkit in your system:




    Hello.
    • Download combofix from here
      Link 1

      1. If you are using Firefox, make sure that your download settings are as follows:

      * Tools->Options->Main tab
      * Set to "Always ask me where to Save the files".

      2. During the download, rename Combofix to Combo-Fix as follows:





      3. It is important you rename Combofix during the download, but not after.
      4. Please do not rename Combofix to other names, but only to the one indicated.
      5. Close any open browsers.
      6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • We need to disable your local AV (Anti-virus) before running Combofix.
    • See HERE for how to disable your AV.
    • Double click on ComboFix.exe.
    • Follow the prompts. NOTE:
    • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
      ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

      **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.

    • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.


    • Allow ComboFix to download the Recovery Console.
    • Accept the End-User License Agreement.
    • The Recovery Console will be installed.
    • You will then get this next prompt that asks if you want to continue the malware scan, select yes


    • Allow combofix to run
    • Post C:\combofix.txt back here.

      Note:
      Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. What kind of Spyware are this.
    By MSL6600 in forum Technical Help Desk Support
    Replies: 16
    Last Post: 5th Dec 2011, 05:10 PM
  2. Virus !!! need help
    By MSL6600 in forum General Discussion
    Replies: 16
    Last Post: 3rd May 2011, 07:27 PM
  3. VIRUS - Any idea about this virus ?
    By pankaj in forum General Discussion
    Replies: 6
    Last Post: 9th Mar 2011, 09:11 AM
  4. Is this a virus?
    By iFlames in forum Technical Help Desk Support
    Replies: 8
    Last Post: 18th Sep 2010, 01:36 PM
  5. Media Industry Wants Mandated Spyware and More
    By Jesse in forum News & Current Events
    Replies: 2
    Last Post: 17th Apr 2010, 06:00 PM

Tags for this Thread

BE SOCIAL