Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Download Now:
Inactive: Spyware called "Security tool"
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Inactive: Spyware called "Security tool"
Hi everyone,
I seem to have stumbled across a kind of spyware called "Security tool" that keeps popping up saying that I have been infected with other spyware. I can't even see my desktop since I have this problem. I tried using Spybot, AVG and Norton but none of them can successfully remove them because my computer automatically restarts whenever I run scans. I would appreciate your feedback very much. |
|
#2
|
||||
|
||||
|
Go here:
8-step Viruses/Spyware/Malware Preliminary Removal Instructions Take your time and post the 3 logs required |
|
#3
|
||||
|
||||
|
sma06, if you are still having problems and have run the programs, please let me know.
|
|
#4
|
|||
|
|||
|
Thanks, I will run all these programs first and let you know.
|
|
#5
|
||||
|
||||
|
After you run the three program, attach the logs from Malwarebytes and Superantispyware. Then paste the log for HijackThis in the reply. (Ctrl V)
|
|
|
|
#6
|
|||
|
|||
|
Hello,
I followed all the steps and I think the problem is resolved for now. Only thing is I can still see 'Security tool' and 'Windows Police Pro' (which is another problem I had) on my desktop. How can I complete get rid of them? Also, I am not sure of which files to delete from HijackThis. I have attached the log files with this post. |
|
#7
|
||||
|
||||
|
Did you run hijackthis before running Malwarebytes? If so, post a new hijackthis log. You have IE6 installed. Even if you don't use it run Windows Update manually and choose "custom" apply all critical and hardware updates, including IE8. Doing this will help your computers security
|
|
#8
|
|||
|
|||
|
Dear Tmagic650,
I ran the programmes in the exact same order as listed. Just in case, I just re-ran Hijackthis again. Here is the logfile. It says I have to be careful before deleting any registry files. Do u know which ones I should delete? |
|
#9
|
||||
|
||||
|
Tmagic, you can see the time and date each log was done. the order they are showing in attahments doe not matter. The time date and versdion appear at the top of each log:
Quote:
sma06, you still have malware. I did a quick check of the logs and it's evident in all 3. Give me a few hours please to review the thoroughly and I will get back to you. You do NOT need to do another HJT scan at this time. |
|
#10
|
||||
|
||||
|
Thanks for the tip Bobbye
There is malware still on sma06's system. I don't like these hijackthis entries:"O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm" "O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm" Is symantec/norton exprired or is it running correctly? You should only have one antivirus program installed at a time. It looks like you have 3 installed. Adobe Reader needs to be updated from 7 to 9. IE6 needs to be updated to IE8. You have spyware doctor and spybot search & destroy installed. Remove them and install free CCleaner and Advanced SystemCare free and run them regularly |
|
#11
|
||||
|
||||
|
I have reviewed you logs and don't have good news:
The most significant infection is the PWS- password stealer TrojanSpy:Win32/Zbot.gen: 1)TrojanSpy:Win32/Zbot.gen!C is a trojan that is used to steal sensitive information from an affected machine. 2)TrojanSpy:Win32/Zbot.gen!C may inject malicious code into explorer.exe or winlogon.exe. 3)This Trojan may try to prevent its removal from the affected system by blocking access to its files, and by recreating its registry entries should they be deleted. 5)TrojanSpy:Win32/Zbot.gen!C may try to delete all cookies stored by Internet Explorer in the URL cache so that users are forced to retype their passwords (should they be cached). Manual removal - file by file-is not recommended for this threat because it's so pervasive. 1. The first thing you need to do is change ALL of your passwords. 2. Monitor any online financial transactions such as online banking. 3. Disable the Real Time Protection for the scans: SYMANTEC ENDPOINT PROTECTION Right click on the icon in the taskbar notification area & select "Disable Symantec EndPoint Protection". ![]() TEA TIMER
Run a full system Scan with the Norton Antivirus- update right before the scan. Save the log and include it in your next reply. Please download ComboFix HERE:
Notes:
Rescan with HijackThis: PASTE the log into your next reply. Attach the Norton AV scan and the Combofix report. We'll see where we are after this. Please don't so any other download/install or install while we're cleaning, except what I am directing you to do. We will cover other parts of the system at the appropriate time. Note: You are using Download Accelerator - (DAP) This delivers popup/popunder ads, and tracks your internet usage. You can find safer alternatives here: http://www.spywareinfo.com/downloads...at=dlman#dlman This is an optional removal. DAP is not malware. You do not have to do anything with this at this time. I just want to make you aware of it. I suggest you remove it. Go to Start > Settings > Control Panel > Add/Remove Programs and remove it. |
|
#12
|
||||
|
||||
|
Hey Bobbye,
is this the TrojanSpy:Win32/Zbot.gen indicator: "C:\WINDOWS\system32\wuauclt.exe" |
|
#13
|
||||
|
||||
|
No- it's the WindowsUpdate process.
|
|
#14
|
||||
|
||||
|
"Tmagic, you can see the time and date each log was done. The order they are showing in attachments does not matter"...
I thought a rescan with Malwarebytes might change the hijackthis logs contents "No- it's the WindowsUpdate process"... WindowsUdate process in the hijackthis log? I can't seem to find "windowsupdate process in the log |
|
#15
|
||||
|
||||
|
Post your registry specifically these keys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnc e Do have Security Tool entry or something that starts with 494*******(some random digits). Search for files (exe) that starts with 494. Post the content of your autorun.inf too. Last edited by WinXPert; 10-16-2009 at 03:31 AM.. |
|
#16
|
||||
|
||||
|
WinXPert, I would appreciate it if you would allow me to finish helping this member. Sending someone on a different track in the middle of a cleaning is a bad idea.
|
|
#17
|
|||
|
|||
|
Dear Bobeye,
I ran the programs as requested and these are the resulting logs. I noticed when I ran Norton a few days ago it said my computer was clean, but today it seemed to detect a lot of trojan viruses. I hope Combo-fix got rid of them. Please have a look and let me know. |
|
#18
|
||||
|
||||
|
Okay, some questions and some housekeeping:
1. Do you have a security suite from Symantec/Norton? Most have a firewall included. I see you are also running Comodo. so if Norton is current, you need to remove the Comodo firewall. 2. Did you miss my instructions to temporarily disable the Real Time Protection of TeaTimer and Symantec Endpoint Protection in Post #11? Having this kind of protection running can affect the scans. And in the Combofix program, you were also instructed to shut dow all security programs. 3. Did you delete the entries Norton put in quaranting? If not, please do that, then the following: 4. TFC (Temp File Cleaner) Download TFC to your desktop
TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC. TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. When through, please Empty the Recycle Bin 5. Old versions of Java and Adobe Reader present another vulnerability and they should be updated:
It is important the you uninstall the outdated versions of Adobe v7 and Java v1.5.11. 6. Please reopen HijcackThis to 'do system scan only'. Check the following entry: O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_SG&c=Q106&bd=pavilion&pf=laptop Close all Windows except hijackThis cna click on "Fix Checked." Do you have any ide what 'Promo' is here? It's a particular port open in the firewall. 53:UDP"= 53:UDP:Promo When you get this done- including deleting all the entries Norton has quarantined, please do this: Run Eset NOD32 Online AntiVirus Scanner HERE Note: You will need to use Internet Explorer for this scan.
Save the log and attach it in next reply. Rescan with HijackThis and paste the new log in next reply. A NOTE: Please do not use the System Restore feature. There is malware in the restore points. I will have you dropp the old restore points and create a new clean on when we finish. |
|
#19
|
|||
|
|||
|
Just wanted to mention that I just got done resolving this myself. bleepingcomputer.com has given a step by step procedure to fix this including a couple small files specificaly created to remove this issue that you can download and install. Follow their steps exactly and it should clear you right up plus fix files that were corrupted by this nasty fake system cleaner.
Here is the link below and good luck ![]() http://www.bleepingcomputer.com/viru...-security-tool |
|
#20
|
||||
|
||||
|
4 month old thread closed due to inactivity.
|
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
"Insecure Internet Activity" and "Security Center Alert" about Win32.zafi.B
|
1 | Virus and Malware Removal | ||
Spyware popups "Security System..."
|
18 | Virus and Malware Removal | ||
Infected with "security toolbar" and spyware ads. Please help.
|
1 | Virus and Malware Removal | ||
I'm having problems with spyware called "adware.needware" I have attatched my HJT!
|
1 | Virus and Malware Removal | ||
Gator dislikes being called "spyware"
|
11 | General Discussion | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 01:12 PM.


There is malware still on sma06's system. I don't like these hijackthis entries:


"Insecure Internet Activity" and "Security Center Alert" about Win32.zafi.B