Fake Trojan Alerts: Trojandownloader.XS & Abebot, PC-Cleaner Spyware

Status
Not open for further replies.
I was working, then the girlfriend and I went out for dinner for our anniversary. Its 4.30pm you could just leave it, it takes a few hours depending on how many files you have.
 
ok ill see how i go i got home from work at 11pm ill see how long i last before i fall asleep. must of been good having your anniversary on st patricks day must of had a big night i went to the local irish pub one of my mates is the manager there so guiness was on the house
 
i dont really do that much for it at all, just try to avoid the plagues of drunk students. Ill have to head out in about an hour or so, if the scan hasnt finished by then ill look it over tomorrow morning.
 
yeah thats no problem ill keep in touch i might wait it out till this finished if i can if not ill post it tomorrow
 
Dont worry too much about how many viruses it finds, a lot of them could be in quarantine folders and system restore points which means that they cant do any harm.

Also bear in mind that Kaspersky will not clean it, but please do not delete anything that I have not told you to.
 
F:\Ahead.Nero.v8.3.2.1.Incl.Keymaker-EMBRACE\Nero-8.3.2.1_eng.exe

This file is infected and needs deleted,

I would also unistall mIRC

Create an uninstall list
  • Launch Hijackthis
  • Click the Open the Misc Tools section button
  • Click the Open Uninstall Manager button.
  • Click the Save list button.
  • Attach this log into your next reply

Nearly done
 
Go to add/remove programs and get rid of these,
Java(TM) 6 Update 2
Java(TM) 6 Update 3


Did you get rid of the other things I said?

Let me know and we can move on.
 
yes i have uninstalled mirc and deleted F:\Ahead.Nero.v8.3.2.1.Incl.Keymaker-EMBRACE\Nero-8.3.2.1_eng.exe
 
Good stuff,

Heres my favourite bit....

Ok then you appear to be all clean :grinthumb , here are some simple steps to help you keep your computer clean and secure:

Now we can remove all the tools that we used.

Please download OTMoveIt2 and save it to desktop.
  • Double-click OTMoveIt2.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.

Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt2 attempting to contact the internet, please allow it to do so.

  • Disable and Enable System Restore. - If you are using Windows XP or Vista then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide

    or

    Windows Vista System Restore Guide

Re-enable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.

    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:

    Instructions for Spybot S & D

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Comodo BOCLEAN <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software

Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

Happy surfing and stay clean! If you need anything else then ill more than likely be here.
 
All done. thanks for all your help kind sir u done a great job. i just finished installing spyblaster and search and destroy. good work
 
im getting a problem programs seem to be not responding now and freezing when i start them up?
 
dvd mov converter and dvd creator i just downloaded them to convert a movie and they dont seem to be responding?
 
Status
Not open for further replies.
Back