Fake Windows security alert

Status
Not open for further replies.
Hi guys,
I got received a fake windows security alert in my computer for the past wo days. I try to clean using some of the antivirues and the spyware softwares....but I cant fully removed frm the pc...if could some pls help me... I attached the error message with this thread....pls help me to fix the problem. thanks in advance guys......

maha
 

Attachments

  • 1.JPG
    1.JPG
    44.2 KB · Views: 17
Dude,
after did all the steps I attached the log files here.....pls guide me for the next step..... so far I didnt see the fake alert....but still my laptop running slow.....is it because of that malware?? before my pc was faster then now......thank u dude
 

Attachments

  • SUPERAntiSpyware Scan Log - 09-14-2008 - 15-26-23.log
    798 bytes · Views: 6
Please do a disc cleanup and delete the temporary internet files, History, Cookies and temp files.
Have SuperAntispyware delete the Tracking Cookies.
Run your antivirus scan, updating right before the scan. Have SuperAntispyware remove the Cookies

One of the reasons you're slow is because you have too much running. You have three players loading at startup, some updater and some other entries that can be stopped.

Reopen HijackThis, scan, then check the following:
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
Phime2002a is not necessary for startup. It is usually run infrequently and can be started manually if needed.
Additional Info: Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
O4 - HKCU\..\Run: [RocketDock] "C:\Documents and Settings\Maharajan\My Documents\Mine\RocketDock\RocketDock.exe"
RocketDock is not necessary for startup. It is usually run infrequently and can be started manually if needed.
Additional Info: "RocketDock is a smoothly animated, alpha blended application launcher. It provides a nice clean interface to drop shortcuts on for easy access and organization"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe> SoundMax integrated sound.
Required if you have custom settings for your sound, such as effects and environments
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
>
System Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - http://www.ooxtv.com/stream.ocx> KooPlayer which is an P2P player.
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/DivXBrowserPlugin.cab
Now close all windows other than HiJackThis, then click Fix Checked.**Close HiJackThis*and*reboot into Safe Mode:

Right click on Start> Explore> Windows> System 32, delete any and all entries of the following if present:
First, click on Tools> Folder Options> View tab> CHECK 'show hidden files and folders'> Apply> OK>
WINDOWS\SYSTEM32\SHCJGJAV.EXE
Windows> Prefetch> delete
Prefetch\SHCJGJAV.EXE-0898302E.pf

Control Panel> Java< Update tab> UNCHECK 'cheek for updates automatically'> Apply> answer Yes> OK
Control Panel> Add/Remove Programs> find the Jave v6u6 and uninstall. That will leave you with the current version v6u7 which is on the system..

After that, Reboot, and post a new HijackThis log here in a reply

Run Malwarebytes again with options to fix checked, run HijackThis again. Attach both new logs.

DO NOT use System Restore while we are cleaning. I have provided you with descriptions of some of the processes. Stopping them for starting at boot does not mean you can't use them. For instance, when you need the features of Phime2002a, go into All Programs n open the program. Same for the others. In the meantime, you will need to open each of those programs and remove any automatic startup. If any of them have a Service, you will need to change the Service to Manual instead of Automatic.
 
Hi
i attached the requested log files. and i didnt remove the Phime2002a because i am mostly using this IME translator, And i cannt find the file from " Windows\System32\SHCJGJAV.EXE" and SHCJGJAV.EXE-0898302.pf from the folder " "Windows>prefetch>"

is there anyother thing to do make it more faster. now i feel its getting little faster. thank you very much.
 
Beautiful mbam log- clean as a whistle! I meant to ask about these 3 entries:
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe

Do you have to download a new program for each new Widget? I don't use this but was surprised to see 3 entries.

Reopen HijackThis, scan, then check the following:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

The Phime is still being loaded either from Startup or the Registry: Remove these entries:
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

Stop the following auto-updates:
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

Delete the following entry:
C:\Program Files\Bonjour\mDNSResponder.exe
Now close all windows other than HiJackThis, then click Fix Checked.**Close HiJackThis*and*reboot into Safe Mode.
Control Panel> Java> Update tab> UNCHECK 'automatically check for update'> answer Yes> Apply> OK
Do the same for Adobe.
Control Panel> Administrative Tools> Services> right click on Bonjour> change Startup type to Manual> Stop the Service
Start> Run> type in 'msconfig' without the quotes> Selective Startup> UNCHECK everything (including Phime snd Bonjour) EXCEPT the AVG processes, touchpad if laptop> Apply> OK> Reboot

Close the nag message that comes up after checking 'don't show this message again'. STAY in Selective Startup.
Run one more HijackThis and attach log. Then I'll have you cleanup the removal tools and drop old restore points.

We also need to get a firewall on the system pluse at least one more spyware/adware program.
 
Hey dude,
after all the process i attached the new log. i cannt find the Bonjour in the "services"... but there is no improvemnet on my pc. still slow....
 
Give me your system specs please:
Operating System
Installed RAM
Make and Model

I notice you're using IE8 which is still in beta. you also have the SP3 update. There is nothing in the log to account for a marked slowness- either startup or surfing. It's possible you do not have enough RAM installed- Windows XP should have at least 512MB to run well, or that the RAM is bad. You may also be having problems due to either or both the beta IE8 and SP3.

I looked at the image again. Firewalls don't display malware names to the best of my knowledge. A firewall listens a ports and blocks IPs, not specific Trojans although there are specific ports known for specific malware. But since you're using a beta browser which may have firewall enhancements, please look here, follow the 'Disable Alert' instructions'. Once that is handled, IF the other alert appears we will know it is indeed 'fake'. It is possible this is a feature now in IE8.

Enable or Disable Windows Firewall Notification:
http://technet.microsoft.com/en-us/library/cc785652.aspx

DO NOT click on the line that says' click here for recommended software'
 
Status
Not open for further replies.
Back