![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) | ||
|
Registered User
Join Date: Apr 2005
Location: Woodstock, CT
Posts: 68
OS: win xp
|
Potentially bogus "Security Update"
I've been having the following problem for a few weeks now...
a window pops up that says there was a security breach and then I get a window to open, that most likely appears to be a bogus site, trying to get me to download some software. Here is what I have tried to do: 1. Initially ran HijackThis and saw a suspcious BHO that I proceeded to remove. (however, it came back upon restarting) 2. I ran a Microsoft AntiSpyware scan and NOTHING was detected. 3. I ran an Ewido Security Suite scan and saved the scan report...it cleaned up a few things, but here is the scan: Quote:
Quote:
|
||
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,322
OS: N/A
|
Please download & run VundoFix.exe
__________________
Question - what have you done for the community today? |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Apr 2005
Location: Woodstock, CT
Posts: 68
OS: win xp
|
Thanks, but when I tried that two different times, it did not open after waiting at least two minutes both times.
I have to get ready for work, but if I come back and there are no replies, I will try doing the steps above and wait for more than a couple of minutes. |
|
|
|
|
#4 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,322
OS: N/A
|
If Vundofix wont work again, please try this other tool
Download this tool and save it to your desktop. Then double click the tool and follow the instructions. VirtumundoBeGone.exe When its done, reboot and post the log that is created on your desktop called VBG.TXT in your next reply
__________________
Question - what have you done for the community today? |
|
|
|
|
#5 (permalink) | |
|
Registered User
Join Date: Apr 2005
Location: Woodstock, CT
Posts: 68
OS: win xp
|
thanks...
had to run the VirtumundoBeGone.exe , but the log looks clean: Quote:
|
|
|
|
|
|
#7 (permalink) | |
|
Registered User
Join Date: Apr 2005
Location: Woodstock, CT
Posts: 68
OS: win xp
|
here's the log...but also, I haven't noticed the pop-up all day and I've been online a lot...
Quote:
|
|
|
|
|
|
#8 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,322
OS: N/A
|
Yes, it does appear to be gone. But just to be safe, please do an online scan, using Interent Explorer at Kaspersky Online Scanner
Answer Yes, when prompted to install an ActiveX component.
__________________
Question - what have you done for the community today? |
|
|
|
|
#9 (permalink) | |
|
Registered User
Join Date: Apr 2005
Location: Woodstock, CT
Posts: 68
OS: win xp
|
thanks -
Quote:
|
|
|
|
|
|
#10 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,322
OS: N/A
|
Please read this post completely before begining the fix.
Right click on this & choose "Save As..." DelO15Domains.inf - DelO15Domains.inf Right click on DelO15Domains.inf and choose Install. It will run immediately (you won't be able to see anything happen). You may delete the file afterwards. Host.zip - From within Host.zip, double click on MVPS.bat & allow it to run. Right click on this & select 'Save As' - DNSManual.bat Doubleclick on DNSManual.bat & allow it to run. SpywareBlaster 3.5.1 Install & update SpywareBlaster with the latest definitions. After you have updated, click the button - enable protection for all unprotected items IE-SpyAD - Extract the contents to a new folder From within the folder, double-click install.bat Select Option #2 - Install the new IE-SPYAD list. Then return to the main menu. Select option #4 - Add the old porn sites domain * * * * * * DELETING FILES/FOLDERS * * * * * * * * * * * * * * * If you have not done so already, please enable the viewing of Hidden files From Windows Explorer, go to Tools -> Folder Options -> View tab.
* * * * * * PURGING TEMP FOLDERS * * * * * * * * * * * * * * * Run Cleanup! using the following configuration: 1. Click Options... 2. Set the slider initially to Standard CleanUp! 3. Uncheck the following:
5. Press the CleanUp! button to start the program. 6. Do NOT reboot/logoff if prompted. * * * * * * USING HIJACKTHIS' DELETE ON REBOOT * * * * * * Start HiJackThis & go to Config>Misc.Tools> Delete a file on reboot...
This will clear the System Volume Information folder Go to Start >> Run - type control sysdm.cpl,,4 & press Enter
Once you have completed the above, please post a fresh HJT log & let me know how the machine is behaving now.
__________________
Question - what have you done for the community today? |
|
|
|
|
#11 (permalink) | |
|
Registered User
Join Date: Apr 2005
Location: Woodstock, CT
Posts: 68
OS: win xp
|
thanks a lot, everything went smoothly:
Quote:
|
|
|
|
|
|
#12 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,322
OS: N/A
|
Your system is clean. Kindly follow these simple steps in order to keep your computer clean and secure:
Update all these programs regularly. Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released. Follow this list and your potential for being infected again will reduce dramatically. Here are some additional utilities that will further enhance your safety.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein After doing all these, your system will be optimised against future threats. It's okay to delete the Hijack This folder in a couple weeks if everything is working okay. Have a safe & happy computing day. ![]() Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Question - what have you done for the community today? |
|
|
| Thread Tools | |
|
|