Please help remove trojan.fakealert and other spyware!

This forum is for removing Malware, Spyware, Adware. Post your HijackThis, DDS, RSIT, Combofix logs here.

Moderator: Moderators

Please help remove trojan.fakealert and other spyware!

Postby spider2901 » Sun Jan 15, 2012 7:54 am

My computer was really slow for a day (ran malwarebytes, no detection) and then after i ran defrag all my files became hidden, my start->all programs is empy, and when i try to run system restore from command prompt it states "System restore is not able to protect your computer. Please restart computer and try again" or something like that. I ran malwarebytes in safe mode and here is the log from it. Hijack Log is beneath it. Thanks guys!

MBAM Log:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.13.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Me :: MYROOM [administrator]

1/14/2012 10:39:55 PM
mbam-log-2012-01-14 (22-39-55).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 241073
Time elapsed: 17 minute(s), 54 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Documents and Settings\All Users\Application Data\ipyJfmDvPvAd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

(end)


Hijack Log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:50:00 PM, on 1/14/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Me\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Me\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://failblog.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 46.4.179.84 yahoo.com
O1 - Hosts: 46.4.179.84 google.com
O1 - Hosts: 46.4.179.84 myspace.com
O1 - Hosts: 46.4.179.84 msn.com
O1 - Hosts: 46.4.179.84 ebay.com
O1 - Hosts: 46.4.179.84 amazon.com
O1 - Hosts: 46.4.179.84 youtube.com
O1 - Hosts: 46.4.179.84 craigslist.org
O1 - Hosts: 46.4.179.84 wikipedia.org
O1 - Hosts: 46.4.179.84 cnn.com
O1 - Hosts: 46.4.179.84 facebook.com
O1 - Hosts: 46.4.179.84 go.com
O1 - Hosts: 46.4.179.84 live.com
O1 - Hosts: 46.4.179.84 blogger.com
O1 - Hosts: 46.4.179.84 aol.com
O1 - Hosts: 46.4.179.84 microsoft.com
O1 - Hosts: 46.4.179.84 comcast.net
O1 - Hosts: 46.4.179.84 imdb.com
O1 - Hosts: 46.4.179.84 digg.com
O1 - Hosts: 46.4.179.84 flickr.com
O1 - Hosts: 46.4.179.84 Expedia.com
O1 - Hosts: 46.4.179.84 Monster.com
O1 - Hosts: 46.4.179.84 Paypal.com
O1 - Hosts: 46.4.179.84 Weather.com
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter25 Class) - http://download.netmarble.net/web/nmsta ... rter25.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {92E82FBB-DA00-41E0-ABFE-95482E21A4F6} (NMTransX Module) - http://download.netmarble.net/NMChatX/NMTransX.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - http://download.netmarble.net/kdefence/kdfense8237.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 7515 bytes
spider2901
 
Posts: 10
Joined: Sat Aug 14, 2010 10:48 pm

Re: Please help remove trojan.fakealert and other spyware!

Postby patrik » Fri Jan 27, 2012 11:15 am

Hello,

sorry for delay.
Run HijackThis. Click "Do a system scan only" button.
Now select the following entries by placing a tick in the left hand check box, if still present:
Code: Select all
O1 - Hosts: 46.4.179.84 yahoo.com
O1 - Hosts: 46.4.179.84 google.com
O1 - Hosts: 46.4.179.84 myspace.com
O1 - Hosts: 46.4.179.84 msn.com
O1 - Hosts: 46.4.179.84 ebay.com
O1 - Hosts: 46.4.179.84 amazon.com
O1 - Hosts: 46.4.179.84 youtube.com
O1 - Hosts: 46.4.179.84 craigslist.org
O1 - Hosts: 46.4.179.84 wikipedia.org
O1 - Hosts: 46.4.179.84 cnn.com
O1 - Hosts: 46.4.179.84 facebook.com
O1 - Hosts: 46.4.179.84 go.com
O1 - Hosts: 46.4.179.84 live.com
O1 - Hosts: 46.4.179.84 blogger.com
O1 - Hosts: 46.4.179.84 aol.com
O1 - Hosts: 46.4.179.84 microsoft.com
O1 - Hosts: 46.4.179.84 comcast.net
O1 - Hosts: 46.4.179.84 imdb.com
O1 - Hosts: 46.4.179.84 digg.com
O1 - Hosts: 46.4.179.84 flickr.com
O1 - Hosts: 46.4.179.84 Expedia.com
O1 - Hosts: 46.4.179.84 Monster.com
O1 - Hosts: 46.4.179.84 Paypal.com
O1 - Hosts: 46.4.179.84 Weather.com

Once you have selected all entries, close all running programs then click once on the "fix checked" button.
Reboot your computer.

If you have previously downloaded ComboFix, please delete that version now.
Download Combofix from here. Close any open browsers. Double click on combofix.exe and follow the prompts.
When the tool is finished, it will produce a log for you.If the log does not automatically open, then it can be found at %systemdrive%\combofix.txt (typically C:\combofix.txt).

If ComboFix will not run, please rename it to myapp.exe and try again!

Post back with combofix log.
patrik
Site Admin
 
Posts: 9313
Joined: Sun Jan 08, 2006 1:11 pm


Return to Spyware Removal

Who is online

Users browsing this forum: No registered users and 3 guests

cron