This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Need Help Removing Malware Defense and Spyware.Possible_Web

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey my computer is infected with a false virus scanner/malware program called Malwar Defense that sends me pop ups and false positives. The program is displayed in the task bar as Windows Security Alert. When tried to remove using Spyware Doctor doesn't work. The virus has slowed my computer down and doesn't let me open some programs such as Malwarebytes. Please help I can't use my computer for the tasks i use it for in this state.
Hi,

Please do the following:


Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Whole computer has died i think i started up windows this morning since i posted the thread just as i went to bed and when i started up computer it just goes to a black screen after the windows loading screen with a cursor but nothing to click just black background + cursor can't even select an account. Is my only option to reformat??
Do this…

hopefully you have access to another computer:




We will need to make a BOOT CD

Print these instruction out so that you know what you are doing.

Two programs to download

First

Please downloadISOBurner and save it to your desktop. This program will allow you to burn OTLPE.ISO to make a bootable CD. 
  •  
  • Double click the ISOBurner set up icon to install the program, from there on in it is fairly automatic.
  • There are Instructions for the iso burner here if you need them.

Second

  • Download OTLPE.iso save it to your desktop. Now burn OTLPE.iso to a CD using ISO Burner. {NOTE: This file is 292Mb in size so it may take some time to download.)
  • When downloaded double click OTLPE.iso > this will then open ISOBurner to burn the file to CD

  • Reboot the infected system using the boot CD you just created.
    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • you will find an icon on the desktop called OTLPE > Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to SafeList
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the C:\OTL.txt file in your reply.
I think i might just go with reformatting because i don't want anything else to go wrong since i am not that tech savvy. But how many more potential steps would be needed to get my computer up and running in a workable state? And if something did go horribily wrong and my computer could not be saved can it always just be reformated???? Could you also explain what REATOGO is so i know what will happen to my PC
you can always reformat your computer, as long as you have the installation CD's but you will lose all your documents etc. The boot CD, allows access to your computer before Windows loads. The infection you have is preventing windows from loading properly. With the boot CD it loads a desktop that looks similar to your windows desktop. There will be an icon to click on and a program to run i will give you instructions to fix the malware that will hopefully allow you to boot normally. We can try it…. If there is anything you don't understand in the instructions, just ask.
Would there be a way to just acess the computers files copy them to a usb/external hdd/portable hdd without a lot of trouble and then just reformatting the computer to fully get rid of the virus since i am very uncertain of my confidence to remove the virus due to my own abilities and unknown things that could happen.
Hi, yes there is - you can slave the drive to another computer, but there is always the risk of transferring the infection as well. You could also access the files from the boot CD. Have you tried getting into safe mode? (tap F8 repeatedly upon reboot untill an option menu appears - arrow up to safe mode) Malwarebytes should run in safe mode. Is there no one you know who could assist you with this if you don't feel you could follow the directions. You may want to consider taking your computer to your local repair shop and have them salvage your important files for you, then reformat.
Ok Safe Mode worked and i logged into my usual account but this message popped up asking if i wanted to continue in safe mode or something, i think it was normal but what do i do now? Also the resolution has changed from 1280x1080 to lower is this normal?? And i selected safe mode with network. I also shut it down once i realized the desktop loaded will this make the virus do something weird and not let me boot in safe mode again?
OK,
good

Boot back into safe mode with networking:

the resolution does change - that is normal

the request to continue in safe mode is normal.

Don't shut the machine down. Allow the safe mode desk top to load.

Malware bytes should run in safe mode. Run it and delete the bad files it finds.

then see if you can boot back into normal mode.

If MalwareBytes still won't run in safe mode.

Try and download and run exeHelper from my first post:

Then try malwarebytes again.

exeHelper
I won't be on the computer for a few hours but do i have to run Malware Byte through a different random named exe or does it not matter since mine is named randomly from when i tried to self help and do i just run a full scan and delete everything it says to and what if the program freezes half way through like it did the last 2 times i tried to remove the program using malwarebyte full scan. Would this be becasue i also had Avast, and Spyware doctor and iobit 360 all running at that time?
Yes, having all those security programs running could have been a problem. see if you can disable them, if not, run MBAM anyway. Just run a quick scan, no need for a full scan. Doesn't matter what it is named, see if it will run, if not, try renaming it to a random name with a .com extension, but it should run fine in safe mode.
Do i delete everything the scan tells me to delete or do i not delete things from lets say system 32, WINDOWS or registry??
Most are temporary internet files, temp files but there are 2 i don't know if i should delete system32/41.exe and system32/warning.html Do i delete or leave it i am now going to shut my computer down and restart it once i have a reply and then just rescan since it is a quick scan.
Yes, please delete everything it finds

Run it and delete the bad files it finds.


please stop shutting down your system and restarting

every time you do the infection regenerates. - keep your system on. Disconnect from the internet until you can log on here for further instructions and download further tools required.



Those two files are bad and need to be deleted. As well as the corresponding reg entries. Don't worry about deleting the items it finds, it's a very safe program.

Once they are gone you should be able to log into normal mode.

Once you are in normal mode.

Please do the following:

Please disable your security programs: You can actually uninstall IOBIT - it is considered a rogue security program now.

Then download and run the following program. Please allow it to install the recovery console, please be patient while it runs it's scan, it seems like it is hanging, but it isn't - it just takes a while to run through everything. Please don't interfere with it…allow it to run to completion. It will take a while to generate a log…just wait for it to do so. Then post the log


Post both the MBAM log and the Combofix log.


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI