This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] I think its the fake alert

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

as per are you infected topic
I am now posting a new topic which I believe I am infected with the fake alert, i have ran malware and did the removal but I continue to get pop ups wanting to scan my system when malware says it cant find anything. ????
I have completed the following

ran the ATF claener

created a restore point

have ran ERUNT

I have ran Malwarebytes' log log follows

Malwarebytes' Anti-Malware 1.44
Database version: 3651
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

1/29/2010 10:21:53 AM
mbam-log-2010-01-29 (10-21-53).txt

Scan type: Quick Scan
Objects scanned: 102736
Time elapsed: 3 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


GMER Rootkit Scanner ark.txt file follows

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-29 11:16:25
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Ric\AppData\Local\Temp\pwldrpow.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler@Heartbeat 0x60 0x10 0x23 0xE9 …

—- EOF - GMER 1.0.15 —-



last I have ran DDS and that log follows


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:28:53.06 on Fri 01/29/2010
Internet Explorer: 8.0.6001.18882
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1315 [GMT -5:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\dldocoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PSIService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Dell 968 AIO Printer\dldomon.exe
C:\Program Files\Dell 968 AIO Printer\memcard.exe
C:\Program Files\Roxio\Media Experience\DMXLauncher.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Ric\Program Files\DNA\btdna.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehRecvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\MSAgent\agentsvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Windows\regedit.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Ric\Documents\Computer Troubleshooting HELP\WhatTheTECH\DDS\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = https://login.yahoo.com/config/login_verify…src=ym&rl=1
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4080623
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [BitTorrent DNA] "c:\users\ric\program files\dna\btdna.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [dldomon.exe] "c:\program files\dell 968 aio printer\dldomon.exe"
mRun: [MemoryCardManager] "c:\program files\dell 968 aio printer\memcard.exe"
mRun: [Dell 968 AIO Printer Fax Server] "c:\program files\dell 968 aio printer\fm3032.exe" /s
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [DMXLauncher] "c:\program files\roxio\media experience\DMXLauncher.exe"
mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\ric\appdata\roaming\micros~1\windows\startm~1\programs\startup\easyga~1.lnk - c:\program files\easy gadget\easy gadget.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxps://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5872/mcfscan.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL

============= SERVICES / DRIVERS ===============

R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-4-29 176128]
R2 dldo_device;dldo_device;c:\windows\system32\dldocoms.exe -service –> c:\windows\system32\dldocoms.exe -service [?]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2008-6-22 1034496]
S2 dldoCATSCustConnectService;dldoCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldoserv.exe [2007-10-5 99568]
S2 gupdate1ca90c8b96bc860;Google Update Service (gupdate1ca90c8b96bc860);c:\program files\google\update\GoogleUpdate.exe [2010-1-8 133104]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-1-15 23456]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S4 AutoSyncService;Memeo AutoSync ;c:\program files\memeo\autosync\MemeoService.exe [2007-7-6 31768]

=============== Created Last 30 ================

2010-01-28 22:37 –d—– c:\program files\TrendMicro
2010-01-28 10:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-28 10:07 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-28 10:07 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-27 17:18 –dsh— c:\programdata\LPCBCG
2010-01-27 17:18 –dsh— c:\progra~2\LPCBCG
2010-01-27 17:18 –dsh— c:\programdata\95a6f49
2010-01-27 17:18 –dsh— c:\progra~2\95a6f49
2010-01-26 12:09 –d—– c:\users\ric\appdata\roaming\Malwarebytes
2010-01-26 12:09 –d—– c:\programdata\Malwarebytes
2010-01-26 12:09 –d—– c:\progra~2\Malwarebytes
2010-01-24 09:57 –d—– c:\programdata\SUPERAntiSpyware.com
2010-01-24 09:57 –d—– c:\progra~2\SUPERAntiSpyware.com
2010-01-24 09:57 –d—– c:\users\ric\appdata\roaming\SUPERAntiSpyware.com
2010-01-24 09:57 –d—– c:\program files\SUPERAntiSpyware
2010-01-17 17:49 –d—– c:\program files\common files\Symantec Shared
2010-01-17 14:03 –d—– c:\programdata\Symantec
2010-01-17 14:03 –d—– c:\programdata\NortonInstaller
2010-01-17 14:03 –d—– c:\programdata\Norton
2010-01-17 14:03 –d—– c:\progra~2\Symantec
2010-01-17 14:03 –d—– c:\progra~2\NortonInstaller
2010-01-17 14:03 –d—– c:\progra~2\Norton
2010-01-15 08:50 23,456 a——- c:\windows\system32\drivers\DrvAgent32.sys
2010-01-15 08:43 –d—– c:\windows\system32\vmm32
2010-01-14 20:38 411,368 a——- c:\windows\system32\deploytk.dll
2010-01-14 09:19 –d—– c:\users\ric\Program Files
2010-01-14 09:19 –d—– c:\users\ric\appdata\roaming\DNA
2010-01-13 07:01 156,672 a——- c:\windows\system32\t2embed.dll
2010-01-13 07:01 72,704 a——- c:\windows\system32\fontsub.dll
2010-01-08 20:11 –d—– c:\program files\common files\DivX Shared
2010-01-07 13:47 18,816 a——- c:\windows\system32\drivers\dvd43llh.sys
2010-01-07 13:47 –d—– c:\program files\dvd43
2010-01-07 13:40 –d—– c:\users\ric\appdata\roaming\AVS4YOU
2010-01-07 13:40 –d—– c:\programdata\AVS4YOU
2010-01-07 13:40 –d—– c:\progra~2\AVS4YOU
2010-01-07 13:40 –d—– c:\program files\common files\AVSMedia
2010-01-07 13:39 24,576 a——- c:\windows\system32\msxml3a.dll
2010-01-07 13:39 –d—– c:\program files\AVS4YOU

==================== Find3M ====================

2010-01-14 11:12 181,120 ——– c:\windows\system32\MpSigStub.exe
2010-01-02 01:38 916,480 a——- c:\windows\system32\wininet.dll
2010-01-02 01:32 109,056 a——- c:\windows\system32\iesysprep.dll
2010-01-02 01:32 71,680 a——- c:\windows\system32\iesetup.dll
2010-01-01 23:57 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-12-24 08:59 143,360 a——- c:\windows\inf\infstrng.dat
2009-12-24 08:59 51,200 a——- c:\windows\inf\infpub.dat
2009-12-24 08:39 86,016 a——- c:\windows\inf\infstor.dat
2009-12-14 14:15 2,146,304 a——- c:\windows\system32\GPhotos.scr
2009-12-14 10:42 73,216 a——- c:\windows\ST6UNST.EXE
2009-12-14 10:42 249,856 ——– c:\windows\Setup1.exe
2009-11-17 03:18 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-09 07:31 24,064 a——- c:\windows\system32\nshhttp.dll
2009-11-09 07:30 30,720 a——- c:\windows\system32\httpapi.dll
2008-07-07 11:14 1,377,872 a——- c:\programdata\pswi_preloaded.exe
2008-07-07 11:14 1,377,872 a——- c:\progra~2\pswi_preloaded.exe
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-10-15 06:17 245,760 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2008-07-19 16:42 168 a–shr– c:\windows\system32\B4AADF26EE.sys

============= FINISH: 11:29:07.29 ===============


it says that the attach log needs to be zipped, I have that and attached it, along with all the other logs as well.
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI