This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

fakeAV-ALD and JS:fakewarn-c

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer's acess to the net was damaged last night. FakeWarn was the first detected I tried to move to chest but was not able to. tried a "boot time scan" and was able to move many files to the chest in what looks like an avast safe mode. No help. I tried system restore to a point 5 days ago. It keeps saying no changes to my system since then. When I tried to get to my home page (boston.com) it stalled, then sometimes showed a screen warning not to go to the directed site. sometimes it redirects to a VERY inappropriate site. The only site I can get to is my work outlook web access - my workplace has excellent security. Pop-up warnings tell me that net.exe is infected and offer to activate my virus software. In the tray there is an icon of a green sheild with a white check. When i put my cursor on it it identifies itself as Antispyware Soft I cannot access the add/remove software folder I don't know how to upload anything to this post because I can't download anything on that computer Please help - I don't know what to do
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

The only site I can get to is my work outlook web access - my workplace has excellent security.

Your workplace may have excellent security - but if your personal computer's security has been compromised, logging in to OWA could expose your password to the world. I'd recommend changing your password at work ASAP, and not logging into OWA from this PC until it's clean. :)

1) exeHelper
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


2) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

3) GMER
Please download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and put it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


4) What You Will Need To Post:
  • exeHelper log
  • DDS logs
  • GMER log
Thank you for helping me. I have been doing the things you told me to do, while the gmer scan was running I went to bed hopping to save the results this morning. However now there is a blue screen that I typed out below. I uploaded the logs I have - The computer is still running wth the Bluee screen up. What should I do? :unsure: ______________________________________________ A problem has been detected and windows has beeen shut down to prevent damage to your computer. If this is the first time you've seen this stop error screen, restart your computer. If this screen apears agin, follow these steps: Disable and uninstall any anti-virus, disk defrgmentation or backup utilities. Check your hard drive configuration, and check for updated drivers. Run CHKDSK /F to check fir hard drive corruption, and then restart your computor. Technical information: *** STOP: 0x00000024, (0x001902FE, 0xEB582798, 0xEB582494, 0xF75EC2CC) *** Ntfs.sys - Address F75EC2CC base at F75B4000, DateStamp 48025be5 Beginning dump of physical memory Physical memory dump complete Contact your system administrator or technical support group for further assistance. _______________________________________________________________
Restart; we'll get to the bluescreen issue.

Download Combofix from any of the links below but rename it to majp.exe before saving it to your desktop.

Link 1
Link 2


==================================

Disable any anti-virus software, then double click on the renamed ComboFix.exe & follow the prompts. Make sure to accept the installation of Recovery Console.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Sorry for such a long delay – I thought I responded, but i don't see it so here it is again. Also - I want you to know that while I have internet acess on the infected computer, I cannot use the browser so I am transfering files and applications using a flash drive. Thanks for all this help. Mary Anne

Attachments:

1) Combofix Script
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DDS::
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

2) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

3) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

4) What You Will Need To Post:
  • Combofix log
  • MBAM log
  • ESET log
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Claire\Application Data\Sun\Java\Deployment\cache\6.0\17\20bdd891-77598bcd
C:\Documents and Settings\Claire\Application Data\Sun\Java\Deployment\cache\6.0\51\184340f3-2fded5ac
C:\Documents and Settings\Claire\Application Data\Sun\Java\Deployment\cache\6.0\60\53d361fc-5b31b64d
C:\Documents and Settings\Claire\Application Data\Sun\Java\Deployment\cache\6.0\60\59af077c-1d9a17c4
C:\Documents and Settings\Claire\My Documents\Install_AIM.exe
C:\Program Files\PestPatrol\Quarantine\20041011185258765.zip
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1837\A0229107.exe
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1837\A0232093.exe
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1837\A0232142.exe
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1837\A0232143.exe


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
1) TFC
Please download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should reboot your machine, if not, manually reboot to ensure a complete clean

2) chkdsk
  • Close any open windows.
  • Go to the Start Menu, Run, type in cmd.exe and press enter
  • In the command window that appears, type chkdsk /r, and press enter
  • Agree to any prompts - then reboot the computer.
  • chkdsk should run as you boot the machine up - this will check the harddrive for damaged sectors and attempt to repair them.

3) Defrag
  • Close any open windows.
  • Go to the Start Menu, Programs, Accessories, System Tools, Disk Defragmenter
  • Defrag all drives in the Disk Defragmenter

Let me know how it's performing now.
I manually rebooted after running TFC Chkdsk ran to completion - a very long time - but then it was frozen and I had to restart to run DEFRAG. Defrag ran to completion, offered to let me view a report, then had an error and had to close the program. The computer seems to run fine now, I only notice a long time to startup and a long time to open the first web page I try to go tow when I start the browser. This is making me pretty optimistic. What's next?
Looking all clean. :) Any speed related issues are more likely to be hardware/software based at this point than malware.

The following will implement some cleanup procedures as well as reset System Restore points:

  • Please press the Windows Key and R on your keyboard. This will bring up the Run… command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
    🖼Click to load external image (Posted Image)
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.

You can remove any other programs that we used, except from MBAM. Keep that, and update/scan weekly for your own protection.

How to reduce your chances of infection in the future

Web Browsers
Internet Explorer does come pre-installed with all Windows machines - but this doesn't necessarily mean you have to use it! Because it is the most widely used browser, it is targeted by more malware writers, making you more susceptible to infection. There are many other free alternatives out there that offer better security, take one of these for a spin and see if it takes your fancy.
Mozilla Firefox
Google Chrome
Opera

WOT - Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for Firefox, Google Chrome and Internet Explorer.

If you would prefer to keep using Internet Explorer, follow these additional steps to make the browser more secure.
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Additional Security Measures
Keep your software up-to-date - You should be manually performing updates of your software once a week to ensure that you are current with anti-virus definitions and patched for any security vulnerabilities. This does not just apply to your anti-virus/anti-malware software; malware authors rely on exploiting commonly used software such as Java and Adobe Reader, which need to be kept up to date as well.

Keep Windows up-to-date - Use Windows Update regularly to stay current with security patches and service packs.

MVPS Hosts File - This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.

Firewalls - Without a firewall your computer is susceptible to being hacked and taken over. If you use the Windows Firewall you might think that's sufficient - but it only controls one way of the traffic (inbound). Simply using a Firewall in its default configuration can lower your risk greatly.

What Not To Do
The Perils of P2P File Sharing - Even if a P2P application is on the 'safe' list, malware can still be downloaded through infected files - executables, zip files and even MP3s. It is just not worth the risk.

Fake Security/Optimization Software - Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Additional Reading
How to prevent Malware - I strongly recommend that you read Miekiemoses' good advice

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
I uninstalled combofix - Can I just delete the others? I don't see them in Add/Remove programs, I think they are all on the desktop. The computer is working well now! Thank you so much.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI