This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware JS:fakewarn-E

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I just got a trojan virus - js:fakewarn-E. I looked at the published notes for js:fakewarn-D but couldn't figure out what MBAM is. I am using XP on an Acer laptop. I also have Avast installed. This recognises he virus and moves it to 'the chest' but the problem doesn't go away. One difficulty I have is that the virus is preventing me using the internet so if the solution requires a download then I will have a problem doing this. NOTE I am using my wife's laptop to write this topic. When I run IE8 all I get displayed is a web page for something called 'Security Suite' and if I enter a different URL I get an IE Explorer warning saying '… visiting this web site may harm your computer'. I also keep getting warnings that varioius pieces of software are corrupt (e.g. wltuser.exe and sf.bin). I would be very grateful if you could help me clear this error. Many thanks in advance.
Hi ajs2k2, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Do you have a usb storage device such as a flashdrive we can use to transfer some tools to the infected computer?

A blank CD will also work.

If using a USB device please follow these instructions to protect it from infection. No need to do this if you are using a CD.

On the Clean computer

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • attach the USB storage device to the computer.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.


Now for the tools.

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Next

Download OTL to your desktop.

Next

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

netsvcs
drivers32 /all
%SYSTEMDRIVE%\*.*
%systemroot%\system32\*.wt
%systemroot%\system32\*.ruy
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\system32\spool\prtprocs\w32x86\*.tmp
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\user32.dll /md5
%systemroot%\system32\ws2_32.dll /md5
%systemroot%\system32\ws2help.dll /md5
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "custom.txt"
  • Click save

Transfer the 3 files to the USB storage device or CD.


On the infected computer

  • Attach the USB storage device or insert the CD.
  • Tranfer the files you saved directly to the infected computer's Desktop

Running GMER

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode


Next, running OTL
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the text from the custom.txt you saved earlier.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Transfer the GMER.txt, OTL,txt and Extra.txt to the usb device or CD. Please post them in your next reply . You may need more than one post to fit them all in.

Thanks
Hi ajs2k2,

However, the GMER.txt file is too big to upload (1.3mb)

That's huge. Did you uncheck the items as instructed?

  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)


Can you zip it then attach it?

Looking at the OTL logs now.
Hi Hi ajs2k2,


Let's clean this up a bit and see if we can get you online. I prefer working directly on the infected computer if possible. We won't do too much untill we see the GMER log.

Next

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
O4 - HKLM..\Run: []  File not found
O21 - SSODL: exemplars - {2acf3add-34a1-4f2f-99cf-cc69785d1e90} - CLSID or File not found.
O22 - SharedTaskScheduler: {2acf3add-34a1-4f2f-99cf-cc69785d1e90} - exemplars - Reg Error: Key error. File not found
[2010/08/23 14:28:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Alan\Local Settings\Application Data\idwoqnpyt

:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\System32\cmd.exe"=-

:Files
C:\sqmdata*.sqm
C:\sqmnoopt*.sqm

:Commands
[emptytemp]
[Reboot]

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "fix.txt"
  • Click save

Transfer the notepad to the USB storage device.

On the infected computer

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the text from the fix.txt you saved earlier.
  • Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Next, open OTL if it's closed and obtain a new OTL.txt (there will only be an OTL.txt this time).

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so.
Save the log and post it in your next reply.

Try to access this forum from the infected computer and post the OTL fix log and the new OTL.txt

If you still are unable to access the internet please transfer the OTL fix log and the new OTL log to the USB device and post them from the clean computer.

Please post the logs by copying and pasting them into your reply.

Thanks
Hi Oldman960, I've attached run the files programs and have attached the files produced. Please note that Upload wouldn't allow the Log file to be attached (file type prevented) so I've changed the extension to 'txt'. Hopefully this can be renamed again and used successfully. Cheers ajs2k2
Hi ajs2k2, Are you able to access the internet with the infected computer? Are you still experiencing the same problems you had? Thanks
Hi Oldman960, Having given it a try the problem now seems to be resolved! Whatever you've suggested seems to have done the trick. Was the relabelled file I sent able to used OK? Many thanks for your help with this. Cheers Ajs2k2
Hi ajs2k2,

No problem reading the logs.

Now that you are online with the infected computer let's continue cleaning this machine.

You have some very old vulnerable java installed. Please go to Control Panel > Add/Remove programs and uninstall


J2SE Runtime Environment 5.0 Update 7
J2SE Runtime Environment 5.0 Update 9
J2SE Runtime Environment 5.0 Update 10
2SE Runtime Environment 5.0 Update 11
Java™ SE Runtime Environment 6 Update 1
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7


Do Not uninstall Java™ 6 Update 21



Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK


Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next,

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt (no Extra.txt this time)

Please post back with
  • MBAM log
  • OTL.txt

How is the computer?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI