This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Fake Antivirus Alert followed by adult website popup.

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was shopping online for Christmas, and clicked on somelink then I closed that window but I have some new grey/green icon showing in my notification area on the task bar. It says,
Windows Security Alert - Application cannot be executed. The file wuauclt.exe is infected. Do you want to activate your antivirus software now?
I didn't click on that because I suspect that would be a fake thing. Then some mid size window popped up in the right bottom corner that says:

You computer is being attached by an internet virus. It could be a password-stealing attack, a trojan-dropper, or similar. Attack from 110.184.59.11 port: 5293 Attacked Port 6243 Threat: Bankerfox.A

Then I some red window popped in the middle of the screen, that says:

ATTENTION! SPYWARE ALERT. (blablabla…)

Then my windows explorer popped with porno.org, adult.com, and vigra.org…..

I happened to have a mbam.exe on my desktop from two weeks ago when I had another problem, so I ran it. It detected two Trojan Dropper and I removed them and restarted my computer but the same alerts and windows are still showing up. So I downloaded a most recent version (mbam 1.50) from another pc and copied by USB to this infected pc, but couldn't run it this time.

So I booted it in safe mode. the alerts and windowns did not show up in safe mode. but the mbam detected nothing. So I booted again in regular mode, and the same alerts and windows are showing.

I also tried to run exehelper in regular mode, I saw a black dos screen for 2 second then it was gone,

exeHelper by Raktor
exeHelper by Raktor
Build 20100414
Run at 11:25:17 on 12/18/10
Now searching…
Checking for numerical processes…
exeHelper by Raktor
Build 20100414
Run at 11:25:25 on 12/18/10exeHelper by Raktor




What can I do next? some yellow little explanation mark thing keeps adding to my notification area now. Thank you!

Seems like I fixed the problem: I ran mbam under the username under which I got affected instead of administrator in safe mode, and mbam found 3 Ttrojan.FakeAV.Gen. I removed them. Those popups seem to be gone.

Can I get some suggestions on how to avoid clicking on the fake links? I need to keep shopping online…
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:


Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.
  • Please download TDSSKiller.zip
    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • Press Start Scan
      • Only if Malicious objects are found then ensure Cure is selected
      • Then click Continue > Reboot now
    • Copy and paste the log in your next reply
      • A copy of the log will be saved automatically to the root directory, root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
    please post the contents of that log TDSSKiller and GooredFix log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI