Fake Malware Scanner Virus...Please Help!

johnb35

Administrator
Staff member
OK, download and run Ccleaner.

http://download.cnet.com/ccleaner/

Then set the options that are checked in the attached image and click on run cleaner.

Please provide an uninstall list using hijackthis.

Open hijackthis, click on open misc tools section, click on open uninstall manager, click on save list, save it and then copy and paste it back here.
 

Attachments

  • ccleaner.JPG
    ccleaner.JPG
    76.3 KB · Views: 265
µTorrent
7-Zip 9.13 beta
Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
AnyDVD
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AVG Free 9.0
Bonjour
CCleaner
CloneDVD2
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel(R) Graphics Media Accelerator Driver for Mobile
iTunes
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Office 2000 SR-1 Professional
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.6.8)
PrimoPDF
QuickTime
SD Secure Module
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165-v2)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Skype™ 4.2
Sonic RecordNow!
SoundMAX
SUPERAntiSpyware
TOSHIBA Power Saver
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB978506)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB978207)
VLC media player 1.1.0
Windows XP Service Pack 3
 
Not sure how to get the logs on that one...but scan ran, and said no threats found. more than happy to run again if you need a log. Still getting redirects unfortunately:(

Any more ideas? I'm willing to make a more drastic move if you have any clues as to the root of the problem.
 

johnb35

Administrator
Staff member
Download and run DR.Web Cureit Save it to your desktop:


Doubleclick the drweb-cureit.exe file and click Scan to run express scan. Click OK in the pop-up window to allow the scan.
This will scan the files currently running in memory and if something is found, click the Yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, select Complete scan.

Click the green arrow
drweb.jpg
at the right, and the scan will start.
Click Yes to all if it asks if you want to cure/move the file.
When the scan has finished, in the menu, click File and choose Save report list
Save the report to your desktop. The report will be called DrWeb.csv
Note:this report may need to be renamed to Dr.Web.txt in order to post it on the forum.
Please post the Dr.Web.txt report in your next reply
Close Dr.Web Cureit.
Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.

NOTE. During the scan, pop-up window will open asking for full version purchase. Simply close the window by clicking on the X in the upper right corner.
 
Sorry for not replying sooner. Haven't had much computer repair time lately. I ran Dr. Webcurit in both quick scan and full scan mode. I accidentally closed afterwards and didn't manage to grab a log file, but the scan results said no viruses found on both acccounts. More than happy to run again and post next time if need be. Still getting redirects on google searches in firefox.
 

gamblingman

VIP Member
Where are you being redirected to? Is it only happening in Firefox? Do you get any redirects in Internet Explorer? Is the redirect affecting your home page from showing or is it when you "search"? Also, is there anyone else using your computer?
 
From what I've seen, the redirects are only in firefox, and only while using google. Basically, I'll perform a search from the google home page, click on the most relevant link, and get redirected several times to different sites.

Example:
Searched for "golden valley brewery"
clicked on top link, which has the correct url listed
get redirected to the following three urls before landing on the last one:

http://5x5search.com/index.php?search=golden+valley+brewery+

http://itcg.21008.asklots.com/jump1...wUzMx8FMx8lM18lM0kzMxAjM4ITM&a=vgpt&mr=1&rc=0

http://mx2.38855.asklots.com/jump2/?affiliate=mx2&subid=38855&terms=golden valley brewery


It doesn't always happen on the first search, but after a couple, even when landing on the correct page, hitting back, and clicking the same link, it will redirect eventually. Same results when using firefox standard search toolbar using google. No problems with any other part of google like maps photos etc. No problems with yahoo search.

Haven't had any problems actually landing on the google home page. Yahoo is my current home page, and I have never had it redirect when opening firefox and loading my home page.

Keep the good questions coming, we'll find a solution some how!
 

gamblingman

VIP Member
Well I have a thought, but first I'd love to see some new HJT and Malwarebytes logs, just to be sure we aren't spinning our wheels.

So if you could re-scan with both and post the logs it may help to know where we are on this. Please update and scan with Malwarebytes first and then HJT and post their logs. Don't scan with both at the same time, and please close all open programs before conducting any scans and refrain from doing anything on the computer during the scans.

Also, for connecting to the internet, do you have:
  • Just a modem which is connected via cable to the computer
  • A modem and a router, but they are separate devices
  • A combination router-modem
  • Other - Please Specify

Be as specific as you can on the brand/model of the equipment you utilize. Also include if you have any other local connections through your computer to another computer(s) via router or through any other means, describe the setup.

Is anyone but you using this computer? If there are other users on this computer, are there multiple windows user profiles for each individual?
 
Downloaded and updated SpyBot S&D, immunized, scanned for problems, and printed the following summary:

DoubleClick: Tracking cookie (Internet Explorer: Bryan) (Cookie, fixed)
Right Media: Tracking cookie (Internet Explorer: Bryan) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Clickbank: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2010-08-18 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-29 Includes\Adware.sbi (*)
2010-07-27 Includes\AdwareC.sbi (*)
2010-08-12 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-07-27 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-07-27 Includes\HijackersC.sbi (*)
2010-06-29 Includes\iPhone.sbi (*)
2010-08-02 Includes\Keyloggers.sbi (*)
2010-08-02 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-08-17 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-07-20 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-07-27 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-07-27 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-08-04 Includes\Trojans.sbi (*)
2010-07-28 Includes\TrojansC-02.sbi (*)
2010-07-28 Includes\TrojansC-03.sbi (*)
2010-07-28 Includes\TrojansC-04.sbi (*)
2010-08-17 Includes\TrojansC-05.sbi (*)
2010-08-15 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
 
Downloaded and updated SpyBot S&D, immunized, scanned for problems, and printed the following summary:

DoubleClick: Tracking cookie (Internet Explorer: Bryan) (Cookie, fixed)
Right Media: Tracking cookie (Internet Explorer: Bryan) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Clickbank: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
AdBrite: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: Bryan (default)) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2010-08-18 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-29 Includes\Adware.sbi (*)
2010-07-27 Includes\AdwareC.sbi (*)
2010-08-12 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-07-27 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-07-27 Includes\HijackersC.sbi (*)
2010-06-29 Includes\iPhone.sbi (*)
2010-08-02 Includes\Keyloggers.sbi (*)
2010-08-02 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-08-17 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-07-20 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-07-27 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-07-27 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-08-04 Includes\Trojans.sbi (*)
2010-07-28 Includes\TrojansC-02.sbi (*)
2010-07-28 Includes\TrojansC-03.sbi (*)
2010-07-28 Includes\TrojansC-04.sbi (*)
2010-08-17 Includes\TrojansC-05.sbi (*)
2010-08-15 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll


...still getting redirected
 

johnb35

Administrator
Staff member
Disable/uninstall all add-ons in both broswers and see if the redirects continue. I've been at a loss for the past few days. I worked on one machine and it ended up being the add-ons that was causing the redirects.
 
First of all,
I apologize for the longest delay in response ever!

Second of all,
By god I think you've done it!

I haven't been using the home pc for more than an hour or two a day, but all this time I've just been avoiding using google. Not a big deal since google maps, images, etc. still worked fine.

Anyways, back to the point...

Tried uninstalling and reinstalling firefox. Didn't work. Still got redirected on google searches. Although, since google has changed their search functionality, it mostly happened when using the google search bar in the upper left corner of firefox. (Not google search toolbar, just standard firefox search bar)

Took your advice, and disabled all add ons in both firefox and internet explorer, and now, I seem to get directed accurately to links found in google search results.

After disabling add ons, i can't seem to replicate the problem. Having said this, are there further steps I can take to permanently uninstall the defective add on in my firefox browser?

Thank you big time for all the advice, and especially for the patience! Also, happy Friday!
 

johnb35

Administrator
Staff member
Can you give me a list of what addons you had disabled? That might help pinpoint which one(s) were causing the redirects.
 
Here are screen shots of my Firefox plugins and extensions that i disabled, as well as the list of IE Add Ons I disabled. Let me know if you have trouble viewing them.

addonscreenshots.jpg
 

johnb35

Administrator
Staff member
I'm not positive, but I'm guessing it could be the roboform toolbar as some toolbars usually cause issues like this.
 
Top