PDA

View Full Version : Total Security, plus others



tntmm6
2009-10-01, 19:24
We noticed Total Security a couple of days ago. I've run Spybot and it found 3 threats and removed them and it's still there. And now we can't run anything else, even Spybot. After many searches I found a post about malwarebytes. I downloaded on an external drive using a different computer, and changed the name, following the directions in this post spyware forum (http://www.2-spyware.com/forum/topic2351.html). I ran the program from the external drive, and it found a e more few and removed them. On the log I saw Total Security, Backdoorbot, Adsense and some others. But now I can't even find the log. It said to reboot, but when it rebooted, it didn't find the external drive, and I don't think it completed the process.

After the reboot, Total Security is still there popping up. The other part of the post said to use ComboFix, but I don't want to do that without help. I'm not super techincal, but can find my way around a PC fairly well.

I hope someone can help us quickly.

Thanks!

I found the log:

Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 3
10/1/2009 12:16:20 PM
mbam-log-2009-10-01 (12-16-20).txt
Scan type: Full Scan (C:\|E:\|)
Objects scanned: 216075
Time elapsed: 1 hour(s), 4 minute(s), 4 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\Kyle\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kyle\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\Kyle\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kyle\Desktop\Total Security.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\iexplore.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
==============

The other part of the post said to use ComboFix, but I don't want to do that without help.
Good idea. :)
Do NOT run 'FIXES' (ComboFix etc) without being asked (http://forums.spybot.info/showthread.php?t=16806)

ken545
2009-10-03, 03:57
Hello tntmm6

Welcome to Safer Networking.

Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.


Please download RootRepeal one of these locations and save it to your desktop
Here (http://ad13.geekstogo.com/RootRepeal.exe)
Here (http://download.bleepingcomputer.com/rootrepeal/RootRepeal.exe)
Here (http://rootrepeal.psikotick.com/RootRepeal.exe)

Open http://billy-oneal.com/forums/rootRepeal/rootRepealDesktopIcon.png on your desktop.
Click the http://billy-oneal.com/forums/rootRepeal/reportTab.png tab.
Click the http://billy-oneal.com/forums/rootRepeal/btnScan.png button.
Check just these boxes:
http://forums.whatthetech.com/uploads/monthly_08_2009/post-75503-1250480183.gif
Push Ok
Check the box for your main system drive (Usually C:, and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the http://billy-oneal.com/forums/rootRepeal/saveReport.png button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.

tntmm6
2009-10-04, 04:32
Thank you for your help. In my haste I had posted in forums on 2 sites. I've been working with the other site, so please remove me from your list. I'm sure there are plenty of other people that need help.

Thank you for all that you and the other sites do. The time you folks put in to helping others to get rid of these parasites must be substantial. I can't even begin to tell you how much it is appreciated.

ken545
2009-10-04, 05:31
tntmm6 , thanks for letting me know.:bigthumb:

This topic is closed