webbyguy
2010-12-21, 07:50
First thanks for your help.
Today, I got a fake antivirus program on my computer that didn't go away on my first attempt, so I tried some more, and ended up here. Unfortunatly, I had tried a few things before I got here, so I hope I didn't mess anything up. I got the virus by following a link to a friend's blog (that were posting family pictures). The website came up, but it also opened a blank pdf. I'm guessing it was a acrobat vunerability. From then on I had been getting pop ups warning that my computer was under attack.
I tried to install spybot, but could not at first. I then went to my other computer, and made a avg boot disk and a spybot boot disk. AVG found the virus files, and deleted them. spybot didn't find anything. I restarted and the problem was still there.
I shut down the system and started in safe mode. It appears in safe mode the virus/trojan doesn't run. I ran spybot, and it found "fraud.sysguard", and says it fixed it. It's log is below. I also downloaded malewarebytes anti-malware to my other computer, and transfered it with a thumb drive to the problem computer. (I hadn't seen the warning not to use a thumb drive on this site before I did that). The anti-malware didn't find anything (again, it was run after spybot had already cleaned).
I am afraid that when I start again out of safe mode the problem will still be there. What should I do next?
Thanks
Spybot Info:
Fraud.Sysguard: [SBI $1D5B98D0] User settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-975534454-977753286-5522801-46786\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\LowRiskFileTypes
DoubleClick: Tracking cookie (Internet Explorer: FFMYGT) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2010-12-20 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-10-05 Includes\Adware.sbi (*)
2010-11-30 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2010-12-14 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2010-11-30 Includes\Hijackers.sbi (*)
2010-11-30 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2010-12-14 Includes\KeyloggersC.sbi (*)
2010-12-14 Includes\Malware.sbi (*)
2010-12-14 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-12-14 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-12-14 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-12-14 Includes\Spyware.sbi (*)
2010-12-14 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-11-02 Includes\Trojans.sbi (*)
2010-12-16 Includes\TrojansC-02.sbi (*)
2010-12-16 Includes\TrojansC-03.sbi (*)
2010-12-16 Includes\TrojansC-04.sbi (*)
2010-12-16 Includes\TrojansC-05.sbi (*)
2010-12-16 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
DDS log:
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 5364
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
12/20/2010 9:59:15 PM
mbam-log-2010-12-20 (21-59-15).txt
Scan type: Full scan (C:\|U:\|)
Objects scanned: 461559
Time elapsed: 1 hour(s), 15 minute(s), 55 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Sorry for the double post, but I had a little more info.
Mcaffe on virus scan didn't find anything either.
Also, I found some people wondering about system restore points, and I one for about every day. I don't know if fraud.sysguard would have gotten to those too.
Oh one other question: Should I leave my computer off while waiting for a response or leave it on in safe mode or ...?
Today, I got a fake antivirus program on my computer that didn't go away on my first attempt, so I tried some more, and ended up here. Unfortunatly, I had tried a few things before I got here, so I hope I didn't mess anything up. I got the virus by following a link to a friend's blog (that were posting family pictures). The website came up, but it also opened a blank pdf. I'm guessing it was a acrobat vunerability. From then on I had been getting pop ups warning that my computer was under attack.
I tried to install spybot, but could not at first. I then went to my other computer, and made a avg boot disk and a spybot boot disk. AVG found the virus files, and deleted them. spybot didn't find anything. I restarted and the problem was still there.
I shut down the system and started in safe mode. It appears in safe mode the virus/trojan doesn't run. I ran spybot, and it found "fraud.sysguard", and says it fixed it. It's log is below. I also downloaded malewarebytes anti-malware to my other computer, and transfered it with a thumb drive to the problem computer. (I hadn't seen the warning not to use a thumb drive on this site before I did that). The anti-malware didn't find anything (again, it was run after spybot had already cleaned).
I am afraid that when I start again out of safe mode the problem will still be there. What should I do next?
Thanks
Spybot Info:
Fraud.Sysguard: [SBI $1D5B98D0] User settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-975534454-977753286-5522801-46786\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\LowRiskFileTypes
DoubleClick: Tracking cookie (Internet Explorer: FFMYGT) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2010-12-20 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-10-05 Includes\Adware.sbi (*)
2010-11-30 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2010-12-14 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2010-11-30 Includes\Hijackers.sbi (*)
2010-11-30 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2010-12-14 Includes\KeyloggersC.sbi (*)
2010-12-14 Includes\Malware.sbi (*)
2010-12-14 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-12-14 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-12-14 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-12-14 Includes\Spyware.sbi (*)
2010-12-14 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-11-02 Includes\Trojans.sbi (*)
2010-12-16 Includes\TrojansC-02.sbi (*)
2010-12-16 Includes\TrojansC-03.sbi (*)
2010-12-16 Includes\TrojansC-04.sbi (*)
2010-12-16 Includes\TrojansC-05.sbi (*)
2010-12-16 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
DDS log:
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 5364
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
12/20/2010 9:59:15 PM
mbam-log-2010-12-20 (21-59-15).txt
Scan type: Full scan (C:\|U:\|)
Objects scanned: 461559
Time elapsed: 1 hour(s), 15 minute(s), 55 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Sorry for the double post, but I had a little more info.
Mcaffe on virus scan didn't find anything either.
Also, I found some people wondering about system restore points, and I one for about every day. I don't know if fraud.sysguard would have gotten to those too.
Oh one other question: Should I leave my computer off while waiting for a response or leave it on in safe mode or ...?