I have tried using FixIEDef and it came back as no malicious programs have been found. I have also tried various virus programs which just cant seem to find it. I have no idea where i got this program and it just started happening tonight. I dont want to reformat my comp as i only just did it last week.
Heres my HiJackthis log,
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:12:56 PM, on 7/5/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal
During the download rename Combofix to Combo-Fix. This is important do not rename after downloading. Combofix must be renamed before it is downloaded to your desktop.
Wait for the scan to finish. It won't take very long.
WARNING: FixIEDef will kill all copies of Internet Explorer and Explorer that are running, during removal of malicious files. The icons and Start Menu on your Desktop will not be visible while FixIEDef is removing malicious files. This is necessary to remove parts of the infection that would otherwise not be removed.
Everything will be restored to normal, once the malicious file is removed.
Click 'Exit' once FixIEDef displays the All Finished message.
Choose Tools -> Delete Temp Files and click Delete Selected Temp Files Then after it deletes the files click the Exit (Save Settings) button.
NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
Physically disconnect from the Internet, then disable your anti-virus and any real-time anti-spyware monitors that are running.
Double click Combo-Fix.exe follow the prompts
When finished, the program will produce a log
Note: 1. Do not mouseclick combofix's window while it's running. That may cause it to stall! 2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
WOOHOO....it worked! I did everything you said, i has an issue with Killbox related file mscomctl but found a download which fixed the error and allowed it to work.
I did recieve a pending operations type message at the end of pocket killbox.
Unless you are having problems from Malware it is time to do the final steps
Uninstall ComboFix:
Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
"%userprofile%\Desktop\Combo-Fix" /u
Notes: The space between the cf" and the /u, it must be there.
This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
Delete the C:\Combo-Fix folder from combofix.
Delete everything in C:\!KillBox
Delete the following from your Desktop (If they exist) ISeeYouXP.exe ISeeYouXP.txt FixMe.reg FixReg.reg
Delete the following: (If they exist) C:\ComboFix.txt C:\SDFix
You can delete and unistall any programs I had you download, that you do not wish to keep on the system.
Empty the Recycle Bin
Run ATF Cleaner
In the ISeeYouXP folder double-click HideIT.bat.
Turn off System restore to flush all your restore points then turn system restore back on.
To manually turn off System Restore, follow these steps: 1. Click Start, right-click My Computer, and then click Properties. 2. Click the System Restore tab. 3. Click to select the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK. 4 Click Yes when you receive the prompt to the turn off System Restore.
To turn on System Restore, follow these steps: 1. Click Start, right-click My Computer, and then click Properties. 2. Click the System Restore tab. 3. Click to clear the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
Hi, my comp did the free-virusscan popup as well, and then later I got on and the backgound changed to the red biohazard "you need privacy protection!" I tried the fixIEDef download and nothing happened. I downloaded hijack this. but now my computer is going very slow the backgroun is now the active descktop recovery background and a window pops up saying windows explorer needs to close every so often and I keep having to restart it. so I will try to get a hijack this log on here. I am on another computer now. any suggestions?
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:14: VIRUS ALERT!, on 7/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Safe mode with network support