Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
   
 
Closed TopicStart new topic
ISpyware Fake Security Alert [CLOSED]
savannahterp
post Nov 30 2008, 09:59 AM
Post #1


New Member
*
Posts: 2
OS: Windows XP Pro



Hello everyone.

I recently had the google redirect virus plus some other not so nice items that also prevented me from updating my AVG (gave me the cannot connect message)-- initially I was running with AVG antivirus and Windows Defender. This weekend I installed Ad-Aware 2008 and StopZilla (have since read a mix of stuff mostly bad re: this product), but after running scans and deleting infected items I am down to a fake security alert box popping up stating that I have a malicious Spyware.ISpynow running on my machine and then if I click on the enable button it takes me to a site where it wants me to download a rogue program. I am looking for some advice here on how to get rid of this fake alert and make sure my machine is clean. I am leaning towards doing a re-install of Windows XP, but was wondering if that is a 100% effective way to get rid of everything harmful OR if there is still a good way to make my PC clean without having to reinstall the OS. Thanks to anyone who takes the time out of their busy day to answer my questions.
Go to the top of the page
 
+Quote Post
greyknight17
post Nov 30 2008, 10:27 AM
Post #2


Malware Expert
Group Icon
Posts: 16,559
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Welcome to GTG.

Is this happening to all the computers in your house (assuming you have more than one)? If so, it could be a hijacked DNS entry in the router.

It sounds like a case of Zlob/DNSchanger that change the router's DNS settings. Please download Malwarebytes' Anti-Malware from Here or Here

Next disconnect your system from the internet, and your router, then…

Double Click mbam-setup.exe to install the application.
  • Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
===============================================

Next you must reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds). If you don’t know the router's default password, you can look it up HERE

However, if there are other Zlob-infected machines using the same router, they will need to be cleared with the above steps before resetting the router. Otherwise, the malware will simply go back and change the router's DNS settings. You also need to reconfigure any security settings you had in place prior to the reset. Check out this site here for video tutorials on how to properly configure your router's encryption and security settings. You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

Once you have ran Malwarebytes' Anti-Malware on the infected system, and reset the router to its default configuration you can reconnect to the internet, and router. Then return to this site to post your logs.

===============================================

Please post the Malwarebytes log and let me know how things are running now.
Go to the top of the page
 
+Quote Post
savannahterp
post Dec 1 2008, 07:18 PM
Post #3


New Member
*
Posts: 2
OS: Windows XP Pro



Thank you for your reply.

My laptop appears to be the only one infected. At least at this time, but there are 2 others in my home who use their computers every day and they are not experiencing any problems.

I am going to go ahead and do a clean wipe of my computer and reinstall the OS-- there's nothing I need on there anyway. You've brought up an interesting concern though regarding our router and home network. Unfortunately I won't have any free time until next weekend to work on my machine, unless of course the problem surfaces on either of the other computers we use in the home. I just wanted to mention this, as I appreciate your response but it will be until next weekend before I can follow the steps you shared with me. I'll let you know how it goes-- thank you for your time.
Go to the top of the page
 
+Quote Post
greyknight17
post Dec 2 2008, 06:52 PM
Post #4


Malware Expert
Group Icon
Posts: 16,559
From: New York
OS: Windows 98, XP, Vista, Mac OS X



A reinstall is not needed at all for this. Malwarebytes' should be able to remedy most of the problems after the first run smile.gif
Go to the top of the page
 
+Quote Post
greyknight17
post Dec 9 2008, 07:59 PM
Post #5


Malware Expert
Group Icon
Posts: 16,559
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts   2 / 373 10th February 2008 - 06:52 PM
sandrunner started - last by Rorschach112
No New Posts   11 / 884 26th October 2008 - 10:37 PM
vanessy started - last by fenzodahl512
No New Posts   2 / 246 27th November 2008 - 07:41 AM
undy started - last by Rorschach112
No New Posts   8 / 174 11th September 2009 - 11:34 AM
spider439 started - last by Essexboy

RSS Time is now: 8th November 2009 - 12:03 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising