CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Suspected Malware Bell / Zlob - analysis needed

 
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
CubreaYmtic

Cadet
Cadet


Joined: May 16, 2008
Posts: 1
Location: UK

PostPosted: Fri May 16, 2008 5:13 pm    Post subject: Suspected Malware Bell / Zlob - analysis needed
Reply with quote

I contracted a virus a few weeks ago and after hours of research (and a handful of tantrums) I still have no idea how to get rid of it. I got the virus trying to download a crack for a game.

The problem:

Every time I change internet page I get a red box System Error! box which says the following:

Quote:
Your system is infected with serious virus!
Note: Strongly recommended to clean your system and avoid total crash of your computer!

Click OK to download the antispyware. (Recommended)


(The message has also come up when I've been using a few other programs or on system start-up.)

I've accidentally clicked OK rather than Cancel a couple of times because when the box comes up the cursor automatically moves to that button. When that's happened I've denied the downloader permission to start but I've seen the names of the 'corporations':

ieantiavdownload.com

The other symptom is that my websearches are all being warped. It tells me I've been hit by porn and all the search results link to sites that try to get me to download fake solutions:

Popup installation request
malwarebellagreement.com

Also, conveniently, all attempts to look for legitimate solutions fail to turn up any results as a blank page is loaded.

Arrow Can anyone tell me what I need to do to get sort this out because I really don't know what I'm doing. If not, I have hijackthis so could post a log file if it is needed.

Thanks in advance,

Cubrea Ymtic

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17403

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sun May 18, 2008 7:14 am    Post subject:
Reply with quote

You need to post a HijackThis Log to get help in this forum.

Please follow the instructions >>>HERE<<< at #5.

Please do NOT post the log here as an attachment. Post it in plain view. Thanks.


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer