Warning your flash player may be out of date! Nightmare please help

jason moffat

New Member
Thread author
Mar 10, 2014
8
This has been a real pain! Every time I open my home page I get the pop up:

WARNING your flash player may be out of date. Please update to continue.

Then I get the redirect bogus update page.

Have followed advice on similar posts but I cant shift it!

I'm using MS Security essentials and I'm always super careful!

I spend days trying to find the root of this to no avail so any help would be massively appreciated!

Logs attached!

Rgds

Jason
 

Attachments

  • FRST.txt
    151 KB · Views: 155
  • Addition.txt
    14.8 KB · Views: 104
  • aswMBR.txt
    2.3 KB · Views: 72

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hi,


Please download zoek.zip or zoek.rar by smeenk (
Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive...
  • Close any open browsers
  • Temporarily disable your AntiVirus program. (If necessary)
    If you are unsure how to do this please read this or this Instruction.
  • Double click on zoek.exe to run the tool .
    Please wait while the tool does not start...
  • Copy the text present inside the code box below and paste it into the large window in the zoek tool:

    Code:
    createsrpoint;
    gpt.ini;z 
    C:\Windows\System32\GroupPolicy;v
    C:\Windows\SysWOW64\GroupPolicy;v 
    StandardSearch; 
    emptyfolderscheck; 
    installer-list; 
    installedprogs; 
    uninstall-list;
  • Click on
    Run%20Script%20by%20zoek.png
    button.
    Please wait until a logreport will open (this can be after reboot)
  • Save notepad to your Desktop and attach here zoek-results.log
    Note: It will also create a log in the C:\ directory named "zoek-results.log"
 
  • Like
Reactions: jason moffat

jason moffat

New Member
Thread author
Mar 10, 2014
8
Here are my results! It was too big to cut and paste. I got an error message!
 

Attachments

  • zoek-results.txt
    189.7 KB · Views: 300

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Re-run Zoek once more with this script:


Code:
C:\Users\hexan\AppData\Local\Mobogenie;fs
C:\Users\hexan\daemonprocess.txt;f
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r
"mobilegeni daemon"=-;r
C:\Program Files\Mobogenie;fs
autoclean;
emptyclsid;
emptyalltemp;
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's run another scan:


1. Please download ComboFix by sUBs from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
Note: ComboFix must be downloaded to your Desktop.


--------------------------------------------------------------------
2. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
If you are unsure how to do this please read this or this Instruction.

--------------------------------------------------------------------
3. Run ComboFix. Click on I Agree!

- ComboFix will display DISCLAIMER of warranty on software.
By clicking I Agree ComboFix shall continue.

- ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
-If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
- ComboFix will scan your computer in stages, total of 50 stages.
Do not mouse-click around while ComboFix is running.
Note:If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart your computer.

--------------------------------------------------------------------
4. When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
Attach log reports ( ComboFix.txt) back to topic.




Download TDSSKiller and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Confirm "End user Licence Agreement" and "KSN Statement" dialog box by clicking on Accept button.
  • Press Start Scan
  • If Suspicious object is detected, the default action will be Skip, click on Continue.
  • If Malicious objects are found, select Cure.

Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.
 
  • Like
Reactions: jason moffat

jason moffat

New Member
Thread author
Mar 10, 2014
8
Here combo log.

TDSS found nothing and produced no log file!

Thanks

J
 

Attachments

  • combofixlog_10_03_14.txt
    12.3 KB · Views: 159

jason moffat

New Member
Thread author
Mar 10, 2014
8
spybot search and destroy found win32.2urface.bho - it categorised it as very critical!

It claimed to fix it but after a reboot the browser hijack remains! : (

Damn this thing!

I installed a new hard drive this week and it found me again! Worried it could be on my 2nd slave drive!

I wonder if Microsoft Security Essentials is any good as I have never clicked anything stupid or fallen for any traps!

J
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top