This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Malware infection similar to "Antivirus System Pro"

110 min read

This thread's last reply is from January 29, 2011, 3:11 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hi via,

I noticed that when I open "My Documents", I see transparent icons that start with the "~" or "~$" symbols. Is that normal?


That sounds like temporary files that are hidden, they should not show once you have run OTL cleanup. If they still show then

  1. Open Windows Explorer by right-clicking the Start button and left clicking Explore
  2. Then select the Tools menu and click Folder Options
  3. Select the View Tab, Under the Hidden files and folders heading select Do not show hidden files and folders
  4. Check the Hide protected operating system files (recommended) option
  5. Click OK


I have an external hard drive on which I backed up all my files. Should I have scanned that hard drive with any of the tools you suggested in this thread?


A full scan with your antivirus should be sufficient.

When I ran WinPatrol, it said "A change had been detected in the following Registry Location which you've asked to be monitored. Is changing this value OK? Software]Microsoft\Internet Explorer\Download CheckExeSignatures:no" Should I click "Yes" or "No" for that?


Click Yes.
Hi deltalima,

I uninstalled Avast and installed my preferred antivirus program, Webroot's Spy Sweeper with Antivirus. I decided to run a scan, just to see if anything would come up. It did.

This is what it detected:

about cookie
ic-live cookie
Troj/FFAdRedr-A
Troj/JavaDI-BE
trojan-downloader-karagany


As you can see, there are three trojans that none of the other programs picked up. I also got some sort of warning while trying to access a Webroot's blog, which contained information about the third trojan. The first was that a program on my computer was blocking "google.ad.sgdoubleclick.net". Later, a message on a browser window popped up: "Navigation to the webpage was canceled. What you can try: Refresh the page."

I also scanned my external hard drive on a clean computer using Webroot's Spy Sweeper with Anti-virus, and found a Troj/JsInject-A on it.

Should I run new programs to get these off my system?
Should I run new programs to get these off my system?


No, please post the log from Webroot with details of the detections.
Hi deltalima,

I can't seem to find the .txt log. I looked under "Program Files." I also looked under the Webroot folder, but I found nothing.

The following stuff I copied by hand:

-Troj/FFAd-Redr-A
c:\documents and settings\owner\local settings\application data\{8c1ed365-1623-474a-a1c8-848669cfbd75}\chrome\content\overlay.xul

-Troj/JavaDl-BE
c:\documents and settings\owner\doctorweb\quarantine\4c997ec4-45b314d2

-trojan-downloader-karagany
C:\Documents and Settings\Owner\Application Data\Adobe\plugs

Webroot doesn't offer email customer service. I'll wait for your instructions before I call them and ask them where this log is. (If you want me to post the cookie locations, let me know...)
Hi via,

It's safe to let Webroot remove those files, then you will be good to go.

Any further questions?
As this issue appears to be resolved,