What is this 'infection" reported by Cyber Defender

  • Thread starter ~*Laughingstar 2009*~
  • Start date
L

~*Laughingstar 2009*~

Daave said:
That doesn't look good at all. What you have is basically a hijackware
infection. See these pages:

http://www.techsupportforum.com/net...help-removing-myidentitydefender-toolbar.html

http://www.techsupportforum.com/sec...-requested-malware-virus-spyware-removal.html

Looks like a very involved process to totally remove! Have you
considered running HijackThis and posting to an appropriate forum?
This page has useful information:

http://groups.google.com/group/micr...p.help_and_support/msg/5df5a390367a40fa?hl=en

I have HiJack This . . . (never know how to post the findings though - the
options seem confusing - to me!) Just didn't run it yet, but I suspect this
thing is well hidden or embeds itself in IE. My Windows Firewall's always
on, too. Dang! In re IE, I did stop it from overtaking my primary search
choice! One move forward!
 
L

~*Laughingstar 2009*~

Daave said:
That doesn't look good at all. What you have is basically a hijackware
infection. See these pages:

http://www.techsupportforum.com/net...help-removing-myidentitydefender-toolbar.html

http://www.techsupportforum.com/sec...-requested-malware-virus-spyware-removal.html

Looks like a very involved process to totally remove! Have you
considered running HijackThis and posting to an appropriate forum?
This page has useful information:

http://groups.google.com/group/micr...p.help_and_support/msg/5df5a390367a40fa?hl=en
Great Hijack This - it is the ONLY one that found this terrorist program.

I've copied the results (not long at all!) to my desktop in a Txt file. Now
what? It appears there are about 3-4 files that may be "it," too.

thank you.
 
D

Daave

~*Laughingstar 2009*~ said:
Great Hijack This - it is the ONLY one that found this terrorist
program.
I've copied the results (not long at all!) to my desktop in a Txt
file. Now what? It appears there are about 3-4 files that may be
"it," too.

Post the results to one of the forums from the David Lipman post. Here
are the first three:

Suggested primary:
http://www.thespykiller.co.uk/index.php?board=3.0

Suggested secondary:
http://www.bleepingcomputer.com/forums/forum22.html
http://www.malwarebytes.org/forums/index.php?showforum=7

You'll have to register first. Then you will receive guided help. Good
luck.
 
L

~*Laughingstar 2009*~

EPILOGUE -

I've registed in the first forum - thank all of you for what you do for us!
I don't know what we would do without you volunteering, and helping us 'out
here.'
 
L

~*Laughingstar 2009*~

Daave said:
You're welcome.

OK. I went back and forth with www.thespykiller.co.uk and ran what I was
told to run, including their Combofix (which I didn't want to run, not
knowing about it, but . . .). no answer on that yet. I had already done
everything they recommended, and nothing was found on any list but Hijack
This!

However, I still found that germ in my IE. Moreover, I have a list of items
in my Add Ons from Motive Communications, such as
McciConnectedDevicesX.dll - Shall I remove them?

Add ons concern me b/c I don't know enough about them to judge
intelligently.

One caveat, using Avast, again, it's still delaying my start up each AM, and
I have most operations unchecked that I know how to regulate. It takes up to
5 minutes and that never occurred until I started with Avast.

Thank you, again, very much.
 
D

Daave

~*Laughingstar 2009*~ said:
OK. I went back and forth with www.thespykiller.co.uk and ran what I
was told to run, including their Combofix (which I didn't want to
run, not knowing about it, but . . .). no answer on that yet. I had
already done everything they recommended, and nothing was found on
any list but Hijack This!

Stick with them; they should fix you up. :)
However, I still found that germ in my IE. Moreover, I have a list of
items in my Add Ons from Motive Communications, such as
McciConnectedDevicesX.dll - Shall I remove them?

What version of IE are you running? What is Motive Communications? If
it's the same thing mentioned here:

http://74.125.93.132/search?q=cache...mmunications"+add-on&cd=1&hl=en&ct=clnk&gl=us

(scroll ALL the way down!)

.... you might want to disable them, but only if they are causing
problems. :)
Add ons concern me b/c I don't know enough about them to judge
intelligently.

One caveat, using Avast, again, it's still delaying my start up each
AM, and I have most operations unchecked that I know how to regulate.
It takes up to 5 minutes and that never occurred until I started with
Avast.

Five minutes is acceptable, IMO. But feel free to post to the Avast
forum for more feedback.
 
L

~*Laughingstar 2009*~

Daave said:
Stick with them; they should fix you up. :)

Shall do. thank you.
What version of IE are you running?

IE 7 - all updates current from MS.

What is Motive Communications? If
it's the same thing mentioned here:

http://74.125.93.132/search?q=cache...mmunications"+add-on&cd=1&hl=en&ct=clnk&gl=us

(scroll ALL the way down!)

... you might want to disable them, but only if they are causing
problems. :)
Have no idea; just don't want stuff that may be causing 'problems.' ;-))
Five minutes is acceptable, IMO. But feel free to post to the Avast
forum for more feedback.

Thank you.
--
 
D

Daave

~*Laughingstar 2009*~ said:
Shall do. thank you.


IE 7 - all updates current from MS.

What is Motive Communications? If
Have no idea; just don't want stuff that may be causing 'problems.'
;-))

Thank you.

YW. Please let us know once the hijackware is gone.
 
D

Daave

~*Laughingstar 2009*~ said:
Daave wrote:


MY IE would not let me open this website! Go figure!!!!!

Google cache. Here's the important info:

**************************
Post 1:

Many broadband ISP include a program from Motive that permits them to
monitor and respond to user request for assistance. Names may be Motive
Smart bridge, MotiveSB, Motive Communication, Motive Monitor, Motmon
etc. Often accompanied by an icon in the lower right.

If you have problem with the addon, uninstall it from Add/Remove
Programs.
Delete the Addon by going to Tools > Addon Manager.

Post 2:
Thanks--especially for the link. It turns out this particular add-on
was placed by Verizon FIOS to 'tune' the system for better response, but
in fact had the opposite effect. Disabling it with MSCONFIG did the
trick.

**************************

However, I doubt this is causing you any problems, so I wouldn't
necessarily disable or uninstall anything. But the option to do this is
always there.

Your priority right now, of course, is to eliminate your hijackware!
 
L

~*Laughingstar 2009*~

Daave said:
Google cache. Here's the important info:

**************************
Post 1:

Many broadband ISP include a program from Motive that permits them to
monitor and respond to user request for assistance. Names may be
Motive Smart bridge, MotiveSB, Motive Communication, Motive Monitor,
Motmon etc. Often accompanied by an icon in the lower right.

If you have problem with the addon, uninstall it from Add/Remove
Programs.
Delete the Addon by going to Tools > Addon Manager.

Post 2:
Thanks--especially for the link. It turns out this particular add-on
was placed by Verizon FIOS to 'tune' the system for better response,
but in fact had the opposite effect. Disabling it with MSCONFIG did
the trick.

**************************

However, I doubt this is causing you any problems, so I wouldn't
necessarily disable or uninstall anything. But the option to do this
is always there.

Your priority right now, of course, is to eliminate your hijackware!

Got it - agree! One can become compulsively "clean" after such an idiotic
move (on my part!). Derek from spykiller just responded and said the CD was
not showing up on anything now - whew. It still seems to be imbedded in my
IE, though, but I'm not sure about that, of course. I really only know what
I hear, b/c of my vision (using Dragon and/or ZoomText).

I'll not download any 'Top' programs again w/o checking with all of you.
grrrrr@me!
 
D

Daave

~*Laughingstar 2009*~ said:
Got it - agree! One can become compulsively "clean" after such an
idiotic move (on my part!). Derek from spykiller just responded and
said the CD was not showing up on anything now - whew. It still seems
to be imbedded in my IE, though, but I'm not sure about that, of
course. I really only know what I hear, b/c of my vision (using
Dragon and/or ZoomText).

Make sure Derek knows your IE is still being hijacked. Give as many
details as you possibly can. In case you haven't tried general
housecleaning yet, try this:

1. Close IE.

2. Right-click your IE desktop shortcut and select Properties.

3. Select General tab if necessary.

4. Under Browsing history, click the Delete button.

5. Click the Delete All button at the bottom.

6. When the Delete Browsing History window comes up, place a check in
the box next to "Also delete files and settings stored by add-ons."

7. Click Yes.

8. Wait. :)

9. Reboot your PC.

Try IE again. Is it working better?

If not, try running it in No Add-ons Mode:

1. Close IE.

2. Right-click your IE desktop shortcut and select "Start without
add-ons."

Working better?

If your IE desktop shortcut doesn't have that option, you can accomplish
the same thing this way:

Start | All Programs | Accessories | System Tools | Internet Explorer
(No add-ons)

Let us know what happens.

One more thing:

If you are familiar with msconfig, check to see if there are any entries
for CyberDefender. If you aren't, someone here can help you with that.
I'll not download any 'Top' programs again w/o checking with all of
you. grrrrr@me!

Sounds like a wise move. :)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top