And I though I was a expert. Help needed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Shyura, Apr 6, 2005.

  1. Shyura

    Shyura Private E-2

    Like topic says. I really though I knew everything there i to know about spyware but aparently I was wrong. I have no bloody Idea how this thing got in on my PC.

    When I enter a site I see a quick adress in the down left feeld that says. ad.se.doubleclick.net. THis must mean I have a spyware on my CP right? On some sites I even get popups.

    I am using Firefox and popups should be impossible? I get liked to pages like www7.paypopup.com and after that I get a popup.

    I always have Ad-wach running om my PC
    I tryed to find something with Ad-aware Pro 0 spywares found
    I tryed to find something with Spybot S&D 0 spywares found
    I tryed to find something with Windows AntiSpyware (Beta) 0 Spyware found
    I tryed to find something with Spy Sweeper 0 Spyware found

    All of the lates updates.

    Nothing nothing nothing. Yet i get popups???
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    [​IMG] Download HijackThis 1.99.1

    [​IMG] Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    [​IMG] Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    [​IMG]Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    [​IMG]Run HijackThis and save your log file.

    [​IMG] Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    [​IMG]Need help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. Shyura

    Shyura Private E-2

    Here ya go!

    Like topic says. I really though I knew everything there i to know about spyware but aparently I was wrong. I have no bloody Idea how this thing got in on my PC.

    When I enter a site I see a quick adress in the down left feeld that says. ad.se.doubleclick.net. THis must mean I have a spyware on my CP right? On some sites I even get popups.

    I am using Firefox and popups should be impossible? I get liked to pages like www7.paypopup.com and after that I get a popup.

    I always have Ad-wach running om my PC
    I tryed to find something with Ad-aware Pro 0 spywares found
    I tryed to find something with Spybot S&D 0 spywares found
    I tryed to find something with Windows AntiSpyware (Beta) 0 Spyware found
    I tryed to find something with Spy Sweeper 0 Spyware found

    All of the lates updates.

    Nothing nothing nothing. Yet i get popups???
    Reply With Quote
     

    Attached Files:

  4. Shyura

    Shyura Private E-2

    Done!
     
  5. Shyura

    Shyura Private E-2

    Wow this forum does not work the way Im used to. Well I posted twice now. But the file is still the same
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Is this log from Normal Mode or Safe Mode?
     
  7. Shyura

    Shyura Private E-2

    Normal Mode.

    I can make a new one if you wish. I didn't pay to close attention to the instructions and had a few programs running.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just a really small log, never have saw one without any services running. Anyway, can you explain your problem to me because you have nothing I see in your log.
     
  9. Shyura

    Shyura Private E-2

    Well Im not a big fan of having alot of prosses running.

    Well for every page I enter I connect to a "ad.####" page.

    For exampel if I enter www.loading.se
    My browser also connects to ad.loading.se and/or ad.se.doubelklick.net

    On more popular adress that i vist daily like Narutofan.com or Newgrounds.com I get popups. Often liked from paypopup. And as I said before I'm using firefox

    Edit: It's not only doubleclick there is also some other adress ad.ariz.. something I only see this adress for ½ a secund or less.
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, lets give this a shot!

    Please download DelDomains and unzip it to your desktop.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    Reboot and see if problem is resolved.
     
  11. Shyura

    Shyura Private E-2

  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download & Run CCleaner

    Run the first scan only!

    Let me know if this takes care of it! If not im creating a fix.
     
  13. Shyura

    Shyura Private E-2

  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, just to be safe create a backup of your registry:
    Backing up the Windows registry

    Click Start > Run > type regedit

    Now navigate to the following keys and delete if any of these entries are found.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run(doubleclick.net)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Backup(doubleclick.com)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell ExtensionsApproved(doubleclick.com)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\URLPrefixes(doubleclick.com)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run(doubleclick.net)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Backup(doubleclick.com)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Backup(doubleclick.net)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell ExtensionsApproved(doubleclick.com)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell ExtensionsApproved(doubleclick.net)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\URLPrefixes(doubleclick.com)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\URLPrefixes(doubleclick.net)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Backup(doubleclick.com)

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run(doubleclick.net)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Backup(doubleclick.com)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell ExtensionsApproved(doubleclick.com)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URLPrefixes(doubleclick.com)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run(doubleclick.net)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Backup(doubleclick.com)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Backup(doubleclick.net)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell ExtensionsApproved(doubleclick.com)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell ExtensionsApproved(doubleclick.net)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URLPrefixes(doubleclick.com)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URLPrefixes(doubleclick.net)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Backup(doubleclick.com)

    After doing this reboot, if problems still remains then procede to the following:

    Download and install Microsoft® Windows AntiSpyware during the install make sure you get any updates, now be sure you have ALL browsers CLOSED!

    Please make sure ALL Browser Windows are Closed

    Now allow the Microsoft Antispyware program to run a full scan. After it completes, reboot again in normal boot mode.
     
  15. Shyura

    Shyura Private E-2

    ... I feel like a truble maker :)

    Nothing in the rigister was found. Not a singel one of them keys.
    I did a full system scan with MS Antispyware NOTHING was found.. All browser windows was closed.
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Click Start > Run > type regedit

    Search for:

    doubleclick

    Post the EXACT entries that it finds. Right click and choose copy key name to do this.
     
  17. Shyura

    Shyura Private E-2

    Here I found something intresting:
    HKEY_USERS\S-1-5-21-436374069-1563985344-1343024091-1003\Software\Microsoft\RAS Autodial\Addresses

    Inside here lies all the stupid url i get like:

    HKEY_USERS\S-1-5-21-436374069-1563985344-1343024091-1003\Software\Microsoft\RAS Autodial\Addresses\ad.doubleclick.net
    HKEY_USERS\S-1-5-21-436374069-1563985344-1343024091-1003\Software\Microsoft\RAS Autodial\Addresses\ad.aftonbladet.se
    HKEY_USERS\S-1-5-21-436374069-1563985344-1343024091-1003\Software\Microsoft\RAS Autodial\Addresses\ad.se.doubleclick.net
    HKEY_USERS\S-1-5-21-436374069-1563985344-1343024091-1003\Software\Microsoft\RAS Autodial\Addresses\ad.aboutwebservices.com
    HKEY_USERS\S-1-5-21-436374069-1563985344-1343024091-1003\Software\Microsoft\RAS Autodial\Addresses\ads.fortunecity.com

    .. List goes on here about 70 of them popup adresses lies here.
     
  18. Shyura

    Shyura Private E-2

    Also in :

    HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial\Addresses
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Make a backup of your registry in case you experience any problems with this.

    Go back in the registry and delete the following keys:

    HKEY_CURRENT_USER\Software\Microsoft\RAS Autodial

    HKEY_USERS\S-1-5-21-436374069-1563985344-1343024091-1003

    See if problems remains after this, if not try deleting the other entries found.
     
  20. Shyura

    Shyura Private E-2

    Nothing happend. After deleting I restarted but, nothing. The broser is till connecting to "ad." pages.

    Do you have any other Idea's? If not. I'll start formating
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give this a try!

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixprefix.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixprefix.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add the changes into your registry say yes.
    Does that help?
     
  22. Shyura

    Shyura Private E-2

    Nop, still the same.

    THis is driving me nuts
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not have time to read thru this whole thread. Has BJ had you run HOSTER to fix your hosts file and have you flushed your DNS cache (ipconfig /flushdns run at a command prompt).
     
  24. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    No I have not, lets try it now shall we. :D

    Shyura,
    Please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
     
  25. Shyura

    Shyura Private E-2

    Well finally some result. I no longer get any popups.

    But the problem still remains that the browser tryes to connect to the "ad." adresses. Is this normal behavoir?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you flush you DNS server as I requested?
     
  27. Shyura

    Shyura Private E-2

    Yes DNS flushed hosts file back to original
    no changes and the Popups are back..
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    This has been bugging me, I just want to be 100% sure so lets rule this out.

    Download the Generic Detection Tool - NT/2000/XP

    NOW:

    Unzip the Generic Detection Tool to a safe folder of your choice and run "find.bat" - Allow it as much time as it needs to run. You may get an error message of "File Not Found," but just let it go.

    The tool should generate a long text file. Attach this log as an attachment to your post.
     
  29. Shyura

    Shyura Private E-2

    Here you go:
     

    Attached Files:

  30. Shyura

    Shyura Private E-2

    Did you take a look at it?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That log does not indicate any problems.

    Please download and install (make sure you do the one time update) and then scan with Spy Sweeper
    This is a 15 or 30 day trial! It will scan and fix. Save the log. After running it, immediately reboot into safe mode and run it again.

    Let us know what this finds and cleans or does not clean (posting the log as an attachment would be useful.)

    Also search your PC (using Windows File Search) to look for the following file: iereset.inf

    You should have one in c:\windows\inf and another in an i386 folder (could be c:\i386 or c:\windows\i386).
     
    Last edited: Apr 9, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds