firefox & spybot results gone mad!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by buttmunch, Jul 15, 2005.

  1. buttmunch

    buttmunch Private E-2

    since i started using firefox ,i now get everytime i run spybot these results

    advertising.com 10 entries
    avanue a 1 entry
    double click
    fast click 5 entries
    hitbox
    mediaplex
    webtrends live


    i never had these on ie ? whats going on ? how do i stop them?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please follow standard cleanup procedures as given below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps below:



    [​IMG] Download HijackThis 1.99.1

    [​IMG] Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    [​IMG] Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    [​IMG]Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    [​IMG]Run HijackThis and save your log file.

    [​IMG] Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    [​IMG]Need help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. buttmunch

    buttmunch Private E-2

    this is really frustrating ive only just got my pc back to normal on this thread

    http://forums.majorgeeks.com/showthread.php?t=67352

    ive never had any of these before spybot is ALWAYS clear ,its only since i started using mozilla on wednesday that these have arrived?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are just cookies! They are not problems. Most spyware applications flag all kinds of cookies. Many cookies are good things.

    If you do not want any cookies (not really a good idea), disable them from being put on your PC in FireFox's Options --> Privacy screen.

    A better choice would be to allow cookies and only keep them until you close FireFox. Personally I don't do that either. I do not really worry to much about them. I use CCleaner to run cleanups and I configure it to keep the cookies that I do not want to remove. (Like majorgeeks and many others).
     
    Last edited: Jul 15, 2005
  5. buttmunch

    buttmunch Private E-2

    the online scan just reported these ? these arent cookies are they?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which online scanner? No they are not cookies but the items in your Norton Quarantine are not problems. They were quarantined by Norton. That does not stop other scanners from looking at them. Just like when you fix things with HijackThis, it makes backups just in case things go wrong. Any malware in the backups is still detected by some scanners because they are not smart enough to realize where they are at is a backup or quarantine folder from another program.

    The ones in System Restore are surprising. Did you have System Restore disabled last time we worked on your PC. How do you already have 58 restore points saved (some of which contain malware)?
     
  7. buttmunch

    buttmunch Private E-2

    bit defender found them ,system restore is off ,has been for months?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange. With system restore store disable, the items found in C:\System Volume Information should not exist.
     
  9. buttmunch

    buttmunch Private E-2

    whats also strange is i just did the online virus scans as reported to you and then stinger ,then i ran adaware and spybot, spybot found them all again?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The online scans and Spybot are not finding the same things. Spybot is reporting cookies which can occur if you are using any browsers at all and going to any websites. You will even get some cookies from MG's
     
  11. buttmunch

    buttmunch Private E-2

    what do you suggest then mate? shall i put up a hjt report?
    its quite ironic how i went over to mozilla and within 2 days got a virus ,d you not think lol
     
  12. buttmunch

    buttmunch Private E-2

    incidently just ran bitdefender again it found in c;recycler\nprotect.00010207.scr infected with trojan ,disinfection failed , deleted
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That file is not a problem. It is because you use Symantec/Norton and have the erase protection program (Nprotect) running. Things you have deleted are being backed up just like quarantine folders for virus scanners do. There are always problems like this when scanning. You need to learn to recognize what you have installed and running and what folders the programs use. These kind of detections are not truly false detections (sometime called false positives) but they are detections of items that have already been fixed. If you want to stop this from happening, you have to remove all backups/quarantines etc that have been made. Also, you must either disable this Nprotect program or tell it to dump anything it has saved.
     
  14. buttmunch

    buttmunch Private E-2

    ok. so now what? well heres a hjt log ,post all the scans in safe mode as instructed. the hjt was done in normal after.
    what should i do with the system restore problem? if you think there is one?
    what is also strange is those cookies re appeared before id even been surfing the web again? i still cant understand where i picked the virus up either? i havent been on it hardly and only safe sites.
     

    Attached Files:

  15. buttmunch

    buttmunch Private E-2

    just a quick add on , ive noticed ccApp not responding popping up more recently and also on my defrag its shows alot of reserve space ,which is usually system restore stuff isnt it? is this why my system restore is showing up odd?

    also i installed ads spy and when i try to run it, it says it cant because i dont have ntfs system , but i do!!!???
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would still like to know what the below is for:

    O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe

    I asked you this in your previous thread but you did not know what it was. I would like to get some more info on the RUNXMLPL.exe file. Locate it using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.

    The only items in your HJT log they can be fixed are below and they are not malware related problems.
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    Go back and double check to make sure System Restore is truly disable. Also look for the following folder C:\System Volume Information and tell me if you see it.


    The below steps can be used to delete either all restore points except the latest one, or all the restore points. I would have expected all of them to already be deleted after doing step 1 in the READ ME FIRST.

    •To delete all restore points except the latest one, use the Disk Cleanup utility. Click Start, All Programs, Accessories, System Tools, and then Disk Cleanup. Click on the More Options tab and then select Clean up in the System Restore dialog box.


    •To delete all the restore points on your computer, disable and re-enable System Restore on the system. Click Start, Control Panel, and then the System icon. Click on the System Restore tab in the dialog box, select the Turn off System Restore check box, and click Apply. Clear the check box again to re-enable System Restore and then click OK.


    •You can reduce the number of restore points saved by decreasing the total amount of disk space available to System Restore. Note that less available disk space will decrease the relative number of restore points.
     
    Last edited: Jul 16, 2005
  17. buttmunch

    buttmunch Private E-2

    company is wistron version 1.0.0.1 ,


    sorry where am i looking for C:\System Volume Information.

    did all the rest you asked to ,just waiting for your advice on above?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Looks like it may be for a graphics card.


    That tells you where to look for it. Its drive C and the folder name is System Volume Information

    It is normally a hidden folder, so if viewing of hidden files it enabled you should be able to see it in Windows Explorer.

    You did not say whether you double checked that system restore was disabled.
     
  19. buttmunch

    buttmunch Private E-2

    yeh double checked restore defo off, cant see that sys volume folder and ive got hidden files to off. ok?
     
  20. buttmunch

    buttmunch Private E-2

    you missed this i think to mate cheers


    also i installed ads spy and when i try to run it, it says it cant because i dont have ntfs system
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean it is set to Show Hidden files and folders? I would interprete Off as Do not show hidden files and folders.

    Also make sure you DO NOT have a check on the setting that reads: Hide protected operating system files (Recommended).


    If there is no System Volume Information folder, why would you get the below messages from the scan you ran in message number 5?


    Deleted
    C:\System Volume Information\_restore{DBC7BF2C-7EA5-4E93-A1A8-F5F60F9746C0}\RP58\A0009867.scr

    Infected with: Trojan.Downloader.Small.AXR
    C:\System Volume Information\_restore{DBC7BF2C-7EA5-4E93-A1A8-F5F60F9746C0}\RP58\A0009867.scr

    Disinfection failed
    C:\System Volume Information\_restore{DBC7BF2C-7EA5-4E93-A1A8-F5F60F9746C0}\RP58\A0009867.scr
     
    Last edited: Jul 18, 2005
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please always give exact error messages. While I'm not sure right now why you got this error, I see no reason to run ADS Spy anyway.
     
  23. buttmunch

    buttmunch Private E-2

    yes it is set to show files and now i can indeed see the system volume folder it says its empty
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If things were set correctly, why couldn't you see it before?

    But if it is empty, your problems with infected files there are gone.

    So what problems if any are you still having?
     
    Last edited: Jul 19, 2005
  25. buttmunch

    buttmunch Private E-2

    ccApp not responding now and then and ADS SPY saying cant install coz not ntfs when my pc is?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may need to uninstall your Symantec/Norton AV program, reboot and then reinstall.

    I repeat for ADS Spy:

     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Open up a command prompt window by click Start, Run and enter cmd and click OK.

    Now enter the following command at the command prompt follow by the enter key.
    chkdsk

    Tell me what the first line you see says after hitting the enter key. Let the command run to completion and tell me if you see any problems.
     
  28. buttmunch

    buttmunch Private E-2

    as i has errors i thought it be best you look yourself
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run chkdks /f and it will fixed the errors.

    As an alternative you can do an Error-Check on your drive by right clicking on the C drive from explorer and then select Properties and Tools. Then click Error-Checking Check Now. Select Automatically fix file system errors.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds