MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 07-20-12, 07:29
Alba37 Alba37 is offline
Private E-2
 
Join Date: Jan 2012
Posts: 7
Thanks: 4
Thanked 0 Times in 0 Posts
Question Malware, inline ads

I have inline ads everywhere, on forums, websites etc. Please see attached screenshot

I am sorry I have been trying to fix this and ran hitman previously before reading the steps for help and advice. I just can't find a solution so any help would be much appreciated.

Thanks
Attached Files
File Type: zip hitmanlog.zip (287 Bytes, 2 views)
File Type: txt mbam-log-2012-04-23 (14-20-25).txt (2.1 KB, 2 views)
File Type: zip MGlogs.zip (310.4 KB, 3 views)
File Type: txt RKreport[1].txt (2.0 KB, 2 views)
Reply With Quote
Sponsored links
  #2  
Old 07-20-12, 07:33
Alba37 Alba37 is offline
Private E-2
 
Join Date: Jan 2012
Posts: 7
Thanks: 4
Thanked 0 Times in 0 Posts
Default Re: Malware, inline ads

Ops, forgot the screenshot!
Attached Files
File Type: zip inline ads screenshot.zip (303.8 KB, 7 views)
Reply With Quote
  #3  
Old 07-20-12, 18:04
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Malware, inline ads

Your logs are clean. Does this only occur when you use Google Chrome to browse the web? Do the same problems occur with Internet Explorer?

__

From Programs and Features (via Control Panel), please uninstall the below:
  • Java(TM) 6 Update 26 (outdated)

I want you to read and follow these instructions: TDSSKiller - How to run

__

Please download OTL by OldTimer.
  • Save it to your desktop.
  • Right mouse click on the OTL icon on your desktop and select Run as Administrator
  • Check the "Scan All Users" checkbox.
  • Check the "Standard Output".
  • Change the setting of "Drivers" and "Services" to "All"
  • Copy the text in the code box below and paste it into the text-field.
    Code:
    activex
    netsvcs
    %windir%\system32\drivers\*.sys /lockedfiles
  • Now click the button.
  • One report will be created:
    • OTL.txt <-- Will be opened
  • Attach OTL.txt to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
Alba37 (07-28-12)
  #4  
Old 07-21-12, 13:00
Alba37 Alba37 is offline
Private E-2
 
Join Date: Jan 2012
Posts: 7
Thanks: 4
Thanked 0 Times in 0 Posts
Default Re: Malware, inline ads

Thanks very much for your help. I can't beleive I have got myself in to bother so fast! I just inherited this computer from my son as mine was chugging along on its last legs!

After taking a while to find IE, (as my son had told me it wasn't installed on the computer and I had believed him at first!) I have checked it and it's fine, so it is a Chrome specific issue. It started around the time I installed utorrent. Which I have since uninstalled again.

Please see attachments as requested, thanks again
Attached Files
File Type: txt OTL.Txt (276.0 KB, 3 views)
File Type: txt TDSSKiller.2.7.46.0_21.07.2012_18.29.49_log.txt (141.4 KB, 1 views)
Reply With Quote
  #5  
Old 07-21-12, 15:57
Alba37 Alba37 is offline
Private E-2
 
Join Date: Jan 2012
Posts: 7
Thanks: 4
Thanked 0 Times in 0 Posts
Smile Re: Malware, inline ads

Good news, I uninstalled the following extensions in Chrome and the problem has gone. I think there was another couple I uninstalled too, GPU something? and another Ad one. So I don't know what caused it but it seems to have gone! Thanks!

Adblock Plus (Beta)
AVG Do Not Track
AVG Safe Search
MonitorTab
Click 2 Save
Reply With Quote
Sponsored links
  #6  
Old 07-21-12, 15:58
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Malware, inline ads

From Programs and Features (via Control Panel), please uninstall the below:
  • Java(TM) 6 Update 26
  • BitComet 1.29 64-bit
  • CleanUp!


Fix items using OTL by OldTimer

Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
Copy the text in the code box below and paste it into the text-field.
Code:
:otl
SRV - [2012/07/12 18:32:22 | 001,239,952 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe -- (Ad-Aware Service)
DRV:64bit: - [2009/07/14 02:47:48 | 000,530,496 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\elxstor.sys -- (elxstor)
IE - HKU\S-1-5-21-1252602699-2952633354-2283345369-1001\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found
IE - HKU\S-1-5-21-1252602699-2952633354-2283345369-1001\..\SearchScopes\{F08CBE59-0BBD-4E81-B857-9B4B0737B6B1}: "URL" = http://services.zinio.com/search?s={searchTerms}&rf=sonyslices
IE - HKU\S-1-5-21-1252602699-2952633354-2283345369-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
CHR - Extension: Click 2 Save = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoinkcpnahjmnkkdkognlihmmebhejhd\1.1_0\
CHR - Extension: The Camelizer = C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghnomdcacenbmilgjigehppbamfndblo\1.5_0\
O3 - HKU\S-1-5-21-1252602699-2952633354-2283345369-1001\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit:] - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
[2012/07/20 21:16:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Antivirus
[2012/07/20 18:44:08 | 000,000,000 | ---D | C] -- C:\Users\Marc\AppData\Roaming\Ad-Aware Antivirus
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Marc\Desktop\*.tmp files -> C:\Users\Marc\Desktop\*.tmp -> ]
[2012/07/21 03:50:15 | 000,027,520 | ---- | C] () -- C:\Users\Marc\AppData\Local\dt.dat
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:0B4227B4
:services 
BITCOMET_HELPER_SERVICE
:files
C:\Program Files (x86)\Ad-Aware Antivirus /d
:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BitComet"=-
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F08CBE59-0BBD-4E81-B857-9B4B0737B6B1}]
:commands
[clearallrestorepoints]
[emptytemp]
Now click the button.
If the fix needed a reboot please do it.
Click the OK button (upon reboot).
When OTL is finished, Notepad will open. Close Notepad.
A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Attach this log to your next message. (How to attach)

__

Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
This updates all of the logs inside MGlogs.zip.
When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
Alba37 (07-28-12)
  #7  
Old 07-21-12, 15:59
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Malware, inline ads

Oh good
Check above as I was planning on removing the "Click 2 Save" addon
You don't have to complete the above set of instructions if everything is OK now
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
Alba37 (07-28-12)
  #8  
Old 07-28-12, 07:17
Alba37 Alba37 is offline
Private E-2
 
Join Date: Jan 2012
Posts: 7
Thanks: 4
Thanked 0 Times in 0 Posts
Thumbs up Re: Malware, inline ads - Solved

Quote:
Originally Posted by thisisu View Post
Oh good
Check above as I was planning on removing the "Click 2 Save" addon
You don't have to complete the above set of instructions if everything is OK now
Thanks a million for your help. Sorry for not getting back sooner, have been under the weather. I really appreciated your help. Thanks again
Reply With Quote
  #9  
Old 07-29-12, 20:52
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,144
Thanks: 263
Thanked 1,412 Times in 1,349 Posts
Default Re: Malware, inline ads

You're welcome.
Be safe
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Need Text Inline With Image - CSS problem? Mada_Milty Programming 4 01-02-07 09:23


All times are GMT -5. The time now is 02:17.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger