Adware.Agent.NFX

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by GuyM, Oct 1, 2007.

  1. GuyM

    GuyM Private E-2

    I have a strange Adware problem. I dont know what else to say other then the name of what NOD32 pops-up.

    Threat:
    WIN32/Adware.Agent.NFX Apllication

    File:
    Main_Uninstaller.exe

    C:\Documents & Settings\Admin\Local & Settings\Tempac8zt2

    Comment:
    Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.

    -----

    I also get: msmdev.dll, nsduo.dll, rmv.exe & msmhost.dll.

    Any help, advice or suggestions will be very appreciated. I have googled for 30 minutes & got no where.

    Thanks.
    GuyM

    [EDIT] I downloaded Video Access Codec v1.4 - I think it is the cause. I can not uninstall it. I also have a new tool menu on IE7 - Remove popups, Scan spyware, Secruity test & spam Protection.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    IMPORTANT: Do NOT run any other options until you are asked to do so!
    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.
    Now attach new logs from:

    * GetRunKey
    * ShowNew
    * HJT

    How are things working now?
     
  3. GuyM

    GuyM Private E-2

    SmitFraudFix v2.234
     

    Attached Files:

    Last edited by a moderator: Oct 1, 2007
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the logs..:)
     
  5. GuyM

    GuyM Private E-2

    Logfile of SmitFraudFix v2.234

    Rapport is the first logfile I got
    Rapport1 is the second while in Safe Mode.

    I am pretty bad at this stuff so I am sorry for being slow.

    I am very greatful for your help.

    [EDIT]

    What are these and how do I get the logfiles?
    * GetRunKey
    * ShowNew
    * HJT
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They are from the Read and Run First sticky ...which should have been followed from the beginning ...though I wanted you to get somewhat clean initially ...so now follow that thread and you will see how to run and attach those logs.:)
     
  7. GuyM

    GuyM Private E-2

    I usually read the sticky's, but for some reason made a new thread. I will read them now.

    Again thanks alot for your help.

    [EDIT]

    HJT Log Below.
     

    Attached Files:

    • HJT.txt
      File size:
      6.6 KB
      Views:
      1
    Last edited: Oct 1, 2007
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's what we're here for ....attach the logs when you are finished so we can make sure there are no leftover remnants of malware.:)
     
  9. GuyM

    GuyM Private E-2

    Hey.

    Sorry for taking so long. My computer packed in last night when I was working.

    I have HJT, getrunkey & shownew logfiles. I have run NOD32, CCleaner, CounterSpy, Cleanup, Spybot Search & destroy, Registery Mechanic, Erhm XoftSpySE (Unregistered).

    Most things are fine :)

    Logs:

    HJT is in previous post.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You downloaded and installed HJT in the exact place we tell you not to do:
    C:\Documents and Settings\admin\Desktop\Virus-killer\HijackThis.exe

    It should be:
    C:\Program Files\HijackThis\analyse.exe ---> note that it must be renamed!

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 9
    Viewpoint Media Player

    You have Counterspy installed ...did you run it and did you have it fix all that it found? I'd like to see the log from that also.

    What do you mean by:
    What exactly happened?

    At the moment I am not seeing much in the way of malware that we haven't already addressed....tell me what is happening.

    Please attach a new log for HJT after you re-install and re-name it. And the Counterspy log, also.
     
  11. GuyM

    GuyM Private E-2

    I had Zlob trojan & Adware agent. Now It seems it has gone. All the information I got from the forums helped me. I had HJT already installed before & never noticed I had to install it elsewhere.

    I will look for the CounterSpy Log. CCleaner cleared ALOT of mess up for me.

    I dont know how to get the log itself. So I will copy the scan history & attache that.

    My computer is slow anyhow & I think I upset it. It was Messing around after I installed a Codec, which I think was Zlob Trojan. The Codec is put on PC's through adult sites, apparently to help view certain video's. Honestly though I dont remember ever downloading the codec from a porn site. I remember searching for Realtek driver & must of messed up & downloaded/Installed it.

    My computer WAS closing folders I was opening, Flashing every so often & bam, folder I was in gone. It attempted many times putting msmdev.dll, nsduo.dll, rmv.exe & msmhost.dll in a folder: C:\Documents & Settings\Admin\Local & Settings\Tempac8zt2. That is all sorted, NOD32 deleted them after some trouble.

    You have been very helpful. Im not the best at this & with work I have not been able to sit down to help you help me - That I am sorry for.

    I will delete those programs you mentioned now. I will download HJT shortly & install it where you said to. I must go back to work.

    Thanks again.

    [EDIT]

    Why do I need to remove these;
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 9
    Viewpoint Media Player

    I will do now, but why?
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem ....you are looking pretty good...so I just want to see the HJT log when you can get to it.

    Glad to hear most things are cleared up!:)
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Old Java versions make your system vunerable to attacks ....
     
  14. GuyM

    GuyM Private E-2

    Ok I re-downloaded it & let it extract to Prgram Files, I renamed it as you said. The log is attached.

    The log has so much in it. I wish I had an idea of what any of it meant. Thank god that forums such as this excist. Thanks to you & to those who help this forum.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    You may wish to install a startup manager ....

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  16. GuyM

    GuyM Private E-2

    Thanks alot.

    I am going to keep CounterSpy & afew other things that find & destroy Malware etc. The rest I will delete.

    I have book marked this site & will probably be back shortly rolleyes

    My brother could do with your help, he is far worse then me, maybe he will join.

    Thanks again!

    Guy M
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.....as to your brother ..the more the merrier!! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds