getting popups in Firefox

Discussion in 'Malware Help (A Specialist Will Reply)' started by Main Frame, Aug 24, 2008.

  1. Main Frame

    Main Frame Corporal

    As the title states, I'm getting popups in Firefox. It randomly opens a new tab with anything from porn sites, to auto loan. I ran a full scan with ZoneAlarm Security Suite and it found no virus or spyware. I then ran a scan with spybot s&d and it found one thing (virtumond trojan or something). I told it to fix that.. continued getting popups. Then I downloaded ad-aware, ran a full system scan with that and found nothing.


    Everything is up to date. This is on Windows XP Pro. I also have NoScript plugin running on Firefox and peer guardian 2.


    I have no idea where these popups are coming from. I thought about uninstalling Firefox, but then I would have to reinstall all the plugins, and it probably wouldn't help anyways.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Main Frame

    Main Frame Corporal

    Sorry.. just read that. Time to start digging.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just attach the logs when you are finished.
     
  5. Main Frame

    Main Frame Corporal

    Well, luckily I didn't have to go through all that. My anti-virus has finally caught it, but it can't remove it.



    The virus is: not-a-virus: AdWare.Win32.Virtumonde.agnf

    And it is located in: C:\windows\system32\iifdddAS.dll



    It says it will delete on reboot, but of course, it can't. The last time I had a virus like this I was able to remove it by doing a system restore to a point before the virus got on there. Then I ran a scan, found the virus in the restore files, and removed it from there. Then I was able to undo the restore back to the current date.

    Should I go about removing this one the same way, or is there something else I should do?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should be doing what I already asked you to do if you want to get this properly and completely removed.
     
  7. Main Frame

    Main Frame Corporal

    Well okay.. my little trick won't work because that clever son of a.. the file was created 8/23/2008 3:09am and all of my restore points before 8/23/2008 3:10am are gone.



    Of course it would almost be as quick to format as it's going to be to follow all of those steps and then get my settings back how they were.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unlikely unless you have very little on this PC. Most people do not realize what a proper reinstall will entail especially if you want to make sure that malware does not survive the reinstall.

    It's your choice on what approach you prefer to take.

    But a new install involves more than you may think. Especially to get back to a level of where your system is at. You have to consider all of the below:
    • you have to backup all you own data, settings, configurations etc and first you have to know what/where all of these are. And you have to have the medium (burnable media, second hard drive, tape drive [yuck] )
    • then you must make sure you have the necessary disks to reinstall not just your OS but all other software you use especially protection before going online
    • then delete your partitions, recreate partitions, format, reinstall the OS
    • now reinstall all your software especially protection
    • get online (requires some setup and config that novices have problems with)
    • download updates for OS
    • download updates for protection software
    • download updates for all other software
    • tweak all software back the way you like it. Including Desktop settings, icons etc.
    • create all the folders that you use for everything in your normally routines
    • re-load from your backups to get data back, to get settings, Favorites,.....etc back
    • now over the next two weeks you will realize that you forgot to backup some stuff and also you will keep finding something else that you need to reinstall.
     
  9. Main Frame

    Main Frame Corporal

    I think SAS did it.. the scan took about and hour and a half, then it crashed upon removal, so I ran it again and it seemed to work. (can't believe I haven't used this before, it found 20 threats :eek:)


    I didn't run spybot s&d because I've ran it multiple times and it found nothing.


    Then I ran MB anti-spyware and it changed two registry entries and jacked with my start menu, so I'll have to fix that back how I like it.


    Ran MG tools.. some of the log file seemed a little intrusive and I would rather not publish it publicly. But I will include the runkeys log.





    BTW, you're right about the format. The scans took longer that it would have taken to format and install windows, but the thousands of updates take forever. I do have everything backed up on another drive, but it usually takes me about 10 hours to get everything set up.. the scans only took about 5 hours.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need the log.

    I also need the log from ComboFix.


    I cannot help you without the MGlogs.zip file. If you do not think you need anymore help, then just do the below.

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
    Last edited: Aug 29, 2008
  11. Main Frame

    Main Frame Corporal

    Okay, here's the logs from malwarebytes.



    I just ran combofix.. now everything is jacked up, and my anti-virus won't even run. Here's the log from that too..
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat!
     
  13. Main Frame

    Main Frame Corporal

    how can I send it to you without displaying it publicly?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you think is so critical in the logs but you can email it to me at majorgeeks.com. Do realize that any fixes that I may need to post (assuming anything needs to be fixed) will contain info from those logs.
     
  15. Main Frame

    Main Frame Corporal

    sent... sorry about being difficult.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log is totally incomplete. You need to run MGtools again and make sure you accept the HijackThis license agreement and that you allow it to finish running.

    Also it looks like you are getting errors while running it. See the error messages and fixes on the using MGtools download page.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The new log you sent me is complete and there are no remaining malware issues to be concerned with. There was also no reason to worry about attach your logs in the forum as I saw nothing to worry about in the logs.

    You should however attach the below SUPERAntiSpyware log as you ran in multiple times and perhaps this would address your statement about it breaking one of your programs:

    Code:
    "C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    supera~2.log  Aug 28 2008       36067  "SUPERAntiSpyware Scan Log - 08-28-2008 - 20-21-15.log"

    And you are correct that ComboFix appears to have removed some files and registry keys from ZoneAlarm Security Suite. I'm not sure why it would do this as I have not seen it do this before.
     
  18. Main Frame

    Main Frame Corporal

    Okay.. thanks. I will get the rest of the issues sorted.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but I still recommend that you attach that SAS log so that they can look at it to see if they are deleting something they should not be.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds