Trojan.AdClicker, posible others.

Discussion in 'Malware Help (A Specialist Will Reply)' started by newbienoob, Oct 14, 2008.

  1. newbienoob

    newbienoob Private E-2

    When Norton finds one, it deletes it.
    it has found numerous *.exe files in my doc/settings/local settgs directory.
    It deleted each one as they came up, but they keep coming back.

    Can anyone lend me a hand?


    Thanks in advance.
     
  2. newbienoob

    newbienoob Private E-2

    Wow...I hope that someone hasw had this happen to them before, for my sake.

    I came back to post the logs, as per the cleaning instructions...only to find that I only had 2 of the 4 logs.

    After I did everything, I only had the combofix-log.txt and MGlogs.zip.
    The other two are nowhere to be found.

    Shall I do this all over again?

    Thanks.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The instructions do explain how you can find them. The are in your C:\Documents and Settings\useraccount\Application Data folder. You will see folders for both programs. useraccount is your user account name.

    Now matter what, attach the combofix and MGlogs.zip file anyway.
     
  4. newbienoob

    newbienoob Private E-2

    well...this suxx. :eek:
    I pride myself on being able to follow simple directions, but I missed that step.

    Obviously, you were right and they were there.
    I can't believe I missed that small step.rolleyes
    I have all four logs, here are the first two.

    Thanks.
     
    Last edited: Oct 16, 2008
  5. newbienoob

    newbienoob Private E-2

    Here are the next two.

    Thanks again.
     
    Last edited: Oct 16, 2008
  6. newbienoob

    newbienoob Private E-2

    first three logs (all small)
     

    Attached Files:

    Last edited: Oct 16, 2008
  7. newbienoob

    newbienoob Private E-2

    last log.
    I hope you don't mind, but I also included a screen shot of a current find by norton. I looked throgh the logs i sent you and they seem to indicate that it's clean, minus the auto task folder, but check the picture out if you want.

    Thanks again.
     

    Attached Files:

    Last edited: Oct 16, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. newbienoob

    newbienoob Private E-2

    CCleaner crashed near the very end (I ran it 2 times to test)-please see attached screen shot.
    This caused the date/time settings to remain, rather than be reversed by the program at the end, so I had to reset my date and time settings to their proper state manually.

    Things are much better than before

    I ran your CFscript file and etc.. However, after the reboot, the AT scheduler created new jobs again, numbered from 49-72(as you will see in the logs).
    I traced this AT creation to a file in the C:\windows\temp folder. I read on MS's site that this was a self healing folder (so I deleted the folder in it's entirety).
    I forgot to mention before that my VM was running high and I was running out, which was obviously bogging down my PC.
    When I deleted the above folder, all my memory settings returned to normal (now under 1 gb)...but...

    I went one step further and altered your cfscript file to include the new AT jobs and ran through all of the steps again.
    This pretty much cleaned almost everything out. I have no new AT jobs being created now, even after multiple reboots, nor any calls from the windows\temp directory....however...

    Now I got a call from the c:\System Volume Information directory, from a double sub directory, as you will see in the screen shot.
    I can't access this directory to either view or alter.
    I am hoping that my extra steps helped more than hurt.

    Regardless, norton caught that call and deleted the file, but the fact remains that there is a file still on my system causing this.

    I will attach the two pictures in the next post.


    Thanks.
     

    Attached Files:

  10. newbienoob

    newbienoob Private E-2

    screen shot attachments...
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is your System Restore folder and will be cleanup during final steps.

    No it did not. Nothing can remove files in System Restore accept for when System Restore is disable. Then ALL RESTORE POINTS are deleted.

    Your other snapshot is only related to the fact that you do not have Microsoft .NET Framework installed. This was explained in the Using MGtools link in the READ & RUN ME.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  12. newbienoob

    newbienoob Private E-2

    Wow Chaslang, thank you very much for educating me on this procedure.

    This was unbelievable, to say the least. Everything seems good for now (hopefully in the long term). I still don't know how I picked this up, as I do not visit any questionable sites, but I will now monitor even more closely where I am going and what I am agreeing to.

    Thanks again - "you da bomb"
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds