Antivirues 360 popup-logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by alma1947, Jan 30, 2009.

  1. alma1947

    alma1947 Private E-2

    I can't remember what I was doing the first time I got the pop-up. But it popped up as soon as I booted up after doing all the steps of the Read & Run Me First, Malware Removal Guide. This started just a few days ago. I am attaching logs.
     

    Attached Files:

  2. alma1947

    alma1947 Private E-2

    Adding my Mglog.zip attachment
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I noticed a reference to yoog, so please do this:
    Yoog Removal

    What is this:
    C:\vale?

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 5

    Now use windows explorer to find and delete:
    c:\windows\system32\AK083E209605E394C.lie

    Reboot and download and install:
    Java Runtime 6

    Tell me if the system32 file is gone.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  4. alma1947

    alma1947 Private E-2

    The c:/vale is a folder where I had downloaded some clips. the Yoog is still there. I probably missed some places where is was stored. The system32 file is gone. I have attached the MGtools log. Thanks
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It was in your FF browser. Please run those instructions again and then get me a new Combo log. :)
     
  6. alma1947

    alma1947 Private E-2

    I did not find it in the list under value.It was not in the searchplugins folder. I could not find a below folder. It still shows up as the default search engine. I tried to go to the Filters/value after rebooting, but when I enter about.config in the address box, it said address not found. Also I did not see the Show All button. The new combo-fix log is attached. The antivirus 360 has not popped up for several days, so maybe something finally caught it. Thanks
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is about : config ---no spaces and not a period but colon :

    about:config

    Try it again.
     
  8. alma1947

    alma1947 Private E-2

    Well, I feel like a big dummy. After reading the instructions carefully this time I saw what you meant by the "below" folder. I tried the "about:config" again. I was looking at the left hand column instead of the right and yoog was there in safe mode and normal mode. When I looked in the"below folder" there was not a "default.zdt folder, but there was a j7fgpo8j.default folder. In safe mode yoog was not in the searchplugins folder, but in normal mode it was, so I deleted it, rebooted and yoog is still showing to be the default search engine. I am about ready to give up, and just click on the arrow and choose google. Thanks
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Next to the address bar in FireFox is a seach box. Click the down arrow and Select "Manage Search Engines"
    If YOOG is listed, highlight it and remove it
    Then Highlight Google and Hit OK.

    Now right click your Start button in the Windows tray and select Explore to open up Windows Explorer.
    Navigate to the C:\Program Files\Mozilla Firefox\searchplugins folder. Locate the one for Yoog or any others you don't want and right click on it and select Delete.

    Also navigate to the below folder and make sure nothing for Yoog appears. Replace UserName with your actual user account name. If you see another searchplugins folder, look in it for anything from Yoog and delete it.

    C:\Documents and Settings\UserName\Application Data\Mozilla\Firefox\Profiles\default.zdt
     
  10. alma1947

    alma1947 Private E-2

    c:program files/mozilla firefox/search plugins
    yoog is not listed

    c:/documents and settings/username/application data/mozilla/firefox/profiles/default.zdt

    replaced username with administrator (which is my user account name)
    there is no default.zdt
    there is j7gpo8.default, there is nothing listed under search plugins

    I also did the manage search engines, removed yoog, highlighted google and clicked ok

    yoog was still there the next time I opened Mozilla
    Thanks, Alma
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is listed under tools / add-ons?
     
  12. alma1947

    alma1947 Private E-2

    Adblock Plus
    Java Quick Starter
    Move Media Player
    Orbit Downloader Firefox Integeration
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try doing a windows search for yoog. Make sure you click the all files and folders as wel as the advanced options.
     
  14. alma1947

    alma1947 Private E-2

    When I do a search it shows up in - c:\documents and settings\administrator\application data\mozilla\forefox\profiles\j7fgpo8j.default/searchplugins. I have already tried deleleting it from this folder, but it comes back the next time I start Mozilla.And twice in the last couple of days the antivirus 360 popup has appeared. Thought I was rid of it. Thanks
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go back to the Read and Run First instructions and download the latest version of MGTools.exe......then re-run the other scans and attach the logs:
    SAS
    MBAM
    Combo
    MGLogs.zip
     
  16. alma1947

    alma1947 Private E-2

    Logs are attached:
     

    Attached Files:

  17. alma1947

    alma1947 Private E-2

    and the MGlog zip
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It appears as though you uninstalled FF. And the only thing I see that is new is this entry from the 13th:
    C:\WINDOWS\system32\a6c719cc-f37b-3f51-dffb-ff84fb266774.exe --> find and delete it.

    Otherwise there is no malware showing in any of the scans or logs.
     
  19. alma1947

    alma1947 Private E-2

    Thanks, yes I uninstalled Mozilla Fire Fox, because it seemed like that was where I was having the pop up and the yoog search problem. I have re-installed the latest version and so far no problems.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.......If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  21. alma1947

    alma1947 Private E-2

    I have Windows Xp, under the disable system restore directions it says to Right click My computer, click properties, click performance tab. I don't see a performance tab.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not reading the XP instructions. They do not say anything about the performance tab. It says the below which is a direct quote from the given link:
     
  23. alma1947

    alma1947 Private E-2

    Ok, thanks
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds