New Thread, please--Fake desktop notice from Acrobat on 32-bit Vista

Discussion in 'Malware Help (A Specialist Will Reply)' started by chriscol, Jun 11, 2013.

  1. chriscol

    chriscol Private E-2

    I can't post a new thread, but this is a different computer, with different symptoms, although the two often share a home network.

    I can't find anything online that describes exactly what I have going on in this one.

    Here's the problem:
    I get this really annoying desktop pop-up notification, supposedly from Adobe. (see jpg attachment). When I check with Adobe properly, they tell me I'm up to date with Reader 10 (11 is still beta). Also, the Adobe symbol is missing, replaced with a star. (Haven't noticed anything else wrong...yet. This is new.)

    Now I realize this message is an invitation to download something I don't want, and I'm smart enough to ignore it. But just the fact that it is ON my desktop tells me that there is something in my computer that I don't want there.

    I've had problems with Windows Defender getting shut off,supposedly by AVG. So I also intend to ditch AVG once I get this cleared up and switch to Comodo. But first things first: what do I have, and how do I get rid of it?

    Windows Vista Home Premium, SP-2
    HP a5414f
    AMD Athlon 64 x2 dual Core Processor 6000+ 3.00 GHz
    3.00 GB RAM
    32 bit OS

    I worked through your procedure, albeit imperfectly. The text logs are zipped together into 5-Logs.zip. That gets me around your attachment limit and allows me to send you a screen-shot of the desktop with the fake Adobe notice.

    ----------Scanning notes:

    Forgot to uncheck the cookies, and inadvertently hit next instead of close w/ Hitman. Hope I didn't screw up anything major!


    Running MGTools: Windows error message:
    ProcessDll.exe - Common Language Runtime Debugging Services

    Application has generated an exception that could not be handled
    Process ID = 0xe94 (3732), Thread Id = 0x1660 (5728),
    Click OK to terminate the application.
    Click Cancel to debug the application.

    Clicked OK. I don't have the skills to debug this!

    Dos Error report: c\MGGLogs.zip failed to be created.

    Ran the batch file, and got the same windows error message as above (closed it again), but this time I got the zip file.
    ----------
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not really seeing any major issues, but let's cleanup a few things and see what happens.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)


    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
     
    :Files
    C:\ProgramData\BBrowseu2save
    C:\Program Files\BrowseToSave
    C:\Windows\Temp\*.*
    C:\Users\Coleen\AppData\Local\Temp\*.*
    
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Search Protection]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9582651F-DE02-497C-BFD4-1FCF2BEA9622}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9582651F-DE02-497C-BFD4-1FCF2BEA9622}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9B41D157-2851-4018-84BF-6B27FAADD4F6}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. chriscol

    chriscol Private E-2

    Thank you for responding. I appreciate the help!!!!!:)

    Notes on cleanup procedures:

    1.
    HJT seemed to work fine.

    2.
    OTM ran the first sections successfully.

    After emptying the temp folders for All Users and Bob, it stalled with this final line in results:
    user: Coleen >temp folder emptied 669326 bytes

    MsgBox:
    "OTM has stopped working. Windows will close programs and notify you if a solution is available."

    I clicked close. There was something minimized at the bottom of the screen--another MsgBox.
    "Microsoft Search Indexer stopped working and was closed. A problem caused the application to stop working correctly.
    Windows will notify you if a solution is available."

    After closing, I had a completely empty desktop. Only the photo left. No icons, no floating task bar to access the start menu.

    I used ctl+alt+delete to bring up the task manager entry screen, and clicked restart from the button.

    3.
    C:\MGtools\GetLogs.bat

    This ran the same way it ran last time, stopping with a windows message box. The Windows text in the box read as follows:
    =========
    Application has generated an exception that could not be handled
    Process ID = 0x1438 (5176), Thread Id = 0xcc0 (3264),
    Click OK to terminate the application.
    Click Cancel to debug the application.
    =========
    I selected OK
    When the batch file finished, I went back and copied the DOS information shown in the batch file just as the program halted--on the off chance it wouldn't turn up in the log file.

    Text in cmdbox
    =============
    running processdll.exe to find loaded DLLs

    Unhandled Exception: System.InvalidOperationException: Process performance counter is disabled, so the requested operation canot be performed.
    at System.Diagnostics.NtProcessManager.GetProcessInfos<Performance CounterLib library>
    at System.Diagnostics.NtProcessManager.GetProcessInfos<String machineName, Boolean isRemoteMachine>
    at System.Diagnostics.ProcessManager.GetProcessInfos<String machineName>
    at System.Diagnostics.Process.GetProcesses<String machineName>
    at System.Diagnostics.Process.GetProcesses<>
    at procdll.modMain.Main<>
    Found and Zipping procdll.txt
    ==============

    I'm re-activating WindowsDefender (Isn't that the Windows Vista Firewall?)

    For what it's worth, last night I ran a couple of additional virus scans (which were all clean). Then I thought that perhaps my Adobe updater had been corrupted, so I repaired Reader. This morning there were some automatic Windows Updates. I haven't seen the crazy update message from the screen shot today--but it doesn't appear every time I reboot--seems to be on some sort of 2 or 3 times a day schedule.

    Please respond to these logs with any relevant information about whether they are clean, or if I need to repair any files--I'm curious about why the batch file and OTM stalled. I'll assume that since I'm in the queue now, I won't bump myself down if I update--and I'll just add a note if and when the fake update message reappears. If it stays gone until tomorrow afternoon, I'll let you know that, as well.
     

    Attached Files:

  4. chriscol

    chriscol Private E-2

    Its baaacckkk! 9:48 PM. About the time it showed up yesterday.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is starting to not look like malware.

    Run Msconfig. Then select the Startup tab. Locate the below process and uncheck it to disable it.

    Startup Item = Adobe ARM
    Command = C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    Then select the Services tab and locate the below service and uncheck it to disable it:

    Service = Adobe Acrobat Update Service

    Then click Apply and okay your way out of MSconfig and reboot your PC. Does this popup come back?
     
  6. chriscol

    chriscol Private E-2

    I took your advice. However, the "update" is back again. Seems to show up every evening around 9:45 CDT. Never any other time of day, so if you have any more ideas, I'll try them--but won't know the results until 9:45 that night.

    (FWIW, I just ran msconfig to check; Adobe updating is currently off.)

    One thing comes to mind--really a long shot, but could the other computer on my network possibly be harboring this thing? (See earlier thread.)

    The reason I ask is that Comodo (on the Win 7 laptop) spotted an active threat the other day, but it was coming from a directory that exists on this computer (Vista) but not on the other one. That directory is one of those that you had me clean out the other day.

    One other thing that has me curious--why did the clean-up programs you had me run the other day get stuck? Did they perhaps trip on something?

    I appreciate your efforts on this. It's a corker. I surely dread what might happen if I actually clicked that *^(^ "update".
     
  7. chriscol

    chriscol Private E-2

    Grasping at straws here... is there a known sequence to the Windows Vista shutdown? Because the "update message" blinked out first, before the rest of the desktop wemt all at once when I shut down last night.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you should try installing a better firewall on this PC. The Windows firewall is not very good.

    Possibly if you are using sharing. But this is a good reason why to have a better firewall.

    Most likely just issues with Windows applications. Or due to protection software conflicts.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really.
     
  10. chriscol

    chriscol Private E-2

    I took your advice about the firewall and software; downloaded Comodo and uninstalled AVG. Interestingly, Comodo found no problems, either.

    So I got brave and clicked the &^%* thing.

    Up pops the "View and Review Your Downloads" Window.

    AdobeReaderSetup_8631360-none pops up in first place.

    There's no location, just the question: "Do you want to run or save this program?"

    I saved it to the desktop, and had Comodo run a scan on it. Found nothing.

    But it sure isn't legitimate from Adobe--

    I'm thinking somebody truly expert should take a look at this thing. I'm sending you a zipped copy of it--I notice that it has a valid certificate from "Trusted Software ApS" and a digital signature email address of "Support@TrustedSoftware.com"

    I think you're right, in that I don't have a virus on my system. But whatever this is, it's behavior is sure hinky--and I'd really like to stop getting the message--because I don't feel safe when it keeps coming in.


    More weird. Had a difficult time uploading the file. And when I did, it wasn't the zip file; instead it was coming from C:\Users\Me\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\I3NG9R67\AdobeReaderSetup_8631360-none[1].exe

    Same thing again. The zip archive icon is on my desktop. But your uploader can't "see" any zip files there at all.

    And, although I am supposed to be able to see hidden files and extensions on my computer, I cannot see the \Low\Content.IE5\etcetera subfolders.

    I thought I'd try to rename the exe file on my desktop--surprise, Windows is hiding the extension, so I couldn't just change that.

    FINALLY, I think I have it. I renamed the entire file to FakeFile. At that point the .exe showed up, and I changed that to .txt. And this time I zipped it right away.


    Guess what--the first zipped file has disappeared from my Manage attachments page. I'm going to try to send you both zipped files, but if you only get one, at least you know how to change the name.

    If I need to send this to one of the Antivirus companies, please tell me where it should go. Or perhaps you can fwd it to the right set of eyes, wherever they are.

    Thanks for your patience with this.
    chriscol
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes this is definitely suspicious but not sure it is really malware or if some other program on your PC is trying to cause an update.

    Download and install Revo Uninstaller
    The use it to uninstall File Type Assistant Then reboot your PC. See if that popup still comes back.

    There are many folders that Windows will block you from directly accessing.
     
  12. chriscol

    chriscol Private E-2

    FYI:
    Ran a full Comodo scan. It found two viruses, which it quarantined.
    (After trying several other non-installable scanners which turned up nothing.)

    C:\Program Files\QuickTime\QTSystem\QuickTimeUpdateHelper.exe Suspicious@#1fy9u1087o1ed Quarantine Success
    C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe Suspicious@#2wsru862x9mkm Quarantine Success
    I'm hoping the QuickTimeUpdateHelper was the source of my 9:42 evening visitor. But, of course, I won't know for sure until 9:43 tonight.

    Thanks for the Revo info. I'm going to wait to see if the QuickTime installer was the problem. If not, I'll use the Revo next.

    BTW, I'm very impressed with Comodo. I had to contact their GeekBuddy team twice in order to upload the questionable file to them--no charge for the help, even for someone like me using the free service. Might have been different if I had been asking for help with my computer specifically, but....
     
  13. chriscol

    chriscol Private E-2

    It's 9:53 and no message. Looks like the problem was the QuickTimeUpdateHelper.exe Suspicious@#1fy9u1087o1ed.

    Unless you have questions for me, we can call this thread closed.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I would be surprised if either of those were the problem for the below reasons:

    • They are both legit programs
    • Neither of them were loading at startup
    • Most importantly, they were not showing as running in any logs so not sure how they would be the problem.

    However, let's hope that the problem is gone. If so, you can do the below.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. chriscol

    chriscol Private E-2

    Before you assume any further, take a look at the attached file, which turned up in my Java directory after I had removed the application using REVO.

    I think I'm still clean, but it's amazing the kind of computer damage this thing can do.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These did not show up after removing the application. There were there all along. They are part of QuickTime.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds