Strange add ons causing new tabs to open

Discussion in 'Malware Help (A Specialist Will Reply)' started by sberkkoch, Mar 1, 2014.

  1. sberkkoch

    sberkkoch Private E-2

    Hey Everyone,
    I am running Windows 7. I was having trouble w the FIND feature in sumatra, so I updated sumatra, or what I thought was sumatra but in fact it was a different pdf reader from their web site. GR.

    It was tab heaven, with several opening at random.

    I uninstalled the program, the new and unwanted toolbar, ran malaware bytes, CCleaner, Panda, disabled the add ons.

    Browsing was better, the extra tabs that opened on their own (such as one to update firefox, other shopping type pages) stopped, but just in case I followed the instructions in your READ ME thread.

    I've waited a day and browsing is still OK, except I looked at my extensions just now and out of nowhere 'arcade games' appeared. (?) I disabled it. Still no odd pop ups or tabs opening.

    I attached the logs. I think it was Hitman (?) that found a few items that I left alone. I wonder if anyone could look at my logs and advise me about what to do next, if anything?

    I appreciate the help. Thank you!

    Sue
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing much to do. Do you know what this is?

     
  3. sberkkoch

    sberkkoch Private E-2

    Hi Kestrel 13!,
    Thank you for reading the logs. Maybe running the malware bytes did the trick? I have no idea what that IE.exe is. I use Firefox as my browser.

    What do you think it is?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think we should be rid of it.

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : IEBrowserSync ("C:\Users\Sue 2\AppData\Roaming\BrowserSync\IE\IEBrowserSync.exe" [-]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3508457672-3135540269-176784899-1004\[...]\Run : IEBrowserSync ("C:\Users\Sue 2\AppData\Roaming\BrowserSync\IE\IEBrowserSync.exe" [-]) -> FOUND
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Uninstall the below:

    • SaveDailyDeals
    • SavingsBull
    • SavingsBullFilter



    Delete these:
    • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SaveDailyDeals
    • C:\Program Files\Level Quality Watcher
    • C:\Program Files\SaveDailyDeals Updater
    • C:\Program Files\SaveDailyDeals

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. sberkkoch

    sberkkoch Private E-2

    Hi Kestrel 13,
    I followed your instructions. I didn't find any leftover save daily deals but I used revo uninstaller so maybe that did the work for me.

    I've attached the logs. Why don't we remove all the items that Rogue Killer finds?

    Things are working well so far.

    Thank you!

    Sue
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can remove these:
    • [RUN][SUSP PATH] HKCU\[...]\Run : AVG-Secure-Search-Update_1213b (C:\Users\Sue 2\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=3f4366dcde4f47d6b42955626d496f73-6f409ed7254082fae961525a128cf4622b8bfbcf /CMPID=1213b [-][x][x]) -> NOT SELECTED
    • [RUN][SUSP PATH] HKCU\[...]\Run : InstallX Search Protect for Yahoo ("C:\Users\Sue 2\AppData\Roaming\InstallX Search Protect for Yahoo\searchprotector.exe" [7]) -> NOT SELECTED
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3508457672-3135540269-176784899-1004\[...]\Run : AVG-Secure-Search-Update_1213b (C:\Users\Sue 2\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=3f4366dcde4f47d6b42955626d496f73-6f409ed7254082fae961525a128cf4622b8bfbcf /CMPID=1213b [-][x][x]) -> NOT SELECTED
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3508457672-3135540269-176784899-1004\[...]\Run : InstallX Search Protect for Yahoo ("C:\Users\Sue 2\AppData\Roaming\InstallX Search Protect for Yahoo\searchprotector.exe" [7]) -> NOT SELECTED
     
  7. sberkkoch

    sberkkoch Private E-2

    Okay, I ran Rogue Killer again and had it delete the four items you mentioned.

    Thank you! I appreciate the help.

    Let me know what's next when you have a few minutes. Things seem fine w the machine!

    Sue
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    These still show as installed:

    • SavingsBull
    • SavingsBullFilter
     
  9. sberkkoch

    sberkkoch Private E-2

    I apologize!

    I looked in my program files, add/remove programs and revo uninstaller. Did a search for SavingsBull and nothing came up. Where could they be hiding?

    I did another MG tools scan and attached the log. Did I do something incorrectly with the last scan?

    I'm stumped.



     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    According to your latest MGLogs, they are both showing in your Add/remove programs list.

    If you can not find them, you can try running CCleaner and see if they show there.
     
  11. sberkkoch

    sberkkoch Private E-2

    Thank you for looking at my logs, TimW!

    I believe you but this is very odd to me. I looked again in Add/Remove programs, in CCleaner (I ran the cleaner, too) however no SavingsBull or SavingsBullFilter appear in the program lists. Honestly, they are alphabetical and it should not be difficult to see them!

    I ran Malawarebytes and it didn't find anything.

    Where can I find this horrible crap and get rid of it?
     
  12. sberkkoch

    sberkkoch Private E-2

    Hi Again,
    I don't mean to bump, but I did further searching in 'see more results' after I searched in the start box. That is where I found some Savings Bull folders! There were nine of them, tucked in strange places. I manually deleted them all. They were called 'savingsbull@jetpack'.

    I did another search the same way and the computer didn't find any more folders.

    I ran MGTools again and attached the log. When you have time if you could let me know if I got them all, I'd appreciate it.

    Thank you.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still showing up in your Add/remove list, but at this point I wouldn't worry about it.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think although it is not a major issue, leaving it hanging around is definately not the best idea. To be thorough, let's manually remove the registry entries that were left behind. (I had not finished working this thread!) :)


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now, if you have not already followed TimW's final steps, please do this:

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. sberkkoch

    sberkkoch Private E-2

    Hi Kestrel 13,

    I created the registry file according to your instructions. It successfully added to the registry! (Yes, I got the message)

    I did another MGTools scan and attached the file.

    Take your time, the machine is working OK! When you have a chance, let me know what the log says.

    Best,

    Sue
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, much better.

    Now, do you see these two folders?

    • C:\ProgramData\APN
    • C:\Program Files\Level Quality Watcher
     
  17. sberkkoch

    sberkkoch Private E-2

    Yes I do! I assume you want me to delete them?



     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. Then reboot the machine afterwards. Navigate back to where those files were and see if they are still gone. :) If so, then you are now ready to follow final steps.
     
  19. sberkkoch

    sberkkoch Private E-2

    Still gone! Hurray!

    I am ready to perform the final steps! Shall I follow TimW s post below?

    Thank you again.

    Sue
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yep. Now is the time to follow those steps. :)
     
  21. sberkkoch

    sberkkoch Private E-2

    All set and instructions completed. Thank you Kestrel 13 and TimW for your assistance!

    This is an invaluable forum, made so because of the great work by knowledgeable volunteers!
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds