123srv.com ads have taken over browser :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by janet_jjj, May 9, 2014.

  1. janet_jjj

    janet_jjj Private E-2

    Hi, my Google Chrome has been taken over by '123srv.com' ads. I have searched everywhere to remove this but havent come across anything that worked.
    Please help.
     
  2. janet_jjj

    janet_jjj Private E-2

    any suggestions?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. janet_jjj

    janet_jjj Private E-2

    Hi Here are my logs. Can someone please help. I still keep getting ads opening up on my google chrome.

    Thank you for any help!!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MGLogs. was incomplete. Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).
    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you have disabled any AV software you have.
     
  6. janet_jjj

    janet_jjj Private E-2

    done. please check attached file. thanks!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.
    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    SN64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  8. janet_jjj

    janet_jjj Private E-2

    sorry dont think i ran it properly last time. pls check this log:
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8118;https=127.0.0.1:8118

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Windows\TEMP\*.*
    C:\Users\m\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_USERS\S-1-5-21-4129746614-3409250849-3867867807-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyServer"=""
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{659C3C8C-6A2E-44B5-BED2-916351219448}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{659C3C8C-6A2E-44B5-BED2-916351219448}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. janet_jjj

    janet_jjj Private E-2

    here are the logs.

    Still getting Ads opening in new tabs-
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. janet_jjj

    janet_jjj Private E-2

    I reset the browser twice, but ads still showing up :(
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is Google Chrome the browser you are using? If you fully followed those instructions for resetting Chrome to defaults it should have fixed Chrome unless there is some other issue at play. Try Internet Explore ( make sure Chrome is closed first ) and see if it also has problems. If not, the issue is still likely with Chrome. It coud be that the shortcut you use to run Chrome is the problem. Try running Chrome.exe directly without using any shortcut or any quicklaunch type icons because these can get infected and we cannot see this info since an lnk shortcut to Chrome would be a valid file. What is in the shortcut may not be valid and you can check this by right clicking on it and looking at the Properties. The same applies to an Internet Explore shortcut like the below

    C:\Users\m\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
     
  14. janet_jjj

    janet_jjj Private E-2

    yes , chrome is my main browser.

    when I click 'reset browser' should it close the entire browser? because it only closes the 'Settings tab' - the chrome browser remain open with the other tabs.

    so I uninstalled google chrome and reinstalled it back a few times and kept clicking 'reset browser' but as soon as I come on to this website the ads are popping.

    I tried IE and no ads.
     
  15. janet_jjj

    janet_jjj Private E-2

    also I tried running using chrome.exe from C:/ but it didn't make a difference.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since IE is fine it is still your Chrome browser that is the problem. And it is definitely in the settings and something is not getting reset. Try the below.

    Try the below:
    • Click the Customize and Control Google Chrome button ( the 3 parallel lines down below the X button used to close the window ).
    • Then on the pop down form select Settings.
    • Now under the Search heading, click the Manage Search Engines button
      • Look in here for anything related to 123srv.com and select it and delete it by clicking the X button to the far right side.
      • Make sure that you look in both the Default Search Engines and Other Search Engines areas and delete any 123srv.com junk.
      • Select the default search engine you want ( like Google ) and click the Make Default button.
      • When finished, click the Done button
    • Now back on the Settings page to the top left you should see an Extensions selection, click on it to bring up the installed extensions.
    • Look for any undesired extension ( like 123srv.com or anything else you did not install ) and if found, click the Trash Can icon to delete the extension.
    • Now close the Extensions/Setting tab to get back to normal view
    • Exit Chrome and reopen.
    • Are you still having a problem with 123srv.com?
    • If you are still having a problem, go back to the Settings form and see the On start-up option.
    • You may have the Open a specific page or set of pages radio button selected. If so, click the Set pages link and look for the problem pages and delete them.
     
  17. janet_jjj

    janet_jjj Private E-2

    cannot see anything related to 123srv on it.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Chrome and Google Update Helper and run the below. Do not reinstall Chrome yet. I will tell you went to reinstall.

    Now delete the below folders:
    C:\Users\m\AppData\Local\Google
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome

    And also delete the below folder if it still exists:
    C:\Program Files (x86)\Google



    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  19. janet_jjj

    janet_jjj Private E-2

    here are the OTL files:

    btw. since I've been on IE, one ad opened up on IE :/
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you able to find all of those Google folders and delete them?

    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts.
    Code:
    :OTL
    PRC - [2014-04-23 17:42:26 | 000,016,384 | ---- | M] () -- C:\Windows\Microsoft\System Update kb70007\WindowsUpdater.exe
    SRV - [2014-04-23 17:42:26 | 000,016,384 | ---- | M] () [Auto | Running] -- C:\Windows\Microsoft\System Update kb70007\WindowsUpdater.exe -- (System Update kb70007)
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    IE - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    IE - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    IE - HKU\S-1-5-21-4129746614-3409250849-3867867807-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-21-4129746614-3409250849-3867867807-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    IE - HKU\S-1-5-21-4129746614-3409250849-3867867807-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-21-4129746614-3409250849-3867867807-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8118;https=127.0.0.1:8118
    :Files
    C:\Windows\Microsoft\System Update kb70007
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. janet_jjj

    janet_jjj Private E-2

    Answer to previous post : I did not find this file : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome


    please find attached the logs :

    I have been using IE for about 45 mins now and no ads yet..

    can I install Google Chrome now?
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, let's give it a try now.
     
  23. janet_jjj

    janet_jjj Private E-2

    Everything seems to be fine. Thank you so much for your help!!!!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds