Addware loaded from Majorgeeks !!

Discussion in 'Malware Help (A Specialist Will Reply)' started by nokia, Jul 20, 2006.

  1. nokia

    nokia Private E-2

    Its my daily ritual to check out M.G.each and every morning..This morning,for the first time ever,I noticed M.G. took long to come up on screen.
    Thats when I noticed info from an addware site loading onto my laptop!
    This was all from M.G...Whats up guys? Id hate to not visit here anymore because of this.
    While typing here I also notice some changes to the M.G. website and a heading"majorgeek-co owner..."

    Unfortunately I dont know enough about the procedure to check for the addware..but I am a master at Hijack this already..(Thanks to M.G...)Will follow up and post my finding..

    Nokia.:confused:
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Need more info. We would NEVER infect you, run popups or anything else. Other websites load popups when you leave as well, so it could be that.
     
  3. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Seems like an ad-ware/spyware company thinks they are funny. Mostly likely your machine is infected and they are loading a dummy page. This is a tactic they have used in the past, but we have not seen it done in over a year.

    Please PM Tim or myself directly as I would personally like to investigate this one.
     
  4. nokia

    nokia Private E-2

    Gees,Thanks guys..give me a coupla secs..I want to find it and Ill pm you guys..
     
  5. nokia

    nokia Private E-2

    Ok,Got it..017-domain hijack

    O17 - HKLM\System\CCS\Services\Tcpip\..\{4A6CBB9D-8EB8-41C0-A127-F63078E46EBF}: NameServer = 196.25.255.34 196.25.255.3

    You need more?
    Log file?

    Nokia.
     
  6. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Well I was hoping they were someplace I could get my hands on their neck but .....

    OrgName: African Network Information Center
    OrgID: AFRINIC
    Address: 03B3 - 3rd Floor - Ebene Cyber Tower
    Address: Cyber City
    Address: Ebene
    Address: Mauritius
    City: Ebene
    StateProv:
    PostalCode: 0001
    Country: MU

    NetRange: 196.0.0.0 - 196.255.255.255
    CIDR: 196.0.0.0/8
    NetName: NET196
    NetHandle: NET-196-0-0-0-0
    Parent:
    NetType: Allocated to AfriNIC
    NameServer: NS1.AFRINIC.NET
    NameServer: NS-SEC.RIPE.NET
    NameServer: NS.LACNIC.NET
    NameServer: TINNIE.ARIN.NET
    NameServer: SEC1.APNIC.NET
    NameServer: SEC3.APNIC.NET
    Comment:
    RegDate: 1993-05-01
    Updated: 2006-04-27

    OrgAbuseHandle: GENER11-ARIN
    OrgAbuseName: Generic POC
    OrgAbusePhone: +230 4666616
    OrgAbuseEmail: ********@afrinic.net

    OrgTechHandle: GENER11-ARIN
    OrgTechName: Generic POC
    OrgTechPhone: +230 4666616
    OrgTechEmail: ********@afrinic.net

    -------------------

    Do you have a screen shot of the problem? Also any idea which spyware/adware loaded the Hijack?
     
  7. nokia

    nokia Private E-2

    Any way I can check back to see what loaded? I dont have a clue as to how I would proceed to check it..Can you advise?
    Will post a screenshot.

    Nokia.
     
  8. nokia

    nokia Private E-2

    The file was too big-had to resize..hope you can see ok..
     

    Attached Files:

  9. nokia

    nokia Private E-2

    Adds.revski.com..Just reloaded itself again as I went on to M.G....
     
  10. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Yeah -- the screen shot looks normal. If you could email the full one to me. I'll peak at it.

    Also I would like to see your HiJackThis log file.
     
  11. nokia

    nokia Private E-2

    Just done a new log..thanks C.P.
     

    Attached Files:

  12. nokia

    nokia Private E-2

    Got a pic of the download..
     

    Attached Files:

  13. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Sorry to butt in guy's but this line in the HJT log looks very suspicious of adware infection

    O4 - HKLM\..\Run: [BIH] C:\WINDOWS\system32\rundll32.exe bih.dll,InitGauge


    I would if not already be using CCleaner to delete all temp folders and cookies, and running through the Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    thread.


    Did an Ewido scan pick anything up as to a location of the above BIH.DLL file, I suspect it maybe in Docs & settings > your user name > Local Settings > Temp or Temp internet files.
     
  14. nokia

    nokia Private E-2

    Halo,No,Ewido does not pick up anything untoward...I also found that rather strange..

    Ill check out the noted HJT log thingy...
     
  15. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    What I can tell you is our ads are straightforward, tribalfusion, google mainly, I never even heard of them, it appears you may have picked up a drive by infection somewhere. Ewido is one program, you might use CCleaner to clear temp folders (from safe mode is best) and do some scans with Ad-Aware or similar. Jim might have more to say on this, but I am sure it is not from us. If we were to do anything like that, people would leave here in droves as many come here for help and security issues.
     
  16. matt.chugg

    matt.chugg MajorGeek

    revsci[dot]net belongs to a company called Revenue Science. the revsci[dot]net domain appears to be just where they store their scripts and ads. Their main site is revenuescience[dot]com

    There privacy statment is here.

    http://www[dot]revenuescience[dot]com/privacyStatement.asp

    Not sure if this helps at all, I've edited live links, after reading that who'd want to go to the page. I can download the whole statement safely without going to the site if anyone wants.

    Matt
     
  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    That's an adware related entry.

    Do the steps in the tutorial Halo linked to.
     
  18. AbbySue

    AbbySue MajorGeeks Administrator

    Good morning nokia!:)

    Just checking in to see how you are progressing with the steps in the READ & RUN ME FIRST Before Asking for Support thread? Are you having any problems with the steps?

    If you have not started to complete them yet I strongly urge you to do so as there does in fact appear to be something malicious on your computer.

    What I DO think is happening is that whatever you have is one of those variants that only shows itself on sites that either have a removal tool to get rid of it or a specialized forum such as we have for helping users to clean their computers. One reason this is done is to try and discredit the site. Some of these malicious proggies will go so far as to block you completely from accessing sites like ours in an attempt to keep you from cleaning it off your computer. We have had multiple cases like this so users will access the site via a different computer to get help.

    Please do complete the clean up steps and attach your logs so we can get to the bottom of this. No one else but you has reported seeing this mysterious hijack and we really would like to see a resolution.

    Thank you.:)
     
  19. nokia

    nokia Private E-2

    I have downloaded all the programs I need,Im actually going to start the complete operation now.
    While logging on now,something downloaded that filled the whole download bar from left to right with numerals,letters and squigly stuff..(!@#$%^&*()_+)..

    Its like swimming in the ocean knowing theres a BIG fish about...

    BTW,This all started just after I installed a program for Firefox called :Stumble:..

    Its a reccomended download from Mozzila themselves...

    Nokia..
     
  20. nokia

    nokia Private E-2

    Ive done the whole procedure and even included an Ewido scan..Nothing at all..I think in total 4 cookies were found and deleted..

    I followed the process to the letter..mmmm...:confused:
     
  21. AbbySue

    AbbySue MajorGeeks Administrator

    You haven't attached the 3 logs...BitDefender, Panda Active Scan & HijackThis (analyse.exe). Please attach them so they can be reviewed and we can make absolutely sure there is no problem.:)

    I find it rather intriguing you mention now that your problem began when you downloaded Stumble for your FireFox browser.:confused: I wasn't familiar with Stumble b/c I don't use FF so I had to look it up to see what it was. Have you tried removing all traces of it from your computer to see if your issue resolves itself?
     
  22. matt.chugg

    matt.chugg MajorGeek

    I have used stumble on IE, and whilst they try to take care about the sites they add, since they are 'user added' pretty much anything could be in there.

    Stumble itsself probably isn't the problem, its only an add on that takes you to a random site when you are bored. Its morelikely one of the sites it took you too has done a driveby on your computer.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds