ADware problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by DiabloStorm, Aug 24, 2010.

  1. DiabloStorm

    DiabloStorm Private E-2

    Hello all.
    Unfortunately it seems as if I've picked up some adware on about the 13th of Aug this month. I use firefox, but yet at odd times of the day/night I'll get a barrage of popups from internet explorer followed with adobe flash installers spamming my screen for me to install (even though I already have the most update one so I know this is associated in some way). I've also had (most likely) fake anti malware installers pop up and spam my screen to be downloaded (I obviously canceled these) and at one point had this one "Find people" Application pop up on it's own.
    I'm guessing all this garbage has been occuring because of my visit to prizerebel.com and it's affiliated websites. (Never again....)

    I've been scanning with Norton, Ad-Aware, Spybot search and destroy (which didn't find crap so I got rid of it), Advanced System Optimizer, Hijackthis, SuperAntiSpyware, malware bytes, I even disabled norton temporarily to run AVG free scan. I also run SpywareBlaster, ATF-Cleaner and CCleaner along with following the instructions written in these forums (http://forums.majorgeeks.com/showthread.php?t=35407)

    So from the 13th until now I've been trying to get rid of this crap. I hope it's gone after following that link above but I think I'll post my logs here to see what you guys think just to be safe.

    Thank you for your time and assistance.

    View attachment SASlog.txt

    View attachment combolog.txt

    View attachment RRlog.txt

    View attachment mbam-log-2010-08-24 (10-48-55).txt
     
  2. DiabloStorm

    DiabloStorm Private E-2

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing that I see which needs to be removed is this:
    C:\Documents and Settings\Nick Cruz\Local Settings\temp\EXmwwFzz.exe.part

    Otherwise, your logs are clean. I recommend that you uninstall Ad-Aware as it is pretty useless these days and is almost scareware now.

    I also see you once had McAfee installed. You can run this to remove the traces:
    McAfee Removal Tool

    What issues are you having, if any?
     
  4. DiabloStorm

    DiabloStorm Private E-2

    Internet explorer pop ups, adobe flash installer pop ups and java errors that weren't occurring until recently. Also the .dll that SuperAntiSpyware keeps picking up continuously returns. Advanced System optimizer was also finding things that none of the other programs picked up. Screencap enclosed, unsure of how to get a log file off it.

    aso.JPG
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I assume you are having it fix these items. Perhaps you can attach the quarantine file for me to look at.

    We can also do an online scan:
    eSet online scan.
     
  6. DiabloStorm

    DiabloStorm Private E-2

    Thanks for the replies! Unfortunately the log only gets exported as an .htm format so I've copied and pasted some of my recent scans to a text file.
    View attachment asolog.txt
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can change the log to a txt extension and attach it, so I can re-name it to an html type file.

    Are you still having issues?
     
  8. DiabloStorm

    DiabloStorm Private E-2

    Well ESET already claims to have found infections and all I did was copy/paste the text directly from the htm log that I got, it included scans from back in february so I only posted the most recent scans I've done since the problem occurred.

    Edit: more infections found with ESET and I'll attach the .htm as a .txt for you anyway.
    View attachment asolog.txt
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, so what issues are you still having? Mostly what it found was infected registry items. Are you having other malware issues?
     
  10. DiabloStorm

    DiabloStorm Private E-2

    Well no symptoms except adobe flash acting oddly and java errors so far, whether I'm barraged with internet explorer pop ups all of a sudden I can't tell yet but it hasn't happened thus far since I followed the instructions on these forums. eset is still scanning.
     
  11. DiabloStorm

    DiabloStorm Private E-2

  12. DiabloStorm

    DiabloStorm Private E-2

    Most serious problems are gone, thanks Tim.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds