Adware virus in my computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by melvica, Apr 16, 2006.

  1. melvica

    melvica Private E-2

    I have been spending the last 3 days trying to clean up the many viruses in my daughter PC.

    I have AVG and Sygate Firewall running. Every 30 seconds there is an outgoing attempt to www.a-d-w-a-r-e.com. I think I have some adware viruses.

    I have run in Safe Mode
    - CleanUp!
    - Spybot Search & Destroy - tells me my computer hasn't got any viruses
    - Adware-SE - it finds Adware.Look2Me but couldn't delete the file in \Windows\System32.
    - Ewido - found 8 virues - Look2Me and Dropper.VB and clean them out

    However when I reboot the system back to normal mode, I am still getting alert from Sygate Firewall attempt to contact www.a-d-w-a-r-e.com. The attempt seems to run as an app from run32dll.exe.
    I have also run Bitdefender, MicroTrend, AVG and CA eTrust online anti-virus scans but none seems to clean out the viruses even when it detected the virus.

    I think I must have repeated these more than 4 times (for the malware and antivirus programs).

    About to give up and just reinstall Windows XP but I hope someone can help me.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures (and I added one step for the Look2Me infection at the begining) which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Look2Me VX2 Removal
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (the last three scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Look2Me-Destroyer.txt
      • Bitdefender
      • Panda Scan
      • HijackThis
     
  3. melvica

    melvica Private E-2

    Hi,

    I have done what you asked me to perform

    1) In normal boot mode
    - Run Look2Me-Destroyer (don't seem to work on Safe Mode reboot)
    - attached Look2Me-Destroyer log

    2) Reboot in Safe Mode
    - run CCleaner
    - run Microsoft Windows Malicious Software Removal Tool
    - run Ad-Aware SE with full system scan (no viruses reported)
    - run Spyboot Search & Destroy (no virus reported)
    - run Microsoft Windows Defender (no vrus reported)

    3) Reboot in Safe Mode with Networking Support
    - run Bitdfdefender
    - run Panda Active Scan but couldn't get PandaActiveScan log
    - set to Disable System Restore

    4) Reboot in normal mode
    - set to Enable System Restore
    - run PandaActive Scan.
    - Run HijackThis

    Atached are the 4 logs
    - Look2Me-Destroyer.txt
    - Bitdefender (bdscan.txt)
    - PandaScan (Activescan.txt)
    - HijackThis (hijackthis.txt)

    I greatly appreciate your help. The Look2Me-Destroyer seems to remove the Adware.Look2Me. But I think I still have a couple of Trojans in the system
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The directions do not ask for it to be run in safe mode.

    You were not supposed to toggle System Restore yet. Step 1 of the READ & RUN ME states the below:
    Please read step 7 of the READ & RUN ME again and follow the directions in it exactly. You are running HijackThis directly from the ZIP file which is exactly what we specify that you not do. You will not get any backups of things deleted if you run it this way.

    After installing HJT properly, move on to my next message.
     
    Last edited: Apr 17, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is optusnet.com your ISP and do they require the below proxy server setting:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=optusnet.com.au:8080

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Network <--- the whole folder
    C:\WINDOWS\keyboard71.dat
    C:\WINDOWS\TWVsYXU\nqpPsro.vbs
    C:\windows\newname7.exe <--- delete any files whose name starts with the text newname and ending in .exe (like newname1.exe, newname2.exe...etc)
    C:\windows\mousepad7.EXE <--- delete any files whose name starts with the text mousepad and ending in .exe (like mousepad1.exe, mousepad2.exe...etc)
    C:\windows\keyboard7.exe <--- delete any files whose name starts with the text KEYBOARD and ending in .exe (like KEYBOARD1.exe, KEYBOARD2.exe...etc)
    C:\windows\GIMMYSMILEYS7.EXE <--- delete any files whose name starts with the text GIMMYSMILEYS and ending in .exe (like GIMMYSMILEYS1.exe, GIMMYSMILEYS2.exe...etc)
    Also look in c:\ for any of the newnameX, mousepadX, keyboardX, GIMMYSMILEYSX files and delete them too

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. melvica

    melvica Private E-2

    Thank you once again for the quick response. Sorry I did not quite follow step1 and step7 in 1st attempt.

    Okay, this is what I have done as per your instructions. Firstly to your question - yes, optusnet is my ISP and it needs that proxy server.

    1) Run HijackThis and Fix the following
    - R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    - R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    - R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    - R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    - R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    - O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
    Question - what spyware is my system infected at this stage?

    2) Boot in Safe mode
    Delete the following:
    - C:program Files\Network folder
    - C:\WINDOWS\keyboard71.dat. There were 3 other - keyboard81, keyboard91 and keyboard111 dat files in that folder. I have not deleted them. Should I delete them?
    - no such file C:\WINDOWS\TWVsYXU\nqpPsro.vbs
    - no file C:\WINDOWS\newname7.exe or any files newname<X>.exe in C:\
    - no file C:\WINDOWS\mousepad7.exe or any files mousepad<X>.exe in C:\
    - no file C:\WINDOWS\GIMMYSMILEYS7.exe. However I found 3 files with the name gimmysmileysB in 3 folders C:\Douments and Setting\All Users\Spybot Search & Destroy\Recovery\SmitfraudC30.zip, SmitfraudC7.zip and SmitfraudC84.zip. I have not deleted them as I am not sure if they are use by Spybot Searcgh & Destroy. Please advice what to do.
    - delete all files in C:\WINDOWS\prefetch folder
    - Reset Web setting in Internet Explorer

    3) Reboot in normal mode
    - Run HijackThis. Attached is the log.

    System looks clean. I have not run any online scanning eg Bitdefender and PandaActive Scan before this posting.

    Once again, thanks alot and waiting for a green light from you that the system is healthy.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had a few infections! One was Adware.Maxfiles and the other is referred to by many names (depends on which tool detects it and which particular filename is found).
    Trojan-Downloader.Win32.Adload.ae
    Trojan-Downloader.Win32.VB.zg

    Your log is clean! How are things working?

    Note you have Symantec Security Center still install and you are using AVG. Did you know this? You need to uninstall all Symantec software.
     
  8. melvica

    melvica Private E-2

    Thanks again. The system is running very well and fast. I am now running AVG. Will delete the rest of Symantec suite. By the way is it also ok to run Windows Defender together with AVG?

    By the way you did not response to my other questions
    - do I need to delete the other keyboard81, keyboard91 and keyboard111 dat files in C:\WINDOWS?
    - do I delete the 3 gimmysmilesB files in Spybot Search & Destroy?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you verify that no Symantec items show in your HJT log afterwards. Much like malware, Symantec does a poor job of uninstalling itself and frequently requires manual intervention.

    Yes Windows Defender should work okay with AVG. They are two different types of programs. Windows Defender is an antispyware program and AVG is an antivirus program.

    Yes you can delete all those files. The keyboard ones are part of the same infection and the files in Spybot's folder are just backups of the baddies it remove and you don't need them.


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds