Apparent Adware Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Zaratoughda, Apr 30, 2011.

  1. Zaratoughda

    Zaratoughda Private E-2

    It started with a pop-up saying I had a hard disk error, and needed to reboot. Then, my desktop icons started disappearing, and so I restarted and did not have any (I believe now the folders were just hidden), so I backed up to a checkpoint earlier in the day, and restarted and now I had my shortcuts but I checked the event log and there was a problem with the restore from checkpoint and all my checkpoints had been deleted.

    Now, when I start my machine it seems to be normal but all of a sudden, before I ever bring up IExplore or anything, I start getting music or mainly adds coming through my speakers. Then, after a while, I get a pop-up saying Internet Explorer has had a problem with running a script. If I check Task Manager it does not show Internet Explorer running. Also, in watching Task Manager after bringing up my machine, the storage used by Explorer keeps getting bigger and bigger and then the ads start coming.

    I downloaded and ran a number of malware programs and most of them found nothing but malwarebytes did find a couple of trojans which it removed. But, this did not stop the problem.

    I've looked at and tried a few other things but feel I have come to the point where I need expert help and, that is where you guys come in (if you can).

    hijackthis.log attached

    Sincere thanks in advance!

    Zaratoughda
     

    Attached Files:

  2. Zaratoughda

    Zaratoughda Private E-2

    I just noticed the intructions you gave Insane111 so if you want me to do the same just say so and I will refer to that thread and proceed as instructed there.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. Zaratoughda

    Zaratoughda Private E-2

    TimW... it looks like we got this one under control.

    I am attaching the two logs from malwarebytes that I ran before I came here for reference as they indeed found some things. The second running was not long after the first but it was a full scan and found another trojan.

    I have attached the SuperAntiSpyware log though it didn't find anything.

    I ran malwarebytes again after this but it didn't find anything additional.

    It was ComboFix that apparently fixed the problem. Looks like this one is the heavy hitter. The log is attached.

    Need to post another reply with the other two logs.

    Zaratoughda
     

    Attached Files:

  5. Zaratoughda

    Zaratoughda Private E-2

    The logs from the last two programs are attached.

    In task manager I have not seen the memory usage for explorer go above 30M so far and have not had any ads come up so far so, so far so good though I will probably have to watch it for a day or two.

    But.... you guys RULE! Would have been impossible for me to isolate something like this (hmmm... ABSOLUTELY impossible and I am a computer engineer).

    Many thanks for the help. I will be sure to recommend this site to others that I know.

    Zaratoughda
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like the scans took care of the malware on your system. We can clean up a few left over junk:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  7. Zaratoughda

    Zaratoughda Private E-2

    OK, went through the procedure and everything seemed to work fine. The REGEdit took and HJT removed the selected entries.

    I had already created a folder in keeping SAS and MWB and also CCleaner which I might have occasion to use over time for browser redirection problems. I had also decided that ComboFix was too dangerous to be kept around and had just deleted it from my desktop (I have recycle bin auto delete) and, couldn't find any trace of it in registry or in add/remove programs. HJT and anything else other than the three programs I saved were not listed in add/remove programs.

    So, seem to be all set here with a new (and clean hopefully) system restore point.

    Thanks again for your expert help!

    Zaratoughda
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds