Help remove Ad Rotator F(logs attached)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Geek7, Jan 19, 2008.

  1. Geek7

    Geek7 Private E-2

    A few months ago I downloaded a free file for converting a PDF file to an image. Well, it had some malware/adware in it and I got burned.

    It seems I removed most of it using a combo of PestPatrol/AVG Anti-Spyware/Search & Destroy/CCleaner/Combofix.
    But still have one that gets buy all the scans.

    It's called AdRotatorF. I use Firefox and when I first open the Firefox browser it usually crashes.
    If I run PestPatrol and remove AdRotatorF, then it's fine. (PestPatrol is the only thing I've found that removes it)

    However, if I close Firefox and open it again it installs
    another instance of AdRotatorF and crashes - then I have to run PestPatrol to remove it and then I can use Firefox again.

    I also get Adssite Ads pop-up sometimes which I think is part of Ad Rotator F

    Thank you for your assistance.
    Greg
     

    Attached Files:

  2. Geek7

    Geek7 Private E-2

    PestPatrol log...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Password protected ZIP files are of no use to us. ;)


    Is the below file something you need? Was it part of the PDF converter?
    C:\WINNT\system32\PDF2IMG.dat

    Delete it if it was from that program.

    Also delete the below files:
    C:\WINNT\system32\rightonadz-uninst.exe
    C:\Program Files\Uninstall My Web Search.dll

    Do you know what the below fairly old folder and file are for?
    Code:
    2005-04-27 02:30 6,656 --sh--r C:\WINNT\system32\iosdt\iosdt.com


    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    The above are the only things of concern in your logs. The best method to remove issues related to Adssite Ads and FIreFox is to uninstall FireFox. Reboot and delete the C:\Program Files\Mozilla Firefox folder and C:\Documents and Settings\USERNAME\Application Data\Mozilla folders (replace USERNAME with the actual user account names). And then reinstall FireFox.
     
  4. Geek7

    Geek7 Private E-2

    - thanks, i'll be sure to post my results
     
    Last edited by a moderator: Jan 20, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't quote procedures. It is not necessary and clutters up the thread.
     
  6. Geek7

    Geek7 Private E-2

    Your recommendations worked. Thanks again for your assistance, I really appreciated the time you took.

    Greg
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds