Help with adware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by )V(eTalMan, Sep 6, 2008.

  1. )V(eTalMan

    )V(eTalMan Private E-2

    My Father's computer has some adware about security software and online virus scans. I have tried going into add/remove software, but they don't seem to be in the list.

    I also did a virus scan witch detected a virus and removed it but the popups keep coming.

    My father's computer has norton 360 from Symantec installed on it.

    Also, a new toolbar called 'Security bar' has appeared in internet explorer witch I have disabled but this is just a workaround, not a fix, I would like to remove it completely.

    I am not exactly sure tha it really is adware but any help would be appreciated.

    Thanks in advance

    )V(
     
  2. )V(eTalMan

    )V(eTalMan Private E-2

    The popups seem to be generated by a program called wcs.exe.:confused

    I want to know how to remove it completely from the computer including inernet explorer and the registry.

    )V(
     
  3. )V(eTalMan

    )V(eTalMan Private E-2

    I deleted wcs.exe using smitfraudfix but the 'internet security' toolbar remains in internet explorer, it is currently disabled, and I would like to remove it completely.

    EDIT: there is also a browser extension called research that shows up in the 'enable/disable' window of IE, is this malware?. This computer has IE7 installedon it.
     
    Last edited: Sep 7, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:


    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  5. )V(eTalMan

    )V(eTalMan Private E-2

    Ran all cleaning procedures. Some malware was found and removed?:confused
    not sure if it's all gone('research' browser extension is still in add-ons of IE), but i will err on the side of caution and attach the logs, so here they are.
     

    Attached Files:

  6. )V(eTalMan

    )V(eTalMan Private E-2

    and.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean now, but you do need to uninstall the below old Sun Java versions:

    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) SE Runtime Environment 6 Update 1

    You should also delete any unknown browser extensions.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Sep 16, 2008
  8. )V(eTalMan

    )V(eTalMan Private E-2

    Thanks for the help.

    I'm not sure how to uninstall browser extension.

    )V(
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really meant to say disable browser addons ;) but for some reasone I said browser externsions. In IE you would click Tools and then select Manage Addons and then disable the addon. Then from the infor given there find out what the program is related to and see if it can be uninstall via Add/Remove Programs.

    Note the Research Addon that you mentioned is not a problem. It is normal.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds