Ie running ads in background + trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by jinerik, Jan 6, 2010.

  1. jinerik

    jinerik Private E-2

    clicked a bad attachment? not sure.
    random misdirects in firefox. (probably in IE too but i don't use it)
    ads playing audio in background IE windows.
    can close with task manager but they immediately come back.
    random number of trojans found with every MBAM scan.
    can hear IE "click" in background
    some random IE windows opening.

    Tried all the normal methods, AVG, AdAware, Spybot SD but apparently that is now old school. i haven't been hit like this in a long time.

    did steps 1-6 to the letter but to no avail

    will attach other logs in next post.
     

    Attached Files:

  2. jinerik

    jinerik Private E-2

    that's the last log.

    Thank you for your time.

    TC.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The reason for your problems is that many of your files and startup process have become infected with an older style Vundo infection. it was also infecting new programs you have been installing that have startup processes that load when your computer boots. You may have to uninstall a bunch of things to properly fix this since many of the programs may have now become corrupted. This includes the below which should be uninstall immediately.

    Adobe Reader 8.0 <--- some of your other Adobe items may also be infected.
    AVG8.5
    iTunes
    Malwarebytes Anti-Malware
    PowerISO
    RealPlayer
    Quicktime
    SUPERAntiSpyware
    Windows Defender

    After uninstalling the above, reboot and continue with the below.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it:
    Code:
    KILLALL::
    
    File::
    c:\program files\Adobe\Reader 8.0\Reader\reader_sl .exe
    c:\program files\AVG\AVG8\avgtray .exe
    c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
    c:\program files\Common Files\Adobe\CS4ServiceManager\cs4servicemanager .exe
    c:\program files\Common Files\Maxtor\Schedule2\schedhlp .exe
    c:\program files\Common Files\Real\Update_OB\realsched .exe
    c:\program files\iTunes\ituneshelper .exe
    c:\program files\Java\jre6\bin\jusched .exe
    c:\program files\Malwarebytes' Anti-Malware\mbam  .exe
    c:\program files\Malwarebytes' Anti-Malware\mbam .exe
    c:\program files\PowerISO\pwrisovm .exe
    c:\program files\QuickTime\qttask     .exe
    c:\program files\QuickTime\qttask    .exe
    c:\program files\QuickTime\qttask   .exe
    c:\program files\QuickTime\qttask  .exe
    c:\program files\QuickTime\qttask .exe
    c:\documents and settings\Tom C\nwiz.exe
    c:\program files\SUPERAntiSpyware\nwiz .exe
    c:\program files\SUPERAntiSpyware\rundll32 .exe
    c:\program files\SUPERAntiSpyware\superantispyware .exe
    c:\program files\Windows Defender\msascui .exe
    c:\windows\pchealth\helpctr\binaries\msconfig .exe
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "SunJavaUpdateSched"=-
    "Windows Defender"=-
    "QuickTime Task"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, reinstall all the programs you uninstalled and still need especially your antivirus protection.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. jinerik

    jinerik Private E-2

    Logs Attached.

    How am i lookin?

    *crosses fingers*
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's much better but you did not say how things are working. I will assume all is good since your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. jinerik

    jinerik Private E-2

    well. everything seems to be ok. no more IE running or ads playing.

    i did get some bad results from MBAM which i will post the logs from but after the initial scan, and removal, its been all clear after multiple scans afterwards.

    i also received similar results from SUPERAntiSpyware. the initial scan was good. the next had a few things reported and the following 3 scans were clean.

    i'm not sure if it was just residual infections that were able to be removed and since the source of the problem was gone they didn't self-propagate like they did before? maybe that's just wishful thinking but it seems to be ok...

    what is Qoobox btw? virus vault for something...

    Oh and i deleted all previous System Restore Points because they seemed to be giving me issues before the big clean.

    ill do the final page of your instructions as soon as im sure this thing is sorted out.

    thanks again.

    it means more than you know.

    TomC

    the attachments are in the order i scanned them.
    mbam 1st scan
    mbam 2nd scan
    Sas 1st scan
    Sas 2nd scan
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I did not ask you to run MBAM. I asked you to complete my final instructions. Most of what MBAM found were things we already removed. If you had followed my final steps, they would have been removed. The QooBox folder was from ComboFix and would have been removed when you completed my instructions.
     
  8. jinerik

    jinerik Private E-2

    Actually your instructions didn't say to do anything except uninstall various malware components if my pc seemed to be running error free. I was attempting to see if it was in fact clean.
    Other than sitting there and possibly letting the infection spread, as was the case before, i decided to run some scans and keep Combofix, MGTools etc. until i was sure no longer needed them.

    I will now continue on per your instructions...

    instructions completed.

    Your help is most greatly appreciated.

    That's the first time I had to go to outside help to remove a virus and you did swimmingly!

    Thank you for your valuable time chaslang i was 10 seconds away from formatting :)

    peace.
    J

    edit: is there a way to close this thread and mark it as "problem solved" or am i thinking of another forum....
     
    Last edited: Jan 15, 2010
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and you are only supposed to do what we request. Also you were running error free, and I already said your logs were clean. I did not say run more scans to look for malware. ;) We don't want you to do this because we already know things are in the quarantines until you follow our final instructions.

    We don't normally close threads. We just make sure we have the last post in them so we know they no longer require a response.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds