Malware I am not able to Remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by sugarbean08, Jan 7, 2009.

  1. sugarbean08

    sugarbean08 Private E-2

    I have recently been infected with something that is causing pop-ups in my internet browser, that automatically direct to "http://www.webthangs.com/count/rotate/click.php?id=2". These happen every 5-10 minutes, and disrupt everything I'm doing. This happens in both IE and Firefox, I use FF as my browser.
    I believe that this occurred after downloading SonicStage software for my MP3 player from CNET's download.com.
    I have ran the initial requests, and am still experiencing the popups. The logs are attached to this message for SAS and MBAM and ComboFix.
    The following message has the MGTools log attached.

    Thank you for your help!
     

    Attached Files:

  2. sugarbean08

    sugarbean08 Private E-2

    This contains the last log, the MGtools log.
    Thanks!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    You are out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    You are also out of date with the definitions for Malwarebytes, run it and update to the current database and run a new scan with it too. Attach the new log.


    You have signs of Symantec Antivirus still installed but appear to be using AVG8. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME


    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the new logs from SUPERAntiSpyware and Malwarebytes
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. sugarbean08

    sugarbean08 Private E-2

    I have done everything in your reply, and attached are the logs. I will attach the MG log in the next reply. As of now, I have just finished, and restarted my system, and I have not gotten another pop-up! I am cautiously thinking that it is gone! Thank you SO much for your help!! :)))
     

    Attached Files:

  5. sugarbean08

    sugarbean08 Private E-2

    Here is the MG Log
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not do what I requested with SUPERAntiSpyware and are still runnning an old outdated version. You must follow those steps as written to get the new version installed. Just clicking Update only updates definitions not the program itself.

    Please do this and attach a new log just to be on the safe side. ;)

    Your logs are clean otherwise.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds