Persistent spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by JerseyITGuy, Jul 8, 2009.

  1. JerseyITGuy

    JerseyITGuy Private E-2

    I am working on the laptop of a work colleague. I have gotten it clean with the exception of 2 things that keep showing up in SAS that I CANNOT get rid of: adware.zango toolbar & SpamBlockerUtility. I am unable to get rid of them through Add/Remove Programs because they do not show up in there. I have attempted 4 times now to remove them using SAS, but they keep coming back!!

    Please see my attached logs. Let me know if you need anything else from me.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Assuming this is only occurring with IE>...then you need to look in the tools and check your add-ons and toolbars.
     
  3. JerseyITGuy

    JerseyITGuy Private E-2

    I honestly do not know when it is occurring. Had it not been for the 2 items showing up in SAS, I wouldn't have known they were there. Because it is infected I haven't put it onto our network yet, so I haven't gone online with it. Any thoughts on how to get it the hell off the machine??
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. JerseyITGuy

    JerseyITGuy Private E-2

    Thanks a lot Tim. I will try that on Monday when I'm back in the office & will post again once I've done it to let you know how it went.
     
  6. JerseyITGuy

    JerseyITGuy Private E-2

    I have tried multiple times to run the online scan & it has failed every time to run. It tries to update the virus definitions, & those updates both fail. Then it asks if I want it to run the scan anyway, I click Yes, & the scan fails immediately.

    In checking the add-ons & toolbars, I only found one thing in the "add-ons that do not require permission to run" & it was for support.com. I disabled that.

    I await your reply.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to use the correct versions of software. Both SAS and MBAM are way out of date!!! Uninstall them and then download and install what we asked you to install in the READ & RUN ME and also update them from within the programs after installing. Then run new scans and attach the new logs.
     
  8. JerseyITGuy

    JerseyITGuy Private E-2

    Good morning Chaslang. I whad tried to do the manual updates from both apps' respective websites. I was unable to run MBAM after doing so, & what I have for SAS is what I downloaded from them for a manual update. As I stated in one of my previous posts, I was a bit leery about putting it online at first. However, I've secured a way to get online here in the office with minimal threat, so I will do that today & repost my logs as soon as I have done so.

    Any thoughts on why the BitDefender scan wouldn't have worked? Just curious...
     
  9. JerseyITGuy

    JerseyITGuy Private E-2

    So... I re-installed the current version of SAS. When I ran it this time, it came up with different things. I cleaned them & ran it again... the scan came back totally clean. I'm going to re-install MBAM now & run that. I will post my results.
     
  10. JerseyITGuy

    JerseyITGuy Private E-2

    OK. Here are the most recent SAS & MBAM logs. MBAM found an instance of adware.zango now, but it came back after trying to remove it.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run Combo and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  12. JerseyITGuy

    JerseyITGuy Private E-2

    OK. I have re-run MGTools. However, I had to download ComboFix again, due to the expiration of the copy I had. When I went to download it again, it got picked up by our corporate anti-virus as being infected (which has never happened before). I have attached the MGTools log.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your system. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  14. JerseyITGuy

    JerseyITGuy Private E-2

    Tim, I have to be honest. I'm finding it hard to believe there is nothing showing in any of the logs, since the MBAM log I posted on 7-15-09 should show the instance of Adware.zango that it found in the scan. It remained even after allowing MBAM to clean it after it was found, then the second scan (which resulted in the log I posted) found it again. I'm VERY unhappy that this is your response. I waited 3 days for an answer to my last posting, only to get the same stock answer you give everyone else when you think their issue is resolved. I am asking that you double-check my MBAM log from 7-15-09 since I know there was an instance of Adware.zango in that scan that would not go away.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, your log from 7-15 showed it as being removed. Let me ask you this, did you disable your corporate AV program when running the scans?
    Was your AV protection turned off/disabled when you tried to download ComboFix--> apparently not.

    That single instance of the registry key is the ONLY instance that is being reported. So, have you looked in the registry to see if it actually exists?

    When you made your reply on 7-21....you did not say that you still had the problem. Perhaps you expected that I would somehow know that it still existed?

    I doubt this will help, but you need to use windows explorer to find and delete:
    This file --> c:\programdata\19962664\19962664.exe
    This folder --> c:\programdata\19962664

    If you are unhappy, you are free to have some other site assist you with your issue.
     
    Last edited: Jul 24, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds