Author Topic: Adware and possible trojan  (Read 8514 times)

0 Members and 1 Guest are viewing this topic.

Saragas

  • Guest
Adware and possible trojan
« on: August 19, 2013, 07:43:32 AM »
Possible adware and/or trojan virus. Random pop-ups and chrome related ads became really annoying after awhile, and I would like to get rid of them 
If I could get some help resolving this issue or any others that would be very appreciated : )
Avast Forums ftw
« Last Edit: August 19, 2013, 07:57:30 AM by Saragas »

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: Adware and possible trojan
« Reply #1 on: August 19, 2013, 07:58:06 AM »
hi Saragas,

Looks as if date/time scans show you ran AdwCleaner first, then MBAM, so MBAM cleaned and quarantined what AdwCleaner did not find.

That's good.

To ensure all of this c**p has been removed, best to run the following programs:  OTL, and aswMBR.exe:  http://forum.avast.com/index.php?topic=53253.0

Once the two new logs are attached in your next reply, a certified malware expert will be notified.  He will join and guide you in removal of any leftovers, so be patient once you submit your new logs.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37531
  • Not a avast user
Re: Adware and possible trojan
« Reply #2 on: August 19, 2013, 08:09:00 AM »
your AdwCleaner log say search.... to remove the crap found you need to click delete
should be done before you run OTL as this makes the log and fix  much smaller.   ;)

« Last Edit: August 19, 2013, 08:37:30 AM by Pondus »

Saragas

  • Guest
Re: Adware and possible trojan
« Reply #3 on: August 19, 2013, 11:18:11 PM »
All right, I did the delete from Adw and here are the other two files from OTL and aswMBR.
Still having delta search and pop-ups appear though : (

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Adware and possible trojan
« Reply #4 on: August 19, 2013, 11:22:34 PM »
Hi,


  Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


========== next ==========




Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Under Optional Scan ensure "List BCD" and "Driver MD5" are ticked.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Saragas

  • Guest
Re: Adware and possible trojan
« Reply #5 on: August 19, 2013, 11:46:05 PM »
Here are the other documents. Also disabled avast to make sure it didn't conflict with the programs.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Adware and possible trojan
« Reply #6 on: August 19, 2013, 11:52:11 PM »
Attach the contents of JRT.txt into your next message.  :)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Adware and possible trojan
« Reply #7 on: August 20, 2013, 12:05:08 AM »


1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system


Code: [Select]
START
Task: {DC077140-FBE0-453F-975A-645A41397987} - System32\Tasks\TopArcadeHits => C:\Users\Carlton\AppData\Local\TopArcadeHits\updater.exe [2013-08-19] ()
C:\Users\Carlton\AppData\Local\TopArcadeHits
C:\Program Files (x86)\Optimizer Pro
C:\Program Files (x86)\WebConnect
HKCU\...\Run: [Optimizer Pro] - C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [135672 2013-06-07] (PC Utilities Pro)
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://searchab.com/?aff=7&uid=8607c61b-6b19-11e2-9c16-bc5ff4490e14&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://searchab.com/?aff=7&uid=8607c61b-6b19-11e2-9c16-bc5ff4490e14&q={searchTerms}
BHO-x32: WebConnect - {2316c625-b487-4410-a1a5-ff040b65245f} - C:\Program Files (x86)\WebConnect\WebConnectbho.dll (Web Connect)
BHO-x32: TopArcadeHits Games - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Carlton\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
BHO-x32: PricePeep - {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} - C:\Program Files (x86)\PricePeep\pricepeep.dll (PricePeep)
C:\Program Files (x86)\PricePeep
CHR HomePage: hxxp://search.babylon.com/?affID=121845&babsrc=HP_ss_sps&mntrId=D27BBC5FF4490E14
CHR RestoreOnStartup: "hxxp://search.babylon.com/?affID=121845&babsrc=HP_ss_din2g&mntrId=D27BBC5FF4490E14", "hxxp://www.delta-search.com/?affID=121845&babsrc=HP_ss&mntrId=D27BBC5FF4490E14"
CHR Extension: () - C:\Users\Carlton\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp\1.0.0_0
C:\Users\Carlton\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp
CHR Extension: (MagniPic) - C:\Users\Carlton\AppData\Local\Google\Chrome\User Data\Default\Extensions\iambhhlobalofpohkppnnjhbmcakilpb\1
CHR Extension: (WebConnect) - C:\Users\Carlton\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon\1.0.0_0
C:\Users\Carlton\AppData\Local\Google\Chrome\User Data\Default\Extensions\iambhhlobalofpohkppnnjhbmcakilpb
C:\Users\Carlton\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon
CHR Extension: (PricePeep) - C:\Users\Carlton\AppData\Local\Google\Chrome\User Data\Default\Extensions\licjnkifamhpbaefhdpacpmihicfbomb\2.2.0.1_0
C:\Users\Carlton\AppData\Local\Google\Chrome\User Data\Default\Extensions\licjnkifamhpbaefhdpacpmihicfbomb
CHR HKLM-x32\...\Chrome\Extension: [ieakfmpjhljbpbfpldjkddkjmmgjmgon] - C:\Program Files (x86)\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx
C:\Program Files (x86)\WebConnect
R2 Update WK; C:\Program Files (x86)\WebConnect\updateWebConnect.exe [199976 2013-08-17] ()
C:\Windows\System32\Tasks\TopArcadeHits
C:\Windows\Tasks\TopArcadeHits.job
C:\Users\Carlton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
C:\Users\Carlton\AppData\Local\TopArcadeHits
CMD: netsh winsock reset
CMD: ipconfig /flushdns
END
2. Save notepad as fixlist.txt
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.

Note: If the tool warned you about the outdated version please download and run the updated version.


============ next =============








1. Please download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.


--------------------------------------------------------------------
2. Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:
  • Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
  • In the window that opens on the top right corner, click Settings.
  • In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.
  • => Again, right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.

--------------------------------------------------------------------
3. Run ComboFix. Click on I Agree!

ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.
If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart computer once more.


--------------------------------------------------------------------
4. When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
 Attach log reports ( ComboFix.txt) back to topic.





Saragas

  • Guest
Re: Adware and possible trojan
« Reply #8 on: August 20, 2013, 01:04:48 AM »
Here are the logs after running the following programs.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Adware and possible trojan
« Reply #9 on: August 20, 2013, 10:16:12 AM »
Please re-run FRST, press Scan button and attach here fresh created FRST.txt logreport.  ;)

Saragas

  • Guest
Re: Adware and possible trojan
« Reply #10 on: August 21, 2013, 08:30:08 PM »
Heres the new log.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Adware and possible trojan
« Reply #11 on: August 21, 2013, 09:37:02 PM »
Run browser Chrome, click on () > Settings > under "Search" option Manage search engines > select Google > close Chrome ;




--------------------------------------

FRST Script ;


Same as before, create fixlist.txt with this script:


Code: [Select]
START
c:\users\Carlton\AppData\Roaming\Optimizer Pro
SearchScopes: HKLM - DefaultScope value is missing.
END

Run FRST, click on Fix button and attach here fresh created fixlog.txt.


How's your computer running now?  8)




Saragas

  • Guest
Re: Adware and possible trojan
« Reply #12 on: August 21, 2013, 10:42:05 PM »
So I added the script to a notepad fixlist and then ran FRST, keeping the list in the same loaction as the log. Don't think I executed it right though...
As for the chrome issues, I'll reset after I run FRST again and see if the browser is clear .

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Adware and possible trojan
« Reply #13 on: August 22, 2013, 12:09:14 PM »
Don't think I executed it right though...

Yes you did. Thing is that FRST is very fast ...  ;D







It is necessary to uninstall ComboFix :
  • Click Start (or ) then Run.


    On Windows7 or Vista you may use Start Search field if Run is not available.

  • In the line of text type in (Copy) the following:
Code: [Select]
ComboFix /Uninstall
    Note that there is a space between " ComboFix " and " /Uninstall " .

    • then click OK (or press Enter ).
    Wait for the uninstall process is complete.


    --------- next --------


    Please download DelFix by "Xplode" to your Desktop.

    Run the tool and check the following boxes below;
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore

    Now click on "Run" button. Wait for the programme completes his work.
    All the tools we used should be gone.
    Tool will create and open an log report (DelFix.txt)
    Note: The report will also be stored on C:\DelFix.txt


    > I don't need DelFix log report.


    --------- next --------


    I recommended to use MCShield if you will.
    You may download MCShield from one of the following links:

    MyCity -  Official download link
    Softpedija - Mirror download link

    It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
    And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.

    Saragas

    • Guest
    Re: Adware and possible trojan
    « Reply #14 on: August 23, 2013, 04:33:40 AM »
    Allrighty ;)
    Thank you very much Magna for the help and tips. I trust avast! and their forum helper like you to help treat daily problems people have with their comps. Thank you guys so so much!
    Do you guys get paid or rewarded at all? Because This is superb help.
    Thanks again, and hopefully I wont be back here soon  ;D