Author Topic: Adware  (Read 4679 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Adware
« on: April 21, 2015, 06:17:32 AM »
Hello

My browser (FF) was recently plagued by adware. It started coming up a little under a week ago. I had not recently downloaded any programs or installed any plugins/add-ons. It did the usual adware stuff - some of it showed up as add-ons in FF (I removed them but they came back each day) and some showed up in 'add and remove programs' (I couldn't remove them).

I ran MalwareBytes and AdwCleaner and refreshed FF. Refreshing seemed to remove the problem. No more add-ons or programs visible on the computer. I got Adblock Plus and Avast as precautionary measures, thinking the issue was solved. Now Avast keeps bringing up the warning 'malicious url blocked' on most pages as I browse. I can't see the ads anymore but I'm guessing this is what Avast is blocking.

I've attached the logs.

What should I do? Will completely removing and restarting FF fix it?

Thanks.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Adware
« Reply #1 on: April 21, 2015, 08:28:39 AM »
Hello,



Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
autoclean;
emptyalltemp;
ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Adware
« Reply #2 on: April 21, 2015, 09:43:43 AM »

Zoek.exe v5.0.0.0 Updated 08-April-2015
Tool run by Ilenora on Tue 21/04/2015 at 17:37:29.95.
Microsoft Windows 7 Professional  6.1.7600  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Ilenora\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

21/04/2015 5:39:30 PM Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\Apowersoft deleted successfully
C:\PROGRA~2\Origin Games deleted successfully
C:\PROGRA~3\ZoomBrowser deleted successfully
C:\Users\Ilenora\AppData\Roaming\CameraWindowDC deleted successfully
C:\Users\Ilenora\AppData\Roaming\WinRAR deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214

user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----

prefs_20152104_0601_.backup

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Thunderbird\Profiles\22f4g5w9.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_20152104_0601_.backup

==== Batch Command(s) Run By Tool======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\Apowersoft not found
C:\PROGRA~2\Origin Games not found
C:\PROGRA~2\free TV deleted
C:\PROGRA~3\{428c556e-fa33-9571-428c-c556efa355bb} deleted
C:\PROGRA~3\17585416907240017803 deleted
C:\Users\Ilenora\AppData\Roaming\ZoomBrowser EX deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214
user_pref("browser.startup.homepage", "www.deviantart.com");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [19/04/2015 10:11 PM]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" []

==== Firefox Extensions ======================

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Thunderbird\Profiles\22f4g5w9.default
- British English Dictionary - %ProfilePath%\extensions\en-GB@dictionaries.addons.mozilla.org
- ReminderFox - %ProfilePath%\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Ilenora\AppData\Roaming\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214
9AE02005247DA91AB1743F5208DBEF76   - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll -   Shockwave Flash
65C1D9F74004E775F9A8598476ABE5EE   - C:\Users\Ilenora\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll -   Unity Player
98137411B9C632095F919E2CE70B288A   - C:\Users\Ilenora\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll -   Google Update
E3B4EA121F7BDEB0F6366E2BA9608CB5   - C:\Users\Ilenora\AppData\Local\Citrix\Plugins\104\npappdetector.dll -   Citrix Online Web Deployment Plugin 1.0.0.104


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[19/04/2015 10:11 PM]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
apdfllckaahabafndbhieahigkjlhalf - C:\Users\Ilenora\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx[24/02/2015 08:37 PM]
lmjegmlicamnimmfhcmpkclmigmmcbeh - No path found[]

Chrome Hotword Shared Module - Ilenora\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2556304672-2921975653-2535048890-1000\Software\Mozilla\FireFox\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8} deleted successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Ilenora\AppData\Local\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Ilenora\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=25 folders=19 14166219 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Ilenora\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Ilenora\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Ilenora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on Tue 21/04/2015 at 18:36:59.38 ======================

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Adware
« Reply #3 on: April 21, 2015, 09:45:25 AM »
How is your PC now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Adware
« Reply #4 on: April 21, 2015, 09:50:12 AM »
Still bringing up the warnings (happened as soon as I visited this page to post the reply). I attached a screenshot of the latest one.

Actually, I think I stupidly forgot to disable my antivirus programs before running zoek  :-[ Should I disable them and run it again?

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Adware
« Reply #5 on: April 21, 2015, 09:50:55 AM »
No need, Zoek did its work. Can you reinstall Firefox?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Adware
« Reply #6 on: April 21, 2015, 09:55:39 AM »
Yep. I'll do that now.

REDACTED

  • Guest
Re: Adware
« Reply #7 on: April 21, 2015, 10:04:26 AM »
I was using Chrome to get instructions on reinstalling FF and the infection warnings appear on there too  :-\

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Adware
« Reply #8 on: April 21, 2015, 10:05:49 AM »
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Adware
« Reply #9 on: April 21, 2015, 10:36:21 AM »
Here they are. Thanks for your help so far :)

REDACTED

  • Guest
Re: Adware
« Reply #10 on: April 21, 2015, 11:03:24 AM »
I uninstalled and reinstalled FF, copying only the most important things from my profile. So far, no infection warnings.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Adware
« Reply #11 on: April 21, 2015, 03:25:10 PM »
CHR dev: Chrome dev build detected! <======= ATTENTION


Chrome is altered by malware, you need to reinstall it.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Adware
« Reply #12 on: April 24, 2015, 02:08:49 AM »
Sorry for the delayed reply. I've uninstalled Chrome (I barely ever use it). What should I do now? Run another scan just to be sure it's all gone? I haven't run into any problems or warnings while using FF for the last couple of days.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Adware
« Reply #13 on: April 24, 2015, 06:44:27 AM »
There is no need to do anything, your PC seems clean now :)
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Adware
« Reply #14 on: April 24, 2015, 06:50:00 AM »
Thank you so much for your help! I really appreciate it! :D