Adware

Hello

My browser (FF) was recently plagued by adware. It started coming up a little under a week ago. I had not recently downloaded any programs or installed any plugins/add-ons. It did the usual adware stuff - some of it showed up as add-ons in FF (I removed them but they came back each day) and some showed up in ‘add and remove programs’ (I couldn’t remove them).

I ran MalwareBytes and AdwCleaner and refreshed FF. Refreshing seemed to remove the problem. No more add-ons or programs visible on the computer. I got Adblock Plus and Avast as precautionary measures, thinking the issue was solved. Now Avast keeps bringing up the warning ‘malicious url blocked’ on most pages as I browse. I can’t see the ads anymore but I’m guessing this is what Avast is blocking.

I’ve attached the logs.

What should I do? Will completely removing and restarting FF fix it?

Thanks.

Hello,

https://sites.google.com/site/cannedfixes/home/hosted-images-tools/51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

[*]Right-click on
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/51a612a8b27e2-Zoek.png
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
[]Wait patiently until the main console will appear, it may take a minute or two.
[
]In the main box please paste in the following script:

createsrpoint;
autoclean;
emptyalltemp;
ipconfig /flushdns;b

[*]Make sure that Scan All Users option is checked.
[*]Push Run Script and wait patiently. The scan may take a couple of minutes.
[*]When the scan completes, a zoek-results logfile should open in notepad.
[*]If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.

Zoek.exe v5.0.0.0 Updated 08-April-2015
Tool run by Ilenora on Tue 21/04/2015 at 17:37:29.95.
Microsoft Windows 7 Professional 6.1.7600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Ilenora\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

21/04/2015 5:39:30 PM Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\Apowersoft deleted successfully
C:\PROGRA~2\Origin Games deleted successfully
C:\PROGRA~3\ZoomBrowser deleted successfully
C:\Users\Ilenora\AppData\Roaming\CameraWindowDC deleted successfully
C:\Users\Ilenora\AppData\Roaming\WinRAR deleted successfully

==== Deleting CLSID Registry Keys ======================

==== Deleting CLSID Registry Values ======================

==== Deleting Services ======================

==== FireFox Fix ======================

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214

user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref(“browser.startup.page”, 3);
---- FireFox user.js and prefs.js backups ----

prefs_20152104_0601_.backup

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Thunderbird\Profiles\22f4g5w9.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_20152104_0601_.backup

==== Batch Command(s) Run By Tool======================

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Apowersoft not found
C:\PROGRA~2\Origin Games not found
C:\PROGRA~2\free TV deleted
C:\PROGRA~3{428c556e-fa33-9571-428c-c556efa355bb} deleted
C:\PROGRA~3\17585416907240017803 deleted
C:\Users\Ilenora\AppData\Roaming\ZoomBrowser EX deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214
user_pref(“browser.startup.homepage”, “www.deviantart.com”);

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
wrc@avast.com”=“C:\Program Files\AVAST Software\Avast\WebRep\FF” [19/04/2015 10:11 PM]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
“{e4f94d1e-2f53-401e-8885-681602c0ddd8}”=“C:\ProgramData\McAfee Security Scan\Extensions{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi”

==== Firefox Extensions ======================

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214

  • Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
  • Adblock Plus - %ProfilePath%\extensions{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

ProfilePath: C:\Users\Ilenora\AppData\Roaming\Thunderbird\Profiles\22f4g5w9.default

  • British English Dictionary - %ProfilePath%\extensions\en-GB@dictionaries.addons.mozilla.org
  • ReminderFox - %ProfilePath%\extensions{ada4b710-8346-4b82-8199-5de2b400a6ae}

AppDir: C:\Program Files (x86)\Mozilla Firefox

  • Java Console - %AppDir%\extensions{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
  • Java Console - %AppDir%\extensions{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
  • Default - %AppDir%\browser\extensions{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Ilenora\AppData\Roaming\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214
9AE02005247DA91AB1743F5208DBEF76 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash
65C1D9F74004E775F9A8598476ABE5EE - C:\Users\Ilenora\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
98137411B9C632095F919E2CE70B288A - C:\Users\Ilenora\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll - Google Update
E3B4EA121F7BDEB0F6366E2BA9608CB5 - C:\Users\Ilenora\AppData\Local\Citrix\Plugins\104\npappdetector.dll - Citrix Online Web Deployment Plugin 1.0.0.104

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[19/04/2015 10:11 PM]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
apdfllckaahabafndbhieahigkjlhalf - C:\Users\Ilenora\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx[24/02/2015 08:37 PM]
lmjegmlicamnimmfhcmpkclmigmmcbeh - No path found

Chrome Hotword Shared Module - Ilenora\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
“Start Page”=“http://www.google.com

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
“Start Page”=“http://www.google.com

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
“DefaultScope”=“{0633EE93-D776-472f-A0FF-E1416B8B2E3A}”
{012E1000-F331-11DB-8314-0800200C9A66} Google Url=“http://www.google.com/search?q={searchTerms}
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url=“http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

==== Deleting CLSID Registry Keys ======================

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2556304672-2921975653-2535048890-1000\Software\Mozilla\FireFox\Extensions{e4f94d1e-2f53-401e-8885-681602c0ddd8} deleted successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ilenora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Ilenora\AppData\Local\Mozilla\Firefox\Profiles\3wwoarg5.default-1429410321214\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Ilenora\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=25 folders=19 14166219 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Ilenora\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Ilenora\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

“C:\Users\Ilenora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not found

==== EOF on Tue 21/04/2015 at 18:36:59.38 ======================

How is your PC now?

Still bringing up the warnings (happened as soon as I visited this page to post the reply). I attached a screenshot of the latest one.

Actually, I think I stupidly forgot to disable my antivirus programs before running zoek :-[ Should I disable them and run it again?

No need, Zoek did its work. Can you reinstall Firefox?

Yep. I’ll do that now.

I was using Chrome to get instructions on reinstalling FF and the infection warnings appear on there too :-\

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

[*]Right-click on
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
[*]Make sure that Addition option is checked.
[*]Press Scan button and wait.
[*]The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

Here they are. Thanks for your help so far :slight_smile:

I uninstalled and reinstalled FF, copying only the most important things from my profile. So far, no infection warnings.

CHR dev: Chrome dev build detected! <======= ATTENTION

Chrome is altered by malware, you need to reinstall it.

Sorry for the delayed reply. I’ve uninstalled Chrome (I barely ever use it). What should I do now? Run another scan just to be sure it’s all gone? I haven’t run into any problems or warnings while using FF for the last couple of days.

There is no need to do anything, your PC seems clean now :slight_smile:

Thank you so much for your help! I really appreciate it! :smiley: