also @ TechSpot: Study suggests majority of Windows 8 users ignore Metro apps

Sirefef .AA .W .AN .P .AB being detected by anti-virus help please!

Discussion in 'Virus and Malware Removal' started by Brennan, Jul 14, 2012.

  1. Jay Pfoutz Malware Helper Posts: 4,286   +49

    Fix it in OTL:
    Open OTL, click the None button and copy and paste this into the Custom Scans/Fixes box, and hit Run Scan:
    Post the log that launches along with the fix log.
  2. Brennan Newcomer, in training Posts: 52

    OTL logfile created on: 31/07/2012 2:41:33 PM - Run 6
    OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\User\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

    3.87 Gb Total Physical Memory | 1.73 Gb Available Physical Memory | 44.74% Memory free
    7.74 Gb Paging File | 5.55 Gb Available in Paging File | 71.69% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 465.66 Gb Total Space | 28.25 Gb Free Space | 6.07% Space Free | Partition Type: NTFS

    Computer Name: USER-PC | User Name: User | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

    ========== Custom Scans ==========

    < %PROGRAMFILES%\*. >
    [2012/07/26 03:42:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
    [2011/07/13 13:13:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
    [2011/01/06 06:44:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AviSynth 2.5
    [2011/10/29 01:56:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
    [2012/02/16 00:38:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Brother
    [2012/02/16 00:38:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Browny02
    [2012/07/26 03:45:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
    [2011/01/16 06:21:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Conduit
    [2012/07/05 20:56:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Creative
    [2012/07/05 20:45:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Creative Installation Information
    [2012/06/26 09:25:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Diablo III
    [2011/09/01 05:49:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Electronic Arts
    [2012/07/29 23:40:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Everything
    [2011/10/27 01:45:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Full Tilt Poker
    [2011/12/12 10:13:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GOG.com
    [2012/07/26 16:45:59 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
    [2012/07/26 16:32:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
    [2012/07/26 03:25:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
    [2011/12/14 04:39:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\IrfanView
    [2012/02/24 05:45:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ishutdown
    [2012/06/17 05:03:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
    [2012/07/26 03:44:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
    [2011/12/15 01:04:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\LibreOffice 3.4
    [2012/07/18 13:31:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/07/15 01:04:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Security Client
    [2012/05/20 03:00:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
    [2010/12/18 11:24:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
    [2010/12/18 10:42:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
    [2012/07/26 03:18:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
    [2012/07/26 03:26:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service
    [2009/07/13 22:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
    [2012/06/02 00:04:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA Corporation
    [2010/12/18 11:47:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenAL
    [2012/07/26 03:45:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Oracle
    [2012/05/07 02:46:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PacificPoker
    [2012/05/18 22:42:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
    [2012/07/26 19:30:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
    [2011/01/06 06:43:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Red Kawa
    [2009/07/13 22:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
    [2011/01/06 06:44:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Regensoft
    [2012/04/18 18:19:20 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
    [2012/07/10 20:28:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\StarCraft II
    [2012/07/30 03:02:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Steam
    [2012/04/18 02:34:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SystemRequirementsLab
    [2012/07/26 19:30:59 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
    [2012/04/18 03:59:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\trend micro
    [2011/07/22 06:30:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TuneUpMedia
    [2009/07/13 21:57:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Uninstall Information
    [2012/01/28 03:09:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Universe Sandbox
    [2010/12/21 02:40:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VideoLAN
    [2012/01/05 06:45:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Vuze
    [2012/07/24 15:14:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Vuze_Remote
    [2009/07/13 22:37:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
    [2012/04/13 23:16:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
    [2012/07/26 18:02:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
    [2012/07/26 18:02:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
    [2009/07/13 22:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
    [2012/07/26 18:02:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
    [2012/07/26 18:02:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
    [2012/07/26 18:02:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar

    < End of report >
  3. Brennan Newcomer, in training Posts: 52

    First time didn't work. Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\crossriderapp498@crossrider.com: C:\Users\User\AppData\Local\RewardsArcade\498\Firefox> in the current context!

    So I did it like the other ones.

    OTL by OldTimer - Version 3.2.54.0 log created on 07312012_145417

    All processes killed
    ========== OTL ==========
    File HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\crossriderapp498@crossrider.com: C:\Users\User\AppData\Local\RewardsArcade\498\Firefox not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: User
    ->Temp folder emptied: 72112 bytes
    ->Temporary Internet Files folder emptied: 78384 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 23193831 bytes
    ->Google Chrome cache emptied: 6836152 bytes
    ->Flash cache emptied: 492 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 14394 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49394291 bytes
    %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 76.00 mb


    OTL by OldTimer - Version 3.2.54.0 log created on 07312012_145826

    Files\Folders moved on Reboot...
    C:\Users\User\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

    PendingFileRenameOperations files...
    File C:\Users\User\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!

    Registry entries deleted on Reboot...
  4. Brennan Newcomer, in training Posts: 52

    I found HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\crossriderapp498@crossrider.com: C:\Users\User\AppData\Local\RewardsArcade\498\Firefox using regedit... can I delete it manually?
  5. Jay Pfoutz Malware Helper Posts: 4,286   +49

    Run this OTL script fix just like normal:


    Remove the following Programs from the Programs list by uninstalling them:

    Conduit - Several open-to-debate toolbars
    Browny02 - Unknown potentially dangerous program
    Full Tilt Poker - Engaged in Ponzi schemes, apparently
    PacificPoker -Engaged in malware distribution

    Post the fix log from OTL once done. Also, let me know if the rogue searches come back.
  6. Brennan Newcomer, in training Posts: 52

    ========== REGISTRY ==========
    Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\crossriderapp498@crossrider.com deleted successfully.

    OTL by OldTimer - Version 3.2.54.0 log created on 08012012_153555

    Conduit - wasn't on the list I think I had uninstalled it before, (there was 2 .dll files left in the folder) I deleted it.
    Browny02 - this is a service for my printer if I remove it my printer doesn't work.
    Full Tilt Poker - I had previously uninstalled this so I just removed the folder with the remaining leftovers.
    PacificPoker - Uninstalled successfully.

    I redid the < %PROGRAMFILES%\*. > scan and they are not showing on the list anymore (except Browny02)

    My new tabs still open in Babylon search (Firefox) Chrome allows me to change what new tabs open as. Is there some way to change the new tab URL in Firefox's hidden settings, I forgot how to access them.

    I downloaded an addon to change the URL that opens in new tabs and it did strange things that it wasn't supposed to. (It kept opening new tabs over and over)
     
  7. Brennan Newcomer, in training Posts: 52

    I opened Firefox's config thing and saw all this stuff.
    [IMG]
  8. Brennan Newcomer, in training Posts: 52

    I forgot to mention, when I open Task Manager there is no menu options at the top so I can't switch to services or close it normally its just a box with the currently running programs.
  9. Jay Pfoutz Malware Helper Posts: 4,286   +49

    Okay. I'll keep that in mind for whitelisting purposes in the future. ;)

    For Task Manager, this might be related to your issue: http://www.helpmyos.com/t955-vista-7-task-manager-small-or-large-mode

    For Firefox, delete all those entries for Babylon search and Crossrider Apps (good job for finding that)!

    For Chrome, open up chrome://chrome/extensions/ in the address bar of Chrome, and tell me what extensions are installed. I'll let you know if they utilize a search campaign, such as Babylon.
  10. Brennan Newcomer, in training Posts: 52

    The Task Manager thing was what your message said, I just had to double-click it, haha.

    I couldn't delete anything on that list so I just saved my bookmarks and did a fresh install of Firefox, I checked the config menu and no more Babylon or "crossfire", yay! (same with new tabs)

    It says I have no extensions in Chrome (I never really used it except to try it out) I'm probably going to uninstall it after this anyway.

    Thankyou!
  11. Jay Pfoutz Malware Helper Posts: 4,286   +49

    If there are no more issues, then we shall clean up!

    Clean up System Restore

    Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."

    To manually create a new Restore Point
    • Go to Control Panel and select System and Maintenance
    • Select System
    • On the left select Advance System Settings and accept the warning if you get one
    • Select System Protection Tab
    • Select Create at the bottom
    • Type in a name I.e. Clean
    • Select Create
    Now we can purge the infected ones
    • Go back to the System and Maintenance page
    • Select Performance Information and Tools
    • On the left select Open Disk Cleanup
    • Select Files from all users and accept the warning if you get one
    • In the drop down box select your main drive I.e. C
    • For a few moments the system will make some calculations:
      [IMG]
    • Select the More Options tab
      [IMG]
    • In the System Restore and Shadow Backups select Clean up
      [IMG]
    • Select Delete on the pop up
    • Select OK
    • Select Delete

    Run OTC to remove our tools

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    Purge old temporary files

    Download CCleaner Slim and save it to your Desktop - Alternate download link

    When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
    Follow the prompts to install the program.

    * Double-click the CCleaner shortcut on the desktop to start the program.
    * Click on the Options block on the left, then choose Cookies.
    * Under Cookies to Delete, highlight any cookies you would like to retain permanently
    * Click the right arrow > to move them to the Cookies to Keep window.
    * Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours
    * Click Cleaner on the left then Run Cleaner on the right to run the program.
    * Important: Make sure that ALL browser windows are closed before selecting Run Cleaner

    Caution: Only use the Registry feature if you are very familiar with the registry.
    Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

    Security Check

    Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
  12. Brennan Newcomer, in training Posts: 52

    Results of screen317's Security Check version 0.99.43
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Microsoft Security Essentials
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Out of date HijackThis installed!
    Malwarebytes Anti-Malware version 1.62.0.1300
    HijackThis 2.0.2
    JavaFX 2.1.1
    Java(TM) 6 Update 31
    Java(TM) 7 Update 5
    Adobe Reader X (10.1.3)
    Mozilla Firefox (14.0.1)
    Google Chrome 20.0.1132.57
    Google Chrome 21.0.1180.60
    Google Chrome VisualElementsManifest.xml..
    ````````Process Check: objlist.exe by Laurent````````
    Microsoft Security Essentials MSMpEng.exe
    Microsoft Security Essentials msseces.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 1%
    ````````````````````End of Log``````````````````````
  13. Jay Pfoutz Malware Helper Posts: 4,286   +49

    Please remove from the Programs list: Java(TM) 6 Update 31 and HijackThis 2.0.2.

    Other than that...good job!

    Personal Tips on Preventing Malware

    See this page for more info about malware and prevention.

    Any other questions before I mark this topic solved?
  14. Brennan Newcomer, in training Posts: 52

    That seems to be everything thanks a bunch I'd be lost without you ;). One more question though would it be better to use a 3rd party firewall such as Zone Alarm instead of the standard Windows firewall? EDIT: Is it worth the 30 bucks for the full version of maleware bytes?
  15. Jay Pfoutz Malware Helper Posts: 4,286   +49

    Both questions... YES!
  16. Jay Pfoutz Malware Helper Posts: 4,286   +49

    Marked as solved.