PDA

View Full Version : Help! Adware_CommandDesktop & ADW_MEDIATICK.AE



Miaka9465
2007-05-18, 02:47
I have used Trend Micro, Ad-Aware Se, & AVG anti-spyware to try and remove the following but will not work.
ADW_MEDIATICK.AE
Adware_CommandDesktop

I currently ran the following program hijackthis.... this is the file it produced.

Logfile of HijackThis v1.99.1
Scan saved at 6:47:25 PM, on 5/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hjt\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu11.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

pskelley
2007-05-20, 18:44
Welcome to Safer Networking, if you still need help and are not receiving it elsewhere, it appears you have missed some important instructions our administrator has posted at the top of the forum, especially this: "BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please read and follow all instructions and post all required logs or reports, anything less will slow your process.
Use "Post Reply" to post the information in the instructions and stay in the same topic.

But did you read and follow the reguired instructions? Trend Micro found the stuff and would not remove it? Is this all Trend reported?
ADW_MEDIATICK.AE
Adware_CommandDesktop
No file names, locations or anything?

Follow these instructions to see what happens:

1) Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list..." Button.
Save it to your desktop. Copy and paste the contents into your reply.

2) How to make files and folders visible:
Click Start > Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm. Click OK.
You may reverse this for safety when we are finished.

3) Please download ATF Cleaner by Atribune
http://www.atribune.org/content/view/25/2/
Save it to your Desktop. We will use this later.

4) AVG Anti-Spyware: Deactivate the Resident Shield
- Before proceeding, deactivate the "Resident Shield" as this may prevent changes to the registry.
- To do this, click "Change State" to the right of the Resident Shield option in the main window.
- You will clearly see the status change to Inactive if you have done this correctly.

5) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu11.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661
227A755E9C2933154389A

Close all programs but HJT and all browser windows, then click on "Fix Checked"

6) RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\WINDOWS\retadpu11.exe <<< delete that file


7) Follow the instruction in the link, make sure your delete or quarantine and post the scan results.
http://forums.security-central.us/showthread.php?t=3165

8) Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Restart the computer and post any information I requested, the uninstall list, the scan report from AVG Anti-Spyware and a new HJT log. Let me know how the computer is running now.

Thanks

Miaka9465
2007-05-21, 20:57
**Hijackthis uninstall list**

Ad-Aware SE Personal
ALPS Touch Pad Driver
Apple Software Update
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AVG Anti-Spyware 7.5
Broadcom 440x 10/100 Integrated Controller
C-Major Audio
Dell ResourceCD
Hijackthis 1.99.1
HijackThis 1.99.1
Intel(R) PROSet/Wireless Software
Internal Network Card Power Management
iTunes
Java(TM) SE Runtime Environment 6 Update 1
K-Lite Mega Codec Pack 2.01
mCore
mDriver
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft Office Professional Edition 2003
mIWA
mIWCA
mLogView
mMHouse
Mozilla Firefox (2.0.0.3)
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB927978)
mToolkit
mWlsSafe
mXML
mZConfig
QuickSet
QuickTime
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
The Lord of the Rings Online™: Shadows of Angmar™ v07.12.30.54
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
World of Warcraft


**AVG Anti-Spyware scan results**

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 12:56:13 PM 5/21/2007

+ Scan result:



:mozilla.100:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.101:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.102:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.98:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.99:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.40:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.166:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.43:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.39:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.44:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.45:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.51:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.52:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.165:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.197:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.61:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.130:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.131:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.132:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.151:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.152:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.153:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.154:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.155:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.156:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.157:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.183:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.184:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.104:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.105:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.106:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.107:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.141:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.142:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.129:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.170:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Web-stat : No action taken.
:mozilla.172:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Web-stat : No action taken.
:mozilla.174:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Web-stat : No action taken.
:mozilla.175:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Web-stat : No action taken.
:mozilla.220:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
:mozilla.147:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.150:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.103:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.148:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.149:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.82:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.83:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.84:C:\Documents and Settings\CC\Application Data\Mozilla\Firefox\Profiles\0g0uvew8.default\cookies.txt -> TrackingCookie.Zedo : No action taken.


::Report end

Miaka9465
2007-05-21, 21:24
After I did everything that was listed in the post, I went ahead and did trend micro scan again.
Still says I have a infection named ADWARE_COMMANDDESKTOP whenever I select the option "Select an individual action for each detected infection" so I can see the file that is infected it says "files infected by this grayware/spyware" and does not show any files.

pskelley
2007-05-21, 21:26
Please read and follow the directions carefully


Trend Micro found the stuff and would not remove it? Is this all Trend reported?
ADW_MEDIATICK.AE
Adware_CommandDesktop
No file names, locations or anything?


7) Follow the instruction in the link, make sure you

delete or quarantine and post the scan results.
http://forums.security-central.us/showthread.php?t=3165


Restart the computer and post any information I requested, the uninstall list, the scan report from AVG Anti-Spyware and a new HJT log. Let me know how the computer is running now.

Thanks

Makes that TM scan next to worthless, run the AVG scan again and delete or quarantine what it finds this time, post the scan results and a new HJT log. Tell me about any malware issues at that point.

pskelley
2007-05-21, 21:37
Unless I am missing something, you have no antivirus program running on this computer. Going online without one is cyber-suicide anymore.
If you need a free one, give this one a try. Make sure to stay with free.
http://free.grisoft.com/doc/avg-anti-virus-free/lng/us/tpl/v5
Once you have it downloaded and updated, then do a complete system scan and see if it will do what TM won't, let me know the results.

Thanks

tashi
2007-05-30, 19:25
This topic has been archived due to lack of a response.

If you need it re-opened, please send me a private message (pm) and provide a link to the thread. Applies only to the original poster, anyone else with similar problems please start a new topic.