2011-05-03, 21:02
My name is Rex. I have many years of computer experience and so have fought this awhile before coming here. Clearly malware is not my specialty. I have always been able to fix infections until now however, & now find myself a "newbie" here. :red:


These infections only show up on SS&D. Malwarebytes - Antimalware, ESET NOD32 V4, Vundofix, etc don't show anything.

I searched for infection because my email account started sending spam. It took a day or so to figure out that it was ONLINE access not machine access that caused that but I *assume* that they got the un/pw from infection on the machine.

Original SS&D infections were Doubleclick Tracking cookie, MTC.MakeMeSearch.com (registry key), Right Media cookie and Statcounter cookie.

You can assume I have run just about every "fixer" type software on my machine (including combofix) before I ever showed up on this forum. I have not used any registry cleaner in probably 6 months however. Machine seems to be OK but I thought it was OK even while I was sending out spam emails. As I said they did not go out through desktop OUTLOOK channel.

This next bit of info took awhile to figure out. What makes this maddening is that the SS&D scan will show clean if the Firefox browser is open. But it will come back infected if it is closed! If the browser is closed, you can clean the infection with SS&D and show infection on the next scan even without reboot. Reboot, of course, always shows return. Doesn't matter if I do the process in safe mode or not, it will not clean. I have even used rkill to stop root kit processes before cleaning with SS&D with no luck.

Having no luck myself, I will stop dead in my tracks and work with you.

I have run ERUNT & DDS

Below are my attachments:

I appreciate any help you can give me.


2011-05-17, 01:47

Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

Until we deem your system clean I am going to ask you not to install or uninstall any software or hardware except for the programs we may run.

Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.

Thank You Atribune

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

2011-05-17, 07:12
Hi Ken,

Thanks very much for taking this on. I can certainly use the help.


Here is the MBAM log

Malwarebytes' Anti-Malware

Database version: 6594

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

5/16/2011 10:38:41 PM
mbam-log-2011-05-16 (22-38-41).txt

Scan type: Quick scan
Objects scanned: 168857
Time elapsed: 1 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Next post(s) will have the OTL logs.

2011-05-17, 07:14
Here is the OTL.txt log

2011-05-17, 07:16
Hi Ken,

Here is the Extras.txt log.

Thanks again, and let me know what else I need to do.


2011-05-17, 11:26

Just a few things jumping out at me, nothing earth shattering

Do you want these in your IE Trusted Zone ?
Trusted Zone: azoogleads.com\login
Trusted Zone: epicdirectnetwork.com\www

I also see an entry for Junky Toolbar, did you install that ?

Are you being redirected or getting any unwanted pop up windows ?

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan (http://eset.com/onlinescan)
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop.

Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button.
Accept any security warnings from your browser.
Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png
Make sure that the option "Remove found threats" is Unchecked
Push the Start button.
ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time.
When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png
Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply.
Push the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png button.
Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.

2011-05-17, 18:37
Hi Ken,

I am not being redirected in Firefox at least. I pretty much never use IE. But best I know I am not being redirected.

I am not familiar with junkytoolbar. I do have an affiliate tracking program called "statsjunky" installed.

I looked under "uninstall software" in the control panel just to see if a junkytoolbar showed up. I didn't see it. Nor did it show up as an addon in FF or IE.

Then I went to find it in the logs you got from me and only see references to statsjunky. I am not sure if you are referring to statsjunky or not but this is an app I have had installed for 2 years.

The IE trusted zones of azoogleleads and epicdirectnetwork were both put in there by me as epicdirect(was azoogle) has login issues and I was hoping this would fix it. (It didn't) Epic Direct (Azoogle) is a CPA network and I am an online marketer. Those could be removed if necessary.

---------ESET online scanner-------------
First let me say that apparently they have changed things since your instructions were made. The links are all different for me. But starting out at http://eset.com/onlinescan which redirects to http://www.eset.com/us/online-scanner, I followed the instructions with IE. Even after checking the "I have read and agree..." checkbox the "start" button would never activate. I played with security levels and making sure .js ran but no help. It appears they may have a problem.

So I brought it up in Firefox and had to download the ESET Smart Installer and save to my desktop. I set it as you stated and ran it. I have 2 - 2TB drives. It took over 2 hours to run but came back clean and gave me no option to see a log. It only offered me options to buy or take a 30 day trial. ESET NOD32 V4 is what I use full time anyway. I know this is a good double check though.


So I have no new info other than that. Anything else to try?

Thanks very much,

2011-05-17, 19:25
You look like your good to go Rex.

Any problems in the future please post back

How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

Safe Surfn

2011-05-18, 02:33
Hi Ken thanks for all your help...

But why does Spybot S&D still find 2 problems EVERY time that I have the browser closed?

See the very first post. I repeated the spybot portion of the log below.

---------Spybot Search and Destroy Short log after cleaning --------
Win32.Small.ddx: Bookmark (Firefox: Rex (default)) (Bookmark, fixed)

Virtumonde: Bookmark (Firefox: Rex (default)) (Bookmark, fixed)

Win32.Small.ddx: Bookmark (Firefox: Rex (default)) (Bookmark, fixed)

--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

This shows up EVERY time. If I run it again now it will be there.

Just wondering...


2011-05-18, 03:30
Lets do this Rex

Download and Run SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1 (http://jpshortstuff.247fixes.com/SystemLook.exe)
Download Mirror #2 (http://images.malwareremoval.com/jpshortstuff/SystemLook.exe)

Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield:


Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

2011-05-18, 06:12
Hi Ken,

I did this and it came back with a warning that I was running wow64 and to use systemlook_x64.

I tracked that down and got the same results (except for the warning)

SystemLook 04.09.10 by jpshortstuff
Log created at 22:09 on 17/05/2011 by Rex
Administrator - Elevation successful

========== filefind ==========

Searching for "Win32.Small.ddx"
No files found.

========== regfind ==========

Searching for "Win32.Small.ddx"
No data found.

-= EOF =-

So I wonder why SS&D find it?

Thanks very much...


2011-05-18, 11:12
Try this one Rex


2011-05-18, 16:00
That is the one I used Ken. :)


2011-05-18, 19:12
Hello Rex

All the problems appear to be Firefox tracking cookies. Sometimes Spybot has trouble removing Firefox tracking cookies. There are suggestions in the following post on how to remove them as well as block them from being stored:

Read this

2011-05-18, 20:13
Hi Ken,

Are these Cookies or bookmarks? I viewed the cookie list and did not see them.

Anyway, I cleared ALL cookies and then closed firefox. Then ran SS&D.

Here is the report

--- Search result list ---
Win32.Small.ddx: Bookmark (Firefox: Rex (default)) (Bookmark, nothing done)

Virtumonde: Bookmark (Firefox: Rex (default)) (Bookmark, nothing done)

Win32.Small.ddx: Bookmark (Firefox: Rex (default)) (Bookmark, nothing done)

--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

Coool huh? Does SS&D detect Flash cookies? I could delete all those I guess. I just viewed my flash cookies and didn't see any that matched up with the ones that SS&D is complaining about.


2011-05-18, 20:43
You know what I would do is post in the Spybot forum. They are more familiar with that program than I am , I will keep this tread open for you so post back and let me know how it went.


2011-05-22, 23:26
Ken I wanted to come back here and let you know what was found. In the Spybot forum it was noted that those were bookmarks it was flagging.

Then after SS&D runs you can click on the plus sign where it refers to the error and it gives you the address of the website that was bookmarked and flagged as bad.

I then opened the "organize bookmarks" in firefox and tracked them down and deleted them.

Problem solved.

I just wanted to get back with you so that you would know the results and to thank you for your help again. I appreciated it so much.:thanks:


2011-05-23, 01:55
Thank you Rex for letting me know

Things running ok now ?

2011-05-23, 02:22
Yup everything is running fine now.



2011-05-23, 03:21

Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups

How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

Safe Surfn

2011-05-23, 06:24
Oh I forgot to mention I put $50 in the donation box. And I know it doesn't go to you but at least I can help where I can. Hopefully others will help some if they can.

Thanks again for your help Ken. :rockon:


2011-05-23, 10:59
Thank you Rex,

The donations go for research and to help keep us online, much appreciated

Take care

2011-05-27, 13:01
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.