Page 11 of 13 FirstFirst ... 78910111213 LastLast
Results 101 to 110 of 130

Thread: New advertising malware?

  1. #101
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    gotcha!

    We'll be here if needed.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  2. #102
    Member
    Join Date
    Feb 2015
    Posts
    73

    Default

    Quote Originally Posted by Juliet View Post
    gotcha!

    We'll be here if needed.

    So far today, everything looked good. I'm going leave Firefox active for a bit tonight, to see if any rogue processes come up. I'm fairly confident that I won't see any, but, once bit, twice cautious.

    Just out of curiosity, if that was the problem, will the offending DLL's be added to the definition files at some point? I still have them in the recycle bin, and am going to try to get them onto a memory stick or something.

  3. #103
    Member
    Join Date
    Feb 2015
    Posts
    73

    Default

    I have the 2 DLL files isolated in secure storage. Here are the VirusTotal links:


    colers.dll

    https://www.virustotal.com/en/file/c...is/1426108563/


    tivesen.dll

    https://www.virustotal.com/en/file/6...is/1426108659/

  4. #104
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    So far today, everything looked good. I'm going leave Firefox active for a bit tonight, to see if any rogue processes come up. I'm fairly confident that I won't see any, but, once bit, twice cautious.
    wooohooo!
    I'm checking into the other to see if the R&D team needs those.

    It's possible you may want to contact your antivirus vendor with these.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #105
    Member
    Join Date
    Feb 2015
    Posts
    73

    Default

    Quote Originally Posted by Juliet View Post
    wooohooo!
    I'm checking into the other to see if the R&D team needs those.

    It's possible you may want to contact your antivirus vendor with these.

    The status report for today is... still no rogue processes.

    It looks like we have the problem under control. Quick question... what program was calling the DLL's? Do I need to remove that program and associated registry entries?

  6. #106
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Quote Originally Posted by jhrowehl View Post
    The status report for today is... still no rogue processes.

    It looks like we have the problem under control. Quick question... what program was calling the DLL's? Do I need to remove that program and associated registry entries?
    To give you an exact program name..., don't know if I can but from what we did find and remove

    C:\ProgramData\Optimizer ---> 3 / 68 (PUP)
    Publisher: MicroTools
    Both of those are capable of adding entries into the C:\Users\Henry\AppData\Roaming folder where malware so often does.
    I honestly think if there was anything residual left behind it would had reared it's ugly head by now.

    We need to remove tools and quarantine folders.

    DelFix
    • Please download DelFix
      or from here http://www.bleepingcomputer.com/download/delfix/ and save the file to your Desktop.
    • Double-click DelFix.exe to run the programme.
    • Place a checkmark next to the following items:
      • Activate UAC
      • Remove disinfection tools
      • Purge system restore

    • Click the Run button.

    -- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).


    ~~~~~~~~~~~~~~~~~~~


    The following programmes come highly recommended in the security community.
    • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
    • CryptoPrevent places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
    • Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
    • Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
    • NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
    • Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
    • Secuina PSI will scan your computer for vulnerable softwarethat is outdated, and automatically find the latest update for you.
    • SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
    • Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.


    Want to help others? Join the ClassRoom and learn how.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #107
    Member
    Join Date
    Feb 2015
    Posts
    73

    Default

    OK, I think I'm ready to say that the problem is gone.

    I'm still curious as to which program was running that called the DLL's that were deleted. I know that's not an easy thing to do. Is it possible to find out with some type of registry scan?

  8. #108
    Member
    Join Date
    Feb 2015
    Posts
    73

    Default

    I did a quick search of the registry, and came up with the colers.dll file in 4 locations. I didn't find the other one that was in the deleted directory, tivesen.dll.
    I've attached a file with the registry keys listed. Don't know if it will help or not, but, I figured it couldn't hurt.
    Attached Files Attached Files

  9. #109
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    OK, I think I'm ready to say that the problem is gone.
    It was a battle!

    CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090} which I think can mean task bar, tool bar or BHO
    56FDF344-FD6D-11d0-958A-006097C9A090 is a windows system Taskbar Communication component.
    AdwCleaner in different logs took it out

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}]
    @="Task Bar Communication"
    When searching it was also located when asking someone to do a Search for "ask"
    Now, if this applies to you, heaven only knows.

    Have you done a search to see if this folder is still on the computer?
    C:\\Users\\Henry\\AppData\\Roaming\\xaeojhej


    We can take out those reg entries

    Next, launch Notepad, (Start > Run, type in: notepad) copy and paste next present in the quotebox below in it:


    Windows Registry Editor Version 5.00

    [-HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}]

    [-HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32]

    [-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}]

    [-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32]

    [-HKEY_USERS\S-1-5-21-1310488628-551009281-1505269296-1000\Software\Classes\Wow6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}]

    [-HKEY_USERS\S-1-5-21-1310488628-551009281-1505269296-1000\Software\Classes\Wow6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32]

    [-HKEY_USERS\S-1-5-21-1310488628-551009281-1505269296-1000_Classes\Wow6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}]

    [-HKEY_USERS\S-1-5-21-1310488628-551009281-1505269296-1000_Classes\Wow6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32]

    Save this as fix.reg and change the "Save as type" to "All Files" and place it on your desktop. It should look like this:
    Double-click on it and when it asks you if you want to merge the contents to the registry, click "Yes" or "OK". You should receive a message that it was successful. You may delete the file afterwards
    Last edited by Juliet; 2015-03-14 at 02:40.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  10. #110
    Member
    Join Date
    Feb 2015
    Posts
    73

    Default

    Yes, it was a battle! But, we managed to track it down, and win the fight.

    Quote Originally Posted by Juliet View Post
    Have you done a search to see if this folder is still on the computer?
    C:\\Users\\Henry\\AppData\\Roaming\\xaeojhej
    Yes I did, no it's not. I had removed it per your instructions in a prior message. That's when the problem went away. I managed to recover it, and the contents, from the recycle bin, and have the folder and the files isolated in a secure storage area.

    The second DLL file, that was in the folder with the colers.dll file, wasn't in the registry. Makes me curious...

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •