Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help with a phantom infection


  • Please log in to reply
13 replies to this topic

#1 garak

garak

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 22 October 2017 - 03:50 PM

Hello, although its my first post i've lurked in this forum for a while so thank you for the help in many problems to date.

 

Since i'm new i'm not sure if this is the right sections, apologies if i'm wrong.

 

I have an infection problem, i think.

 

I have 3 browsers installed in my pc, Vivaldi, which i believe is derived from chromium, Firefox and of course Edge. Suddenly a strange thing happened, all three browsers started taking me to a site called Ame.Avira. that looked like an ad for paid Avira. The weird thing is it was not when i clicked links but entire sections of the browsers UI had become a link, when i clicked on buttons in the browser i was redirected.

 

I did some research and found this sites giving advice:

 

https://sensorstechforum.com/ame-avira-redirect-virus-remove-pc/

 

http://virusguides.com/remove-ame-avira-virus/

 

The weird thing is i followed the advice but found nothing, i went to safe mode, checked extensions, host files, registry, there was no sign of the infection to remove!! I scanned with Avira, which i do have installed, Malwarebytes and ESET online scanner to have another opinion. Result: NOTHING. Somewhere along the way the effect dissappeared on its own, but the fact remains IT WAS THERE for 20 minutes or so.

 

I'm concerned as everything seems normal now but no infection was ever found or removed, it might still lurk.

 

Info: Running Windows 10 with the fall upgrade

         Avira running

         Malwarebytes free version

 

Any info or advice would be appreciated

 

Garak



BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:27 PM

Posted 22 October 2017 - 04:35 PM

Welcome to BC....

 

I suggest you uninstall any programs suggested by those sites.

 

Are you using the FREE Avira or the PAID version?

The free Avira  is bundled with adware....not that it has anything to do with what you saw...Ame.Avira.

 

Use the programs below to clean, remove adware and remove malware.

 

 

Use CCleaner to remove Temporary files, program caches, cookies, logs, etc. Use the Default settings. No need to use the

Registry Cleaning Tool...risky. Pay close attention while installing and UNcheck offers of toolbars....especially Google.

After install, open CCleaner and run by clicking on the Run Cleaner button in the bottom right corner.

CCleaner - PC Optimization and Cleaning - Free Download

 

Download AdwCleaner by Xplode onto your desktop. (compatible with Windows 7, 8 and 10)

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  • download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 JCNWB

JCNWB

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:27 AM

Posted 23 October 2017 - 01:34 AM

i tried running the adwCleaner, it seems administrator has blocked it from running and i cant unblock it despite pressing unblock and thereafter running as administrator



#4 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:27 PM

Posted 23 October 2017 - 03:30 AM

Try shutting down Avira and Malwarebytes before running AdwCleaner. If that doesn't work then try it in Safe Mode With Networking.

If you haven't uninstalled the programs suggested in the links of your first post....do that, too.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#5 garak

garak
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 23 October 2017 - 12:40 PM

Thanks for the reply Buddy215

 

Fortunately i didn't install any of the software on those sites, they seemed mpore like ads to me.

Regarding your question i have the free version of Avira.

 

Here are the logs, although they seem to have found something i don't see anythin related to Ame.Avira.

 

JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Pro x64 
Ran by ACSM (Administrator) on 22/10/2017 at 22:53:15.94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 2 
 
Successfully deleted: C:\Users\ACSM\AppData\Roaming\Mozilla\Firefox\Profiles\FmWeVrDT.default\searchplugins\startpage-hxxps.xml (File) 
Successfully deleted: C:\Users\ACSM\AppData\Roaming\Mozilla\Firefox\Profiles\FmWeVrDT.default\searchplugins\youtube-video-search.xml (File) 
 
Deleted the following from C:\Users\ACSM\AppData\Roaming\Mozilla\Firefox\Profiles\FmWeVrDT.default\prefs.js
user_pref(browser.urlbar.suggest.searches, false);
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22/10/2017 at 22:55:28.01
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
AwCleaner
 
# AdwCleaner 7.0.3.1 - Logfile created on Sun Oct 22 21:57:06 2017
# Updated on 2017/29/09 by Malwarebytes 
# Running on Windows 10 Pro (X64)
# Mode: clean
 
***** [ Services ] *****
 
No malicious services deleted.
 
***** [ Folders ] *****
 
No malicious folders deleted.
 
***** [ Files ] *****
 
Deleted: C:\END
 
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks deleted.
 
***** [ Registry ] *****
 
No malicious registry entries deleted.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries deleted.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries deleted.
 
*************************
 
::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0
 
 
 
*************************
 
C:/AdwCleaner/AdwCleaner[S0].txt - [948 B] - [2017/10/22 21:54:41]
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########


#6 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:27 PM

Posted 23 October 2017 - 01:58 PM

  • download Security Check by glax24 and save the file to the Desktop
  • Run the tool by accepting all the Security prompts
  • when complete the tool will produce a log file C:\SecurityCheck\SecurityCheck.txt and also copy the contents to the Clipboard
  • Simply Paste the log to your reply

Do you have an ad blocker installed in your browsers?


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#7 garak

garak
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 23 October 2017 - 02:03 PM

The only extension on my browsers is Privacy badger

 

Log:

 

SecurityCheck by glax24 & Severnyj v.1.4.0.52 [25.07.17]
WebSite: www.safezone.cc
DateLog: 23.10.2017 13:00:15
Path starting: C:\Users\ACSM\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: ACSM
VersionXML: 4.71is-20.10.2017
___________________________________________________________________________
 
Windows 10(6.3.16299) (x64) Professional Release: 1709 Lang: English(0409)
Installation date OS: 18.10.2017 08:58:37
LicenseStatus: Windows®, Professional edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
SystemDrive: C: FS: [NTFS] Capacity: [931.1 Gb] Used: [276.6 Gb] Free: [654.5 Gb]
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Avira Antivirus v.15.0.32.12
-------------------------- [ SecurityUtilities ] --------------------------
Malwarebytes version 3.2.2.2029 v.3.2.2.2029
--------------------------- [ OtherUtilities ] ----------------------------
7-Zip 15.06 beta (x64) v.15.06 Warning! Download Update
Uninstall old version and install new one.
-------------------------------- [ Java ] ---------------------------------
Java 7 Update 51 v.7.0.510 Warning! This software is no longer supported. Please uninstall it and use Java SE 8 (jre-8u152-windows-i586.exe).
--------------------------- [ AdobeProduction ] ---------------------------
Adobe AIR v.2.5.1.17730 Warning! Download Update
------------------------------- [ Browser ] -------------------------------
Vivaldi v.1.8.770.56 Warning! Download Update
Mozilla Firefox 56.0 (x86 en-US) v.56.0 Warning! Download Update
----------------------------- [ EmailClient ] -----------------------------
Mozilla Thunderbird 52.4.0 (x86 en-US) v.52.4.0
------------------ [ AntivirusFirewallProcessServices ] -------------------
Avira Scheduler (AntiVirSchedulerService) - The service is running
C:\Program Files (x86)\Avira\Antivirus\sched.exe v.15.0.32.11
Avira Real-Time Protection (AntiVirService) - The service is running
C:\Program Files (x86)\Avira\Antivirus\avguard.exe v.15.0.32.11
Avira Mail Protection (AntiVirMailService) - The service has stopped
Avira Web Protection (AntiVirWebService) - The service has stopped
Avira Service Host (Avira.ServiceHost) - The service is running
C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe v.1.2.98.29730
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe v.1.2.98.29730
C:\Program Files (x86)\Avira\Antivirus\avshadow.exe v.15.0.32.12
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe v.15.0.32.11
Malwarebytes Service (MBAMService) - The service has stopped
C:\Program Files\Windows Defender\MSASCuiL.exe v.4.12.16299.15
Windows Defender Antivirus Service (WinDefend) - The service has stopped
Windows Defender Antivirus Network Inspection Service (WdNisSvc) - The service has stopped
----------------------------- [ End of Log ] ------------------------------


#8 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:27 PM

Posted 23 October 2017 - 02:23 PM

Uninstall these programs:

Java 7 Update 51 v.7.0.510

Adobe AIR v.2.5.1.17730

Vivaldi v.1.8.770.56 (OR UPDATE)

 

Suggest you install Adblock Plus. Once installed click on the ABP icon and choose Filter Preferences. Then UNcheck the box

next to Allow some non-intrusive advertisements. Adblock Plus :: Add-ons for Firefox

 

Block ad and tracking cookies....aka Third Party cookies....from installing in your browsers. Once blocked, run CCleaner to remove the

existing ones. How to disable third-party cookies in all major web browsers


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#9 garak

garak
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 23 October 2017 - 04:26 PM

I installed adblock

updated Vivaldi as is my main browser 

third party cookies were already blocked

unistalled adobe air

ran ccleaner

 

only part where i ran into a problem is java, since its needed for a work related software, i checked and java 8 should work if you think updating is safe.

 

Other than that you think there is some kind of infection in my pc? the fact that part of the browsers ui behaved as links made me think so, but all my initial scans and the software you told me to use don't seem to pick up anything related to what i saw. I'm a little confused.


Edited by garak, 23 October 2017 - 04:34 PM.


#10 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:27 PM

Posted 23 October 2017 - 05:06 PM

No, I don't see any reason to think the computer is infected. If your searches are being redirected or you are seeing ads after installing

Adblock Plus then it is possible that there is some adware lurking. Let me know if that happens.

 

You should get the latest Java and uninstall the old one. Be sure to pay attention while installing because it will be bundled with some adware and unless

you UNcheck its offer it will install. java.com: Java + You


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#11 garak

garak
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 23 October 2017 - 05:30 PM

I'll get the latest Java

 

Adblock is working ok, in fact everything is perfectly normal now (even before the scans, the effect passed), but that little episode did spook me, specially since there seems to be no reason, explanation or culprit found.

It was weird, along all three browsers the upper left corner of the ui behaved as a link, if i clicked back, reload buttons, etc. all opened the same Ame.Avira site.



#12 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:27 PM

Posted 23 October 2017 - 06:49 PM

You may of landed on a web page that was hacked/ compromised. Odd though that the ad appeared on all browsers at once. Maybe what

JRT found and removed was the culprit. Like I said earlier...let me know if ads or redirects occur.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#13 garak

garak
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 24 October 2017 - 06:44 PM

well no more redirects have happened, its all back to normal. I guess its the end of it unless you think there's something else i need to do.

 

Thanks for all the help Buddy, really appreciate it.



#14 buddy215

buddy215

  • Moderator
  • 13,195 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:27 PM

Posted 24 October 2017 - 06:53 PM

You're welcome...happy surfin'


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users