This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Blekko infection...or? [Solved]

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the initial file after running as instructed with the code, however the hijack continues! I'm not certain if you wanted me to "run scan" or "run fix" when you instructed me to: run "a new OTL log by rerunning it after reboot without custom scans scrip." ========== OTL ========== C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\extensions\[removed] moved successfully. C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\extensions\[removed] moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 56468 bytes User: Default User ->Flash cache emptied: 0 bytes User: John-Sandi 1 User: Public User: UpdatusUser ->Flash cache emptied: 56466 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: John-Sandi 1 ->Temp folder emptied: 144896 bytes ->Temporary Internet Files folder emptied: 784741 bytes ->FireFox cache emptied: 51188804 bytes ->Opera cache emptied: 34214 bytes User: Public ->Temp folder emptied: 0 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 432 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50467 bytes RecycleBin emptied: 1179 bytes Total Files Cleaned = 50.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.43.0 log created on 05202012_124415 Files\Folders moved on Reboot… C:\Users\John-Sandi 1\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot…
I meant to ask you to run the OTL scan again after running the OTL fix which produces two different logs for review. One which is exactly what you have posted just now and two is the fresh log for OTL. Could you please uninstall Firefox and then reinstall it again?
I misunderstood how you wanted OTL run, sorry. I've uninstalled Firefox and now have the new 12.0 version…and still have Blekko!!!
Whew…I found it!!! :woot: Hidden in "Ad-Aware" in the browser security files. I uninstalled the program, rebooted and it no longer shows up…I think this did it finally!!! I'm about to do a thorough cleaning. Thanks so very much for your time! John
Great! :)

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now copy/paste the code into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
Combofix /Uninstall
[external image: Posted Image]

===================================================

Thank you for your patience, and performing all of the procedures requested. I would also like to take this opportunity to apologize for any delay that may have occurred.

————————————————————————————————————–

MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.


Passwords
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.


SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How Did I Get Infected In The First Place? by TonyKlein
  • How to Prevent Malware by miekiemoes
  • PC Safety and Security–What Do I Need?

To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an add-on available for both Firefox and IE.

  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
  • Download Host.zip and Save it to your Desktop.
  • Right-click hosts.zip and select 'Extract all files' or 'Extract files…'.
  • Follow the prompts and click 'Finish'.
  • This will open the newly created hosts folder on your Desktop.
  • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
  • Once updated you should see another prompt that the task was completed.
Follow this list and keep your antivirus program and antispyware programs updated and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so.

**Please respond this one more time to ensure it is resolved and close this topic.
I've run OTL.exe clean up function, I don't have a "run" to click…or at least I don't know where it is, I could find it on XP but not Win 7??? No problem about any delay we all have lives to live, I appreciate all your effort!!! I always keep my computers up to date and have several good spyware/malware programs running, I keep all of them up to date as well including the one that was compromised (Ad-Aware). I have SpywareBlaster, Spybot, Threatfire, Superantispyware, WinPatrol and Malwarebytes along with a good firewall and anti-virus. I'm at fault here, I clicked the download button at Cnet where this nasty was hiding, just goes to show you NO website is truly safe! I'm installing the MVPS Hosts File as suggested too! Thanks again for all your time! John

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI