Constant Nonsense Popup Box in IE...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by artistsneverdie, Jul 19, 2005.

  1. artistsneverdie

    artistsneverdie Private E-2

    Hi everyone,

    Recently got absolutely inundated with spyware and adware by 1 poxy website. I've followed all the instructions on removing spy sherrif which was one of the major culprits.

    Thought I had erradicated it all, until I tried loading IE today, when it brings up a small popup with "shfksdhjfhjse" and an "ok" option... it's in the form of a standard javascript alert with an "ok" only option. (I can screenshot if required). It won't let the operation continue until you've clicked the close "x" in the top right.

    This popup appears everytime a new window is opened, a link is clicked or a refresh is performed. I've followed the instructions and used AdAware SE, Microsoft Spyware Beta1, Spybot S&D, CCleaner, BitDefender etc... but nothing seems to get rid of it. It's almost as though it's a half removed piece of spyware or something.

    Any help you guys can provide would be great, as this is on my work computer and it's severly disrupting all my website/ graphic design work I do =(.

  2. artistsneverdie

    artistsneverdie Private E-2

    Just as a quick addition which has happened in the past few minutes...

    The TNS network has started highjacking my system again. :(

    I was damned sure this had been erradicated but it's come back somehow and I've only visited one site which I know doesn't contain any spyware.
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program

    Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
  4. artistsneverdie

    artistsneverdie Private E-2

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach your log here to your message.

    Is the below your expected Startpage:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://C:\WINDOWS\blank.mht

    Also the below does not seem valid, do you know what it is:
    O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
    Last edited: Jul 20, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to svchost.exe or moto Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":


    If that does not work, try the short name: moto

    Now exit HijackThis and we will restart it in a few lines with different options.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\svchost.exe <--- just incase it is still running. The other step should have kill it.

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {78364D99-A640-4ddf-B91A-67EFF8373045} - C:\WINDOWS\system32\appwiz.dll
    O2 - BHO: (no name) - {B75F75B8-93F3-429D-FF34-660B206D897A} - C:\WINDOWS\System32\zolker005.dll
    O2 - BHO: ZToolbar Activator Class - {FFF5092F-7172-4018-827B-FA5868FB0478} - C:\WINDOWS\System32\ztoolb005.dll
    O3 - Toolbar: ZToolbar - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - C:\WINDOWS\System32\ztoolb005.dll
    O4 - HKCU\..\Run: [wupd] C:\WINDOWS\System32\symcsvc.exe
    O15 - Trusted Zone: *
    O15 - Trusted Zone: * (HKLM)
    O15 - Trusted IP range:
    O23 - Service: svchost.exe (moto) - Unknown owner - C:\WINDOWS\svchost.exe <--- this may be gone if the previous steps worked

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
  7. artistsneverdie

    artistsneverdie Private E-2

    Thanks for the help, it seems to have cleared out the junk and I haven't had any popups "yet"...

    The only problem I had was killing the svchost process as there were two when I run the HJT Process Manager and it gave an error saying they were protected by windows. I booted into safe mode and disabled the svchost process through services.msc. Then back in XP normal mode I removed the svchost service using "delete an NT service", which seemed to work.

    The only file I was able to find with explorer was the svchost.exe, the others didn't exist and I have view hidden and system files on as standard, and system restore turned off anyway.

    I've attached the log here as requested.

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first step was not to kill the svhost.exe process. The first step was to run services.msc.

    Also the only svchost.exe process that needed to be killed was this one: C:\WINDOWS\svchost.exe
    Not the ones in system32.

    You did not answer my questions from message # 5.

    Also the below does not seem valid for Ccleaner and we will need to run some other tools to look for some potential hidden problems.

    O21 - SSODL: CCleaner - {8AF0A992-DD76-300B-4C0D-D6D6CBD9A971} - c:\program files\applications\ccleaner\winejiej32.dll

    Other than that, your log is clean.

    Please downloaded and extract the files from the attachment to its own folder - C:\Program Files\Find Qoologic2.
    Then, DoubleClick Find-Qoologic.bat to run the tool. It will produce a log of what it finds. Please attach it to your next message.

    Attached Files:

    Last edited: Jul 21, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds