having problems with popups - have tried all in the malware removal guide

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gerard.keenaghan, Feb 21, 2007.

  1. gerard.keenaghan

    gerard.keenaghan Private E-2

    Can anyone help me please
     

    Attached Files:

    Last edited: Feb 21, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome


    We will also need a small explanation of what is up with your PC, do the popups have names if so what?


    Also we will need the other logs as per the guide, ShowNew, GetRunKeys and Bitdefender.
     
  3. gerard.keenaghan

    gerard.keenaghan Private E-2

    Hi,
    The popups start on the toolbar with !triangle and lead to various antispyware and antivirus download sites. One common popup is computer speed and efficiency is down by 47% and 39% (can't remember which way round).
    Please find attached logs as requested.

    Thanks,
    Gerard
     

    Attached Files:

  4. gerard.keenaghan

    gerard.keenaghan Private E-2

    Hi Halo,
    Just an update on some of the popups
    PC Registry Cleaner (www.plimus.com)
    Error Protector
    PSW.xVIR Spyware
    Drive Cleaner
    Antivermins.com

    any help?

    Thanks
    Gerard.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to delete these files and folders:

    c:\program files\common files\winantispyware 2007 free
    C:\Program Files\Video Access ActiveX Object
    C:\Documents and Settings\Gerard\Application Data\WinAntiSpyware 2007
    C:\Program Files\MalwaresWipeds
    C:\Program Files\WinAntiSpyware 2007
    C:\Program Files\Common Files\WINANT~1
    C:\Program Files\Common Files\WINANT~2
    C:\WINDOWS\system32\drivers\"etc"


    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video Access ActiveX Object\isadd.dll
    O4 - HKLM\..\Run: [DC6_Check] "C:\Program Files\Common Files\WinAntiSpyware 2007 Free\uwasdc.exe"
    O4 - HKLM\..\Run: [ERS_Check] "C:\Program Files\Common Files\WinAntiSpyware 2007 Free\uwasers.exe"
    O4 - HKLM\..\Run: [was7cw] C:\Program Files\Common Files\WinAntiSpyware 2007\was7cw.exe -c

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  6. gerard.keenaghan

    gerard.keenaghan Private E-2

    The following happened when I tried to delete through windows explorer. I did not pass the delete steps.

    c:\program files\common files\winantispyware 2007 free Popup stating "cannot delete uwasdc.exe Access is denied"
    C:\Program Files\Video Access ActiveX Object Popup stating "cannot delete isadd.dll it is being used by another person or program"
    C:\Documents and Settings\Gerard\Application Data\WinAntiSpyware 2007 Deleted
    C:\Program Files\MalwaresWipeds Deleted
    C:\Program Files\WinAntiSpyware 2007 Deleted
    C:\Program Files\Common Files\WINANT~1 This does not exist
    C:\Program Files\Common Files\WINANT~2 This does not exist
    C:\WINDOWS\system32\drivers\"etc" Deleted

    Also I don't understand what you mean by th R0 - O4 lines of text in your reply.

    thanks for your help
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use add/remove programs to uninstall:
    Winantispyware 2007

    What part if this do you not understand?
    We still need new logs for:
    GetRun
    ShowNew
    HJT
     
  8. gerard.keenaghan

    gerard.keenaghan Private E-2

    Done,
    tried it but O4 [DC6.....]..... & [was....].... were not there to check & fix.

    attached are logs. for some reason runkeys will not upload
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myoffice.esb.ie/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.presario.net/scripts/...rchredir2.dll?c=1c02&lc=0809&s=search&ap=b204 G
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/...rchredir2.dll?c=1c02&lc=0809&s=search&ap=b204 G
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/...rchredir2.dll?c=1c02&lc=0809&s=search&ap=b204 G
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.eircom.net/
    O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video Access ActiveX Object\isadd.dll
    O21 - SSODL: didynamia - {8329660f-e248-4872-98cc-fb9c4fec7ba8} - (no file)

    After clicking Fix, exit HJT.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the Folders button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Video Access ActiveX Object
    C:\Program Files\Common Files\WinAntiSpyware 2007 Free
    C:\Program Files\Common Files\WinAntiSpyware 2007


    * Return to Killbox, go to the Folders menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete Folders button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run Pocket Killbox again by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Video Access ActiveX Object\isamntr.exe
    C:\Program Files\Video Access ActiveX Object\pmsnrr.exe
    C:\Program Files\Video Access ActiveX Object\isamini.exe
    C:\Program Files\Video Access ActiveX Object\pmmnt.exe
    C:\Program Files\Common Files\WinAntiSpyware 2007 Free\uwasdc.exe G
    C:\Program Files\Common Files\WinAntiSpyware 2007\was7cw.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  10. gerard.keenaghan

    gerard.keenaghan Private E-2

    Hi TW
    here is the update from actions carried out Text in blue are responses

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!). Did not receive this either time

    If Killbox does not reboot just reboot your PC yourself. Rebooted itself

    Killbox asked me individualy to backup & delete files listed below (I clicked yes)
    C:\Program Files\Video Access ActiveX Object\isamntr.exe
    C:\Program Files\Video Access ActiveX Object\pmsnrr.exe
    C:\Program Files\Video Access ActiveX Object\isamini.exe
    C:\Program Files\Video Access ActiveX Object\pmmnt.exe

    C:\Program Files\Common Files\WinAntiSpyware 2007\was7cw.exe

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!). Did not receive this message

    If Killbox does not reboot just reboot your PC yourself. Killbox did not reboot me

    Attached are logs - Runkeys opens a blank notepad
    Runkeys does not upload this time either
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and run WinAntispw removal

    Attach the log and also the other three (GetRun/Shownew/HJT ...did you rename the log?).
     
  12. gerard.keenaghan

    gerard.keenaghan Private E-2

    SpyHunter log attached (did not "Start Remove" - Should I have?)
    runtext will still not attach.
    I didn't intentionally change names.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, please do.
     
  14. gerard.keenaghan

    gerard.keenaghan Private E-2

    Done,

    Please find attached new logs

    runkeys still failed to upload
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and run the below program and see if it can uninstall the below.
    Your Uninstaller!.


    C:\Program Files\Video Access ActiveX Object
    C:\Program Files\Common Files\WinAntiSpyware 2007 Free
    C:\Program Files\Common Files\WinAntiSpyware 2007

    Manually delete these:
    C:\Hol1495900.exe
    C:\hol442456.exe

    Was there no resultant log after running SpyHunter?

    Attach a new ShowNew and HJT.
     
  16. gerard.keenaghan

    gerard.keenaghan Private E-2

    Your Installer cannot find any of 3 listed to carry out uninstall.

    have manually deleted items as requested.

    no spyhunter log except one previously attached.
    (Spyhunter opens immediatly on log on - Should this be?)

    Please find attached HJT & Shownet logs
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please print these instructions out, or write them down, as you can't read them during the fix.

    Download and Install RogueRemover Free http://www.majorgeeks.com/RogueRemover_d5360.html

    Run RogueRemover and select Scan and the program will walk you through the remaining steps.

    Remove:
    Video Access ActiveX Object
    WinAntispyware
    And any others it may find.

    Step 1:
    Download SmitfraudFix (c) S!Ri http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Extract the content (a folder named SmitfraudFix) to your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
    Please copy/paste the content of that report into your next reply.

    Do NOT run any other option other than 1

    Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
    http://www.beyondlogic.org/consultin...rocessutil.htm

    Step 2:
    Next, reboot your computer in Safe Mode by doing the following:
    1) Restart your computer
    2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    3) Instead of Windows loading as normal, a menu should appear
    4) Select the first option, to run Windows in Safe Mode
    5) Choose your usual account.
    Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
    Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

    You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

    The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
    A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
    The report can also be found at the root of the system drive, usually at C:\rapport.txt

    Warning: running option #2 on a non infected computer will remove your Desktop background.

    Reboot

    Follow the directions for Virtumonde aka Trojan Vundo Removal procedure.

    Post the Following Logs:
    1. rapport.txt from SmitFraudFix
    2. ShowNew
    3. GetRunKey
    4. HijackThis
     
  18. gerard.keenaghan

    gerard.keenaghan Private E-2

    Step 1:

    Please copy/paste the content of that report into your next reply.
    I saved this as smitfraud.log but cannot find it now

    Step 2:
    please copy/paste the content of that report into your next reply.
    The report can also be found at the root of the system drive, usually at C:\rapport.txt

    SmitFraudFix v2.144

    Scan done at 10:41:53.92, 26/02/2007
    Run from C:\Documents and Settings\Gerard\Desktop\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\Program Files\Video Access ActiveX Object\ Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End


    Warning: running option #2 on a non infected computer will remove your Desktop background. This DID happen

    Reboot

    Please find attached logs, getrunkey will still not upload
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video Access ActiveX Object\isadd.dll

    After clicking Fix, exit HJT.

    Tell me how things are running.
     
  20. gerard.keenaghan

    gerard.keenaghan Private E-2

    Did this but only
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    present to fix!!!

    System is better but I think a little slow.

    When I open Internet explorer now however the about:blank home page comes up. This was diverting/coming up as asecuritystuff.com until now.

    popups appear to have stopped.

    Are we there
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run CCleaner ...the cleaner and the issues (make the backup when prompted) ...this will fix bad registry items.

    To Reset Web Settings:

    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    If you still suspect problems, please attach new logs for:
    GetRun
    ShowNew
    HJT

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  22. gerard.keenaghan

    gerard.keenaghan Private E-2

    Thanks TW,
    Things seem to be running smoothly now. Just a couple of quick queries:
    Should I download the "updates that are ready for your computer" from the popup balloon?
    SpyHunter starts up upon booting should I allow this to continue?
    If I am still logged in at 2am counterspy runs, should I allow this to continue?
    I ofter get and adobe flash player install updat popup when I access certain info on the web, Should I download this?

    Thanks for all you help again,
    Gerard.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I right click the icon and choose custom install so I can review which updates are trying to be installed, and usually only allow the "security" updates.

    SpyHunter is shareware ...limited trial period. Unless you wish to purchase (or have - in which case yes let it run at start up) then I would use one of our freeware programs.

    This also is trial ware and we ask you to uninstall after the cleaning process (again, unless you have purchased the software ...then let it run).

    www.adobe.com ....download and install it directly from there.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds