HELP! Url.adtrgt getting me ticked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Christopher_78, Feb 7, 2008.

  1. Christopher_78

    Christopher_78 Private E-2

    Okay... this has been an on going issue... I have corrected much of the problems however this one has got me ticked...

    I am only receiving pop ups on IE; does not seem to be affecting Firefox. The only solution that I have found is to kill IE within my ZoneAlarm. However, if I am needing to use IE to view a site the moment I enable IE the pop ups start coming.

    I also notice in my Zone Alarm program there are sites that show up under the privacy heading... This area allows me to set my privacy setting for each particular site that I may have visited. Problem is I do not recognize these sites.

    I issue seems to be coming from url.adtrgt, but again it could deeper than that. Any help regarding these pop ups and any overall Malware would be appreciated. I noticed on other threads hijackthis logs where attached and/ or posted. I went ahead and added mine; however I can run and/or download any other information that is needed.
     
    Last edited by a moderator: Feb 7, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Christopher_78

    Christopher_78 Private E-2

    Okay I have ran through all of the steps. Below are the attached files that where requested.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and save to RenV.exe from following link to Desktop (must be on the Desktop).
    * Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).

    Code:
    C:\Program Files\Analog Devices\Core\smax4pnp .exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
    C:\Program Files\Intel\Intel Application Accelerator\iaanotif .exe
    C:\Program Files\Messenger\msmsgs .exe
    C:\WINDOWS\SYSTEM32\dla\tfswctrl .exe
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  5. Christopher_78

    Christopher_78 Private E-2

    Thank you very much for all of your help so far... After following all of the directions my attachments have been added. I also want to let you know that I own a company that deals with independent retailers nationwide, along with some major national drop shipping companies. All of which use and have direct access to the internet and also may often find themselves in situations such as myself. I have and will continue to direct them to majorgeeks.com for help and preventive care. I also make them full aware that a small donation is welcomed to show just how much we appreciate your help.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can tell me what these are:
    C:\Program Files\Zzaph
    C:\zzaph

    You can run avenger and have it remove:
    Otherwise you look good ...are you having any other problems?
     
  7. Christopher_78

    Christopher_78 Private E-2

    As far as the ZZaph files go; I have no idea what they are or where they would have come from...

    After changing my setting in Zone Alarm to allow IE full access I have not had any other issues.

    Now, I do quite a bit of downloading on the internet and also recieve a vast amount of attachments due to my company. Is there anything you can recommend that I do or program that I need to run on a regular schedule to help me prevent issues like this. I do run Zone Alarm virus scan once a week and a spyware scan daily. I also have all of my browsers set to delete cookies and also dump my cache, cookie, history, and temp internet files at least 4 times a day.

    Thank you for all of your help...
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just being vigilant and careful about the attachments and have an active anti-virus not a passive one.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    *How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds