I am still getting popups and other junk

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JoeJoe515, Oct 5, 2006.

  1. JoeJoe515

    JoeJoe515 Private E-2

    I followed the instructions on Read and Run me first thread, but i am still getting a popup for the WinAntiVirus 2006 software. There are no longer annoying alerts in the bottom rigth corner of my screen telling me i have spyware, but there is one that when first starting the computer says my Norton Anitvirus is off and that my firewall is down. Before this happened, my computer never gave this alert and both things were up and running when the computer started. Also the time that it takes to open things has become considerably longer and makes me think that not everything was cleaned up.

    The logs from the bitdefender and the panda activescan are attatched. The Runkeys log has also been attached but since there is a 3 file limit to attachments, the last log will be in another post.

    Also, spybot SD has constantly been finding win antivirus 2006 and C Dilla on my computer, i know that i never had anything named C Dilla on my computer before hand.
     

    Attached Files:

  2. JoeJoe515

    JoeJoe515 Private E-2

    Here are the rest of the logs including hijackthis.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You appear to have quite a few problems to fix. SmitFraud, Virtumode, Winlogonhook and more. Let's get started with the Smitfraud issues. Then we will move onto the other problems after this (so don't expect everything to be perfect until we get thru to the other procedures later ;) )

    I'm going to post two messages! This is the first! Complete this procedure completely including attaching the requested log before doing the second procedure.


    First install the current version of Sun Java from: Sun Java Runtime Environment

    Now Uninstall the below old software (some of these should have been uninstalled in step 0 of the READ ME):
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    Safety Bar
    Screensavers Installer
    Viewpoint Manager (Remove Only)
    Viewpoint Toolbar V35 (Remove Only)

    If any of these do not uninstall, just continue on with the below and tell me about it later.


    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is my second message. Make sure you have follow the first procedure before doing the below.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.

    Now also attach new logs from ShowNew and HJT!
     
  5. JoeJoe515

    JoeJoe515 Private E-2

    Ok here is the Rapport.txt file, i have already posted the HJT and ShowNew logs in this thread and it will not let me post them again. If i need to post them agian be sure to mention in your reply what the steps are to either erase the old ones or to get around it.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to create NEW logs on your PC from today. Then you should be able to attach them.
     
  7. JoeJoe515

    JoeJoe515 Private E-2

    I also realized recently that I am still getting pop ups for the WinAntiVirus 2006 website. Also occasionally i get pop ups for SystemDoctor 2006. I know that the removal process isn't done yet, but i just wanted to be sure we covered whatever causes those to show up.
     
  8. JoeJoe515

    JoeJoe515 Private E-2

    Ok i have used HJT and ShowNew and here are the new logs.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is part of what we are still working on and hopefully the below finishes the fix.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ddccbca.dll once and then click the kill button. After you have killed all of the ddccbca.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    wvwwx.dll

    Next double click on explorer.exe and again click once on each instance of ddccbca.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    wvwwx.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\bfpcviip.dll
    O2 - BHO: (no name) - {4AFF07E7-EDCF-F41A-3E4C-018F9F16B982} - C:\WINDOWS\system32\sgoinrl.dll
    O2 - BHO: (no name) - {588EE89F-6790-41CC-BED3-E1E9E03642E7} - C:\WINDOWS\system32\wvwwx.dll
    O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll (file missing)
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll (file missing)
    O2 - BHO: (no name) - {D3B3C51E-8D11-4667-85B9-0930F519BED7} - C:\WINDOWS\system32\ddccbca.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll (file missing)
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
    O20 - Winlogon Notify: ddccbca - C:\WINDOWS\SYSTEM32\ddccbca.dll
    O20 - Winlogon Notify: winlkv32 - winlkv32.dll (file missing)
    O20 - Winlogon Notify: wvwwx - C:\WINDOWS\system32\wvwwx.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    If you get an error message while doing the above command prompt step, just ignore it and continue!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\{F8EF2BA3-0A60-1033-0519-030429200001}\Update.exe
    C:\WINDOWS\mickey32.dll
    C:\WINDOWS\system32\bfpcviip.dll
    C:\WINDOWS\system32\cortrpif.dll
    C:\WINDOWS\system32\ddccbca.dll
    C:\WINDOWS\system32\gdukjmg.dll
    C:\WINDOWS\system32\iklqtkdt.dll
    C:\WINDOWS\system32\jkhetnuo.dll
    C:\WINDOWS\system32\movtwdbg.dll
    C:\WINDOWS\system32\qtvkqcis.dll
    C:\WINDOWS\system32\ryvnnifn.exe
    C:\WINDOWS\system32\sgoinrl.dll
    C:\WINDOWS\system32\wvwwx.dll
    C:\WINDOWS\system32\xwwvw.tmp
    C:\WINDOWS\system32\xwwvw.ini
    C:\WINDOWS\system32\xwwvw.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folders and delete if found:
    C:\Program Files\Common Files\{F8EF2BA3-0A60-1033-0519-030429200001}
    C:\Program Files\Safety Bar
    C:\Program Files\Viewpoint

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\Joann\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. JoeJoe515

    JoeJoe515 Private E-2

    The steps went smoothly, and nothing different happened. Here are the logs that you asked for and I will post again if the pop ups come back.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your HJT log you did not run the steps I gave you in message # 9. You must make sure that no browsers are open and you must all make sure you remember to click the Fix checked button in HJT. Please repeat the previous steps and make sure you fix everything. Post new logs afterwards.
     
  12. JoeJoe515

    JoeJoe515 Private E-2

    Here are all three logs
    I did all the steps over again and i got this message when using Killbox

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    When i first scanned with HJT in response to the steps in post #9, I found all the things that you listed, I checked them, and i closed all my browsers, and then i told it to fix the checked items.
    After i had posted the wrong log, i scanned with HJT again and i found 2 things that were still there: one was the common files and i dont remember the other one. i selected both and fixed them.
    When i scanned with HJT on the 17th, all the things that you listed were not on the scan list this time.

    While looking through my program files on the 17th, i found a viewpoint file and i deleted it.

    I have not recieved any pop ups since my last post, but the computer is a little slow on startups and when i am playing large games.

    If there is something still wrong with the logs, i will need more help because as far as i know, i have followed the steps twice now.
     

    Attached Files:

  13. JoeJoe515

    JoeJoe515 Private E-2

    I was looking at my add or remove programs list and i found Viewpoint Media Player. I deleted it because of the previous things with viewpoint. It would be good to know if this means that i still have malware on my computer or not.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! All of your malware problems are gone now after repeating those previous steps.

    Any problems you are having now are not due to malware but are due to things that you are running. Do you really need AOL toolbar? You don't need to load QuickTime, RealPlayer, or Microsoft Office Startup Assistant when you startup your PC. You could just use HJT to fix the below lines to stop them from loading:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE


    Also I see a service from Symantec running (see the O23 line in your HJT log). Exactly what is it from Symantec that you still use? I see this Norton WMI Update in your log from ShowNew. Is there anything else you use from Symantec. That would require that service which is normally part of their antivirus application.

    Do you know what Software Suite is that appears in your Uninstall Programs list?
     
    Last edited: Oct 21, 2006
  15. JoeJoe515

    JoeJoe515 Private E-2

    I used to have a Norton antivirus installed on my computer but since my subscription ended, my friend suggested that i download Avast.

    I do know what software suite is on my computer and i am aware that it is in the add and remove programs list. I dont know if it was put there when i reformatted my computer but when i searched my computer for the folder it brought up some simple software programs from a company called Arcsoft and it basically just contained a picture editor, a greeting card creator and some other thing that i didn't use. I have used the picture editor once or twice and it works normally. I dont use the greeting card creator.
     
    Last edited: Oct 19, 2006
  16. JoeJoe515

    JoeJoe515 Private E-2

    Should i just delete the AOL toolbar things with HJT since i only use Mozilla Firefox. I have IE available in case something is wrong with mozilla or if i need to use IE for something like a scan.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The proper thing to do is to uninstall software when possible. Deleting files or fixing with HJT should never be the first step because that could make it impossible to uninstall the application at a later point.

    Do you use the AOL software you have installed? I see the below:
    AIM Ad Hack"
    AOL Coach Version 1.0(Build:20020929.1)
    AOL Instant Messenger
    AOL Uninstaller (Choose which Products to Remove)


    You did not comment on Yahoo Toolbar! Do you us it? It does have an uninstall shown in Add/Remove Programs.

    You should also uninstall the Norton WMI Update software I mentioned.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds