Won't stop telling me I won a 1000 Walmart gift card!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by winepooh, Sep 9, 2008.

  1. winepooh

    winepooh Private E-2

    Spyware invaded my computer a few weeks ago and has gotten worse. The specific problems I am having is pop ups and audio ads randomly opening. The Walmart and Nintendo Wii audio ads are constant. Other ads will pop up and disappear leaving the computer very slow to the point it has to be restarted. My browsers are being disabled as well.

    I mad the mistake of downloading programs that would rid me of the spyware, but they were ineffective and seem to have caused more problems. I installed a purchased copy of Norton 2008 Internet Security, but it did not remove anything.

    Here are my logs. Thanks so much.
     

    Attached Files:

  2. winepooh

    winepooh Private E-2

    4th log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already had McAfee installed!!! And your logs also show signs of Avast being installed. You need to uninstall all but one of these immediately. Then tell me which one you decided to keep.

    After doing the above, continue with the below. DO NOT DO THE BELOW until all but one antivirus has been uninstalled.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_15\bin\jusched.exe"

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). MAKE SURE you let GetLogs finish running because your last logs may have had incorrect info due to not letting MGtools finish. I saw some files with a 9/1 date and others with a 9/3 date.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. winepooh

    winepooh Private E-2

    I now only have Nortons. I had an outdated McAfee scan, which I have just deleted. As far as the Avast, I tried deleting several times before creating the logs, but it wouldn't let me. I had to manually remove most of it, but I don't know where the small remnants are still coming from.

    I had some problems with the MGTools log, mid way through it said there was an error.

    Thanks.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Several error messages were explained & fixes were supplied in the Using MGtools link. Depending on which error, it may have run anyway.
     
  6. winepooh

    winepooh Private E-2

    I was able to fix the MGlog. So it should all be there now. I think the problem was tied to Avast.

    So far, I haven't had any pop ups or invisible audio.

    Thanks again!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs shows you did not do the below:
    Please do this now.

    Also you did not create the CFScript.txt file properly. You created. CFScript.txt.lnk. Please make sure you follow instructions properly as it can often be the difference between success and failure. ;)

    Also you did not get Avast uninstalled completely. More than likely this is due to having to many antivirus programs installed and interferring with each other. We will fix this in the below.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_15

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (file missing)
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe (file missing)
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now doubleclick the fixme.reg file saved to your desktop in the previous fix and allow it to be added to your registry.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 13, 2008
  8. winepooh

    winepooh Private E-2

    Here are the logs. They *should" be right this time, at least I hope. :)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but no. Two things seem to be wrong.

    1. it does not look like ComboFix ran properly since the drivers were not removed. Did you create the CFScript.txt file properly with only the information in the quote box in it and not anything outside of the quote box. Did you run into any problems when doing this? Did Symantec popup any warnings?
    2. You did not allow GetLogs.bat to finish running. You must have closed the command prompt window before it was finished. Or again, did Symantec get in the way?
    Try the full fix again and make note of any issues that you have. Try to shutdown as much of Symantec as you can before running the fix.
     
  10. winepooh

    winepooh Private E-2

    I am so sorry, I don't know why it isn't working. I let the the programs run and there were no error messages. Everything was copied correctly. When I drag the CFScript.txt onto the combofix.exe the bar appears and it opens, asks if I want an updated version (no), I click yes to the agreement and then it scans and produces a log.

    The only thing I noticed out of the ordinary is that right after the scan, aol popped up saying it blocked BiFrost. I think it happened last time as well.

    I ran combofix twice, unfortunately I am not sure it worked any better than the last time. :(

    Thanks.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it did not and neither did the GetLogs.bat file run properly. It still is not running all the way thru to the end. Do not let any programs block anything including AOL blocking BiFrost which was a false detection.

    However let's do some different steps.

    First delete the current C:\MGlogs.zip file.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Watch for any error messages or any popup warnings from your protection software. If you get any popup, you need to shutdown that software and run GetLogs.bat again. Make sure you DO NOT close the command prompt window that opens until the scans finish. You can see what this looks like in the below link (see the thumbnail about half way down the page ):

    Using MGtools


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. winepooh

    winepooh Private E-2

    I'm not jinxing myself by saying it worked this time. ;)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this time it worked. :) Your logs are clean, but I do suggest that you delete the below 3 left over files from Avast.
    Code:
    C:\WINDOWS\system32\drivers\
    aswmon2.sys   Jul 19 2008       94416  "aswmon2.sys"
    aswrdr.sys    Jul 19 2008       23152  "aswRdr.sys"
    aswtdi.sys    Jul 19 2008       42912  "aswTdi.sys"
    
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. winepooh

    winepooh Private E-2

    I deleted the remaining Avast files and it looks like I am all done! I am so grateful, thank you so much:)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds