Cannot remove malware..excessive popups!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by romy, May 14, 2007.

  1. romy

    romy Private E-2

    ive tried the past "read me and run first "posts. and tried all those tests, but my problem stil persists.
    theres are so many popups.!

    i was wondering if i should do a system recovery.
    but ive done a lot of those in the past 2 months..
    like 3-4.
    so.
    any other possible ways?
    i dont wanna do "hi-jack this" unless i have to!
    thankss!

    reply.asap.
    dads getting mad at the pop ups :(
     
    Last edited: May 14, 2007
  2. romy

    romy Private E-2

    EDIT: Cannot remove malware..excessive popups!

    herES my hijack this log..

    does it help?
     

    Attached Files:

  3. romy

    romy Private E-2

    heres my SPYBOT report..
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Running the READ ME means that you have to follow ALL of the instructions. This includes installing and renaming HijackThis and attaching the 6 requested logs from the READ ME. HijackThis logs are the last thing we ask for.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. romy

    romy Private E-2

    heres my CounterSpy results
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not allow CounterSpy to fix what it found. There is no sense in running the scans unless you fix what they find. Run it again and Quarantine or Delete what it finds. Attach a NEW log.

    Then after you attach the 5 other requested logs, we can get started.
     
  7. romy

    romy Private E-2

    here are the other 2.. bdscan
    and the panda..
    also. the getrunkey...

    and yea i will run the counterspy scan again
    sorry!

    EDIT:
    THE newfiles.txt is in a new thread..as well as the counterspy.results.
    thanks
     

    Attached Files:

    Last edited: May 15, 2007
  8. romy

    romy Private E-2

    Romy's newfiles.txt

    i have to post a new thread..since im only allowed 3 attachments..
    this is my newfiles.txt
    and counterspy scan results..ill attach as soon as its done scanning.
    ty!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Romy's newfiles.txt

    No you do not need to start a new thread!!! You just need to add another message in the same thread! Please remember that.

    I'm merging this back to your original thread.

    You did not attach the new log from CounterSpy after fixing what it found!


    You also forgot to attach the last requested log which is HijackThis. Your original log was obtained before the other scans were run and may not be the same anymore. Please attach a new HJT log.

    You also need to do the below which was requested at the beginning of step 6 in the READ ME.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Romy's newfiles.txt

    I also noticed signs of a Deluxe Communications infection! Please run the below too:


    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  11. romy

    romy Private E-2

    counterspy wasnt finsih scanning so here it is

    sry
     

    Attached Files:

  12. romy

    romy Private E-2

    heres the hijack thiss
    and the combofix.txt
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still do not have HijackThis.exe renamed to analyse.exe as requested in the READ ME and as specified in message # 4. Please rename it now, but do not attach a new log yet!

    You will find that things will go a lot faster and smoother if you take care to follow instructions properly and completely the first time. By the time you reply to this message, we will be at 14 messages and this should not have taken more than 4 to be at this point.



    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\sys010746796011.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [sys010746796011] C:\WINDOWS\sys010746796011.exe

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\HP_Administrator\Application Data\Dxcknwrd.dll
    C:\WINDOWS\Downloaded Program Files\SysInfo.dll
    C:\WINDOWS\Downloaded Program Files\sysinfo.inf
    C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
    C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
    C:\WINDOWS\casinom.exe
    C:\WINDOWS\invupdi.exe
    C:\WINDOWS\sys010746796011.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  14. romy

    romy Private E-2

    im sorry for not following ur steps correctly the first time.
    i didnt find that process on my list..
    but i continued with ur other steps.

    here are the logs u requested!

    thanks so much
    :]


    also im not getting any popups..so far..
    i think its working!

    :]
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you receieve a the Pending Operations error message I mentioned when deleting files with Killbox! It did not delete them successfully. Did you use Delete on Reboot as requested?

    Boot into safe mode and run Windows Explorer (right click Start and select Explore). Then navigate to the below files and right click on them and delete them:
    C:\WINDOWS\casinom.exe
    C:\WINDOWS\invupdi.exe
    C:\WINDOWS\sys010746796011.exe

    Then reboot in normal mode.

    It appears that you did not install the new Sun Java version as I requested in message # 9.

    Install the current version of Sun Java now from: Sun Java Runtime Environment


    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Now get a log from ShowNew and attach it.
     
  16. romy

    romy Private E-2

    no i didnt receive the pending operations error mesage.
    and yes i checked marked "delete on reboot"

    and yes i did download the sunjava u requested but i will re-download itt

    and i will post the ShowNew
    in just a few minutes
     

    Attached Files:

    Last edited: May 16, 2007
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Downloading and installing are two different operations. If you downloaded it already, you need to install it. Based on this last ShowNew log, you still have not installed it.

    Your malwar files are gone now. After getting Sun Java reinstalled. Move on to the final steps below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. romy

    romy Private E-2

    hey
    thank u so much for the helpp
    :]


    i performed all the steps u told me.
    but some of the folders u asked me to delete were like already deleted..
    so i didnt find emm
    but yea thanks
    !
     
  19. romy

    romy Private E-2

    when i run spybot search and destroy
    im still getting that i have the issues (tegasauras..and such)

    i press "fix selected issues" but im still getting them..
    and the popups
    i get one every like half hour or so.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach a log from Spybot!

    What are the popups for? Is there a URL indicated? Do they occur when no browsers are open?

    Attach a new HJT log?
     
  21. romy

    romy Private E-2

    yea now, there arent ne popups.
    but can u make sure for me?
    3 problems are still occuring when i run spybot search and destroy

    including tagasauras..
    here are the logs u requested
     

    Attached Files:

  22. romy

    romy Private E-2

    here are the logs u requested
    tagasauras still apears
    but now no popups
    can u make sure?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spybot only found cookies which are not problems! You will learn this after you complete the below steps and work thru the How to protect yourself link.


    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  24. romy

    romy Private E-2

    o ok
    yea there arent ne popups ..
    thanks a lot! i followed ur procedures..
    i have the avast antivirus , ad-adware, spybot seach and destroy,ccleaner, a squared free, and thats it i believe
    ahah

    and also can i delete hijack this?
    yea?
    thanks for ur help!
    i appreciate it
    :]
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    You need more and one of them needs to be a realtime malware blocking tool. So do the below:

    • first install SpyWare Blaster which use no resource and provides some nice protection. Make sure you update it and enable all protection. This tool only needs to run when you get updates for it periodically.
    • Now install one of the below two programs to give you a realtime blocking tool:
    Yes if you would like too. It is not necessary and if you do get infected again, you will need to go thru the download and installation procedures again. You can uninstall HJT from its Misc Tools menu selection seen when you boot it up. Then after uninstalling it, delete the files and folder for it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds