pop up city

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jnicely79, Dec 2, 2007.

  1. Jnicely79

    Jnicely79 Private E-2

    Hello all, getting beat up wth pop-ups. SpyBot detected Virtumonde.rtk - Adrevolver - Virtumonde - and Smitfraud-C.Coreservice.
    I am not very computer oriented, and would appreciate any help you could give me. Below is my HJT log

    • Edit by bjgarrick: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Dec 2, 2007
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  3. Jnicely79

    Jnicely79 Private E-2

    Just finished following the read and run me. Virtumonde and Smitfraud have been eliminated, just ran spybot and came up with the following: Doubleclick, Hitbox, and MediaPlex. Not real sure where to turn from here...
    Any ideas?
     
  4. Jnicely79

    Jnicely79 Private E-2

    Also i just ran asquared and on the second scan it detected two trojan files?
    Hopefully its ok to attach these files now. AVG log was not available for some reason (I did install per proceedure). Not sure if it would be of any use to re-run? I will also attach my a-squared log as it is the only one to detect the trojans thus far. Any help is appreciated.
     

    Attached Files:

  5. Jnicely79

    Jnicely79 Private E-2

    Can anyone help me??
    asquared came up with virtumonde last night. Should I re-do the read and run me? can anyone help? Any help is greatly appreciated.
    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now Disable Spybot's TeaTimer as requested in the READ ME
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Now uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 4

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {45C5803C-4A8C-462D-B07B-0B20CE099641} - (no file)
    O2 - BHO: (no name) - {57C48F0F-D286-4DE2-860F-FC336604C3C0} - C:\Program Files\Movie Maker\mexokasocC:\WINDOWS\system32\i2\mper83122.exe.dll (file missing)
    O2 - BHO: (no name) - {DDF8EBEC-3F84-4560-87ED-D4F0F927158C} - (no file)
    O2 - BHO: (no name) - {E2F13973-8F19-474D-8C6A-F8FC81403C3E} - (no file)
    O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [70748412] rundll32.exe "C:\WINDOWS\system32\uvvthdxh.dll",b
    O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  7. Jnicely79

    Jnicely79 Private E-2

    ill try that now. Thank you very much, Ill let you know how it turns out
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It probably would be a good idea to uninstall AVG Anti-Spyware if it was installed during the READ ME. If you purchased it then you can leave it.
     
  9. Jnicely79

    Jnicely79 Private E-2

    So far so good. Havent really run my machine much yet though...
    Attached are my two logs. Thank you very much for all of your help, I truly appreciate it. I'll let you know how things work out. Thanks again.
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Go back to post 6 and run Avenger again, something did not go properly.

    Be sure you shutdown all antispy and antivirus programs before running Avenger. Once you complete this, attach the new log from Avenger with new logs from MGTools.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds