A lot of pop ups I need help =(

Discussion in 'Malware Help (A Specialist Will Reply)' started by jamespt89, Jun 30, 2008.

  1. jamespt89

    jamespt89 Private E-2

    Hi Guys, Ive ran through all your reaD and run me first tutorials and ran everything yet still the pop ups keep on coming. I have found various files tha have been obvious viruses Using other programs such as ADAware and such, and those are not able to be deleted they are all genuine Trojan viruses to my knowledge nothing out of the ordinary, I have a feeling that they are all lodged into my registry But i can not tell you more, as my computer expertise has sufferly demised as i lost interest in the subject due to lack of time and such lol.

    Well the following are my logs.
     

    Attached Files:

  2. jamespt89

    jamespt89 Private E-2

    Here are the rest
     
  3. jamespt89

    jamespt89 Private E-2

    Eh last one: Listen I really appreciate the help I recieve, Like seriously having people take time out of their life to help people they don't even know means a hell of a lot to me. And it is a quality that i respect with people. When people share their skills amongst others and to help others I am completely taken aback and amazed. So yeah Take this as my complete Appreciation and Thanks.:)
     

    Attached Files:

  4. jamespt89

    jamespt89 Private E-2

    I am lacking on detail so Heres some more. As with most problems it seems to be internet based. Whenever I am using other programs whether its typing based or Video Game Based, or what have you Videos anything, My computer seems to Have a split second "alttab" if you understand what i mean, like it switches between prgrams if i have something ful screen it will minimize it as if something else is about to open up. The internet is drained. Mozilla Firefox Has seized to work entirely and IE is my only web browsing utility, actualy its so bad that I cant use the internet what so ever for anything, I am using my laptop to type this message, I had to upload all the logs onto a memory stick and upload them from here, Everything seems to get progressively worse when it comes to the internet. All the pop ups seem to show up from Internet Explorer, even though IE isnt my default Browser.

    Im not to sure if this adds more detail into the situation. But it has been happening for about 2 - 3 weeks. And recently it has been getting Much Much Worse.
    Once again thanks a lot!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I suggest that you get your Desktop clutter cleaned up ASAP. A cluttered Desktop makes a great place for malware to hide.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 5
    Java(TM) 6 Update 3
    Spyware Striker <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: {c8c9bfab-5d1c-4bf8-11c4-58bfb51ef990} - {099fe15b-fb85-4c11-8fb4-c1d5bafb9c8c} - C:\WINDOWS\system32\trqnrgps.dll (file missing)
    O2 - BHO: (no name) - {A24041AA-45B4-4E6B-817C-9A139C4E7866} - C:\WINDOWS\system32\yaywXPHy.dll (file missing)
    O2 - BHO: (no name) - {BAFFE38C-C38F-421D-A619-854106535705} - C:\WINDOWS\system32\jkkHBQih.dll
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [9400bd3e] rundll32.exe "C:\WINDOWS\system32\ddpppipf.dll",b
    O4 - HKLM\..\Run: [BM97338ea2] Rundll32.exe "C:\WINDOWS\system32\wvcpwjjs.dll",s
    O4 - HKCU\..\Run: [Bfb] C:\WINDOWS\system32\?icrosoft.NET\?canregw.exe
    O15 - Trusted Zone: http://*.trymedia.com (HKLM)
    O20 - Winlogon Notify: hggghef - hggghef.dll (file missing)
    O20 - Winlogon Notify: jkkHBQih - C:\WINDOWS\SYSTEM32\jkkHBQih.dll
    O20 - Winlogon Notify: zhwfnpac - zhwfnpac.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. jamespt89

    jamespt89 Private E-2

    O2 - BHO: (no name) - {BAFFE38C-C38F-421D-A619-854106535705} - C:\WINDOWS\system32\jkkHBQih.dll


    O4 - HKLM\..\Run: [9400bd3e] rundll32.exe "C:\WINDOWS\system32\ddpppipf.dll",b
    O4 - HKLM\..\Run: [BM97338ea2] Rundll32.exe "C:\WINDOWS\system32\wvcpwjjs.dll",s


    As far as these 3 Checks They don't exist in the Hijack This Log. Is that bad?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it just means the at some point you rebooted after attaching your previous logs and they may have been cleaned up by some remaining processes from the previous scans. Just continue on!
     
  8. jamespt89

    jamespt89 Private E-2

    Ok! Im up to the combofix part its being run as we speak.!
     
  9. jamespt89

    jamespt89 Private E-2

    Ok, Well as far as everything you instructed me to do, it has been done. The registry add on thing Was succesful. Except as far as INternet and such goes, Nothing is loading. I don't seem to have any pop up issues anymore but For example homepages will load both on Mozila and IE, Ill get onto Google / Gmail facebook etc. just fine, but as soon as i type something into the search bar, or try and log in, the loading bar goes but the page never loads. I am running that pc off a wireless connection, and I don't see the problem to be internet related, as This computer is also running via WiFi, and running just fine. The connection is very Good on both computers as the modem is no more than 3 feet away.

    Any ideas? I posted both logs. and ran / unninstalled everything i was supposed to.
     

    Attached Files:

  10. jamespt89

    jamespt89 Private E-2

    =( still getting pop ups Much much Less, but they are the same ones that i have been getting.
     
  11. jamespt89

    jamespt89 Private E-2

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the sticky threads. This cost you more than an additional days worth of waiting time. See this: Don't Bump! It Only Hurts You!!!


    Are you saying that your only remaining problem is that you cannot enter anything into the search box on Google? But general browsing to websites (even here at Major Geeks) works fine?
     
  13. jamespt89

    jamespt89 Private E-2

    No like websites in general. as my pop up problem has seemed to have vanished for the most part completely, Google only loads its home page, gmail only loads the home page and quickly for the most part, but as far as majorgeeks.com and lets say signing into gmail or searching something on google, it is still loading as i write this post (from another computer). The connection is fine. Yet nothing seems to be working. this might also help. I play Counterstrike, Idk if you are familiar with it, but its an online videogame, and that works fine no lag no ping jumps. Nothing The problem seems to be based off the way my computer is taking in websites. Any Ideas?

    Thanks
    And sorry for the bump
     
  14. jamespt89

    jamespt89 Private E-2

    Essentially Web Browsing is unable to be done on the computer But aside from that the internet is fine for everything else internet based minus the browsing. Which seems to be the most important lol
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What browser are you using?

    We have some more cleaning to do since you managed to pickup a bunch of new malware files. So let's see what happens after we get all of your malware removed.

    Is the below the startpage you configured?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://officialhomepage.org/home15.html


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: {d9433e60-4772-ae6b-8cd4-9036f92db991} - {199bd29f-6309-4dc8-b6ea-277406e3349d} - C:\WINDOWS\system32\oegdgy.dll
    O4 - HKLM\..\Run: [9400bd3e] rundll32.exe "C:\WINDOWS\system32\vjxsavtk.dll",b
    O4 - HKLM\..\Run: [BM97338ea2] Rundll32.exe "C:\WINDOWS\system32\cofhkmxw.dll",s
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now double click ofn the fixme.reg patch you saved to your desktop in the previous fix. Make sure you allow it to be added to your registry.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 3, 2008
  16. jamespt89

    jamespt89 Private E-2

     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you should also fi that line with the analyse.exe (HijackThis) program like in my last fix.


    This is just due to the items we were removing and those messages should not occur anymore after your next reboot.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds