"Advanced Card Verification" pop up

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ekalbs4, Oct 11, 2008.

  1. ekalbs4

    ekalbs4 Private E-2

    I came to the malware removal forum because I've had a pop up window titled "Advanced Card Verification" showing up whenever I make online credit card purchases or schedule a credit card payment using my banks online bill pay service.

    I've only seen this pop up window with a Mastercard logo, however, my wife tells me she has seen the same pop up with a Visa logo when she made an online purchase. The pop up is a form to be filled in and it already has my credit card number filled in and empty fields for "Expiration date", "CCV2" and "ATM PIN". There is also a SUBMIT button. Neither my wife nor I have ever completed the form. We just close the window using the red X in the corner. I've probably had this for at least 2-3 months. Until recently making some online purchases, I'd only seen it a few times when making my monthly credit card payment. The recent online purchases made me realize this is a recurring problem that I need to take care of.

    I completed all of "READ & RUN ME FIRST" steps. As a test, I scheduled a credit card payment using my online bill payment service and proved that the pop up is still on my computer.

    While working to complete the read & run me first steps and to make this post, I have concluded two additional problems exist with my computer:

    1. Most importantly, I cannot seem to upload files. Therefore I'm not able to attach my log files at this time. I experienced a similar problem recently when I was working to exchange my Samsung refrigerator. They asked me to upload a copy of my receipt and it continually crashed IE when I tried. I was able to complete the upload from my work computer without any trouble, but that will not be an option for these files.

    2. Second, all of the surfing required to complete the read & run me first served to remind me that I've been having problems with IE v7 crashing periodically while surfing. In general, the crashes have been few and far between and I've never felt compelled to identify the root cause. However, it seems that perhaps it has been more prevelent in the last couple of weeks and slowed me down a couple of times while trying to complete the read me stuff. At this time, my priority is taking care of the credit card pop up, but I just wanted you to have all of the facts.

    Please let me know what my next step should be.

    Thanks!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have another browser installed such as FIreFox?

    Can you Attach the files using another browser?

    Many sites are now doing the advanced credit card verification....it stores a password for future purchases and so is meant to protect you in case of theft. You do not have to participate.
     
  3. ekalbs4

    ekalbs4 Private E-2

    I've never used Firefox. I downloaded Firefox from your website and the file upload worked great. Thanks.

    Your comments made me think that perhaps you do not consider this issue to be malware. I hope that is the case, but my research on the internet led me to believe that I'm dealing with malware. I saw similar issues on this site and other removal forums, but I would not be capable of attempting to do the fix myself by reading those posts.

    Here is one link (not a removal forum) that I found with some basic info,
    http://juleslife.wordpress.com/2008/07/12/beware-of-advanced-card-verification-popup-window/

    I've attached MGlogs.zip and a picture of the pop up that I'm talking about. I did an Alt,Printscreen and then pasted to Word so I could block out my credit card number before taking a picture with my camera. I'll attach the other three logs in another reply.
     

    Attached Files:

  4. ekalbs4

    ekalbs4 Private E-2

    Here are the additional log files.

    Thanks.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you run Spybot S&D? Please attach that log.....then go to Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  6. ekalbs4

    ekalbs4 Private E-2

    Spybot log file attached. I hope this is the right file. There were no instructions in the READ & RUN ME FIRST guide for retrieving and attaching the Spybot file.

    I'll work on the Bitscan instructions next.

    Thanks.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try this:

    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.
    Now Reboot and use windows explorer to find and delete:
    Code:
    C:\WINDOWS\Temp\"
    bca4e2da.$$$  Oct  9 2008       46910  "bca4e2da.$$$"
    fa56d7ec.$$$
    
    
    C:\Documents and Settings\Angie & Blake\Local Settings\temp\"
    cf16994.exe   Oct 11 2008      389120  "CF16994.exe"
    cf19796.exe   Oct 11 2008      389120  "CF19796.exe"
    MSOHTML       Oct 11 2008              "msohtml"
    MSOHTML1      Oct 11 2008              "msohtml1"
    
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from GMER.
     
  8. ekalbs4

    ekalbs4 Private E-2

    I completed the Bitscan. I see it found some stuff. HTML Log is attached as zip.

    I ran mbr.exe. Log is attached. Then I rebooted.

    I was able to delete (send to recycle bin for now) the four files,

    C:\Documents and Settings\Angie & Blake\Local Settings\temp\"
    cf16994.exe Oct 11 2008 389120 "CF16994.exe"
    cf19796.exe Oct 11 2008 389120 "CF19796.exe"
    MSOHTML Oct 11 2008 "msohtml"
    MSOHTML1 Oct 11 2008 "msohtml1"

    I was not able to delete the two files,
    C:\WINDOWS\Temp\"
    bca4e2da.$$$ Oct 9 2008 46910 "bca4e2da.$$$"
    fa56d7ec.$$$

    When trying to delete these two files I would get a message similar to the following:
    "Error Deleting File or Folder"
    "Cannot delete bca4e2da: It is being used by another person or program. Close any programs that might be using the file and try again."

    I ran GetLogs.bat and attached MGlogs.zip.

    Thanks.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now delete the current mbr.log file and then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
         [B]"%userprofile%\desktop\mbr.exe" -f[/B] 
    
    
    Now double click on the mbr.exe file and attach the new mbr.log

    Then reboot and see if the below files still exist. If they do, then see if you can delete them.

    Code:
    C:\WINDOWS\Temp\"
    bca4e2da.$$$  Oct  9 2008       46910  "bca4e2da.$$$"
    
    fa56d7ec.$$$
    
    Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file
     
    Last edited: Oct 13, 2008
  10. ekalbs4

    ekalbs4 Private E-2

    Ran Start > Run with the code provided.
    Ran mbr.exe
    Rebooted
    Successfully deleted the two files (sent to recycle bin)
    Ran GetLogs.bat

    New mbr.log and MGlogs.zip files attached.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Another one popped up that I was expecting:
    C:\WINDOWS\Temp\ed47fa.$

    Can you delete it also?
     
  12. ekalbs4

    ekalbs4 Private E-2

    Yes,
    I was able to delete the file, C:\WINDOWS\Temp\ed47fa.$
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet.....are you still having issues?

    In the meantime, we can start the cleanup process from running the scans:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then:

     
  14. ekalbs4

    ekalbs4 Private E-2

    My problem appears to be fixed! No more pop up asking for credit card data. I completed the cleanup process and toggled system restore.

    Wow, what a great service you and MajorGeeks are providing! Thank you so much for your help. I really appreciated the READ & RUN ME FIRST guide. I've attached some notes about one area that tripped me up while following the guide.

    I'll surely be back to MajorGeeks for any future information, hopefully, not the malware removal forum though.

    Thanks again. Keep up the fight!
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know....and you are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds