Advanced Credit Card Verification pop-up

Discussion in 'Malware Help (A Specialist Will Reply)' started by GaryGnu74, Apr 17, 2009.

  1. GaryGnu74

    GaryGnu74 Private E-2

    Hi Guys -

    Just yesterday I started getting the Advanced Credit Card Verification pop-up. Discovered this when I was trying to make an online purchase. Also, since then, I've gotten the blue error screen upon start-up several times.

    Attached are the requested logs.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are way way out of date with your version of Malwarebytes!!!!

    Please run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Also your MGtools log is very incomplete. Did you allow it to finish running? We will try to run a new scan at the end of the below fix.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. GaryGnu74

    GaryGnu74 Private E-2

    Thank you for your help!

    I updated my Malwarebytes and I have attached the latest log. Also attached are my latest combofix log and MGlogs zip.

    My OS isn't crashing on me anymore, so definite improvement there. As far as the pop-ups, they only occured when I was about to finalize an online purchase, so I haven't been doing any online shopping since.

    Again, thank you very much for you help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We have some more to do.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. GaryGnu74

    GaryGnu74 Private E-2

    Went ahead and removed Windows Messenger and uninstalled old versions of Java.

    New ComboFix log and MGlogs zip attached.

    Still experiencing Advanced Card Verification pop-up. Just popped up again at this site's store - http://www.darkmaze.com/. Has also popped up at sites such as Amazon.

    Pop-up occurs right when you are ready to finalize online purchase. A window opens that says Advanced Card Verification and is marked with a Mastercard logo. The window has several fields including name and credit card number which have already been populated by going through the site's legitimate shopping cart. Two empty fields remain, however, and they are asking users to enter their CCV number and PIN number. This window can be ignored by simply closing it.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume the browser you are using is Internet Explorer? Please download and install this Mozilla FireFox Try the same thing and tell me if it happens.

    Have you tried the same thing using a different PC?


    There do seem to be a few things that did not get deleted with the last ComboFix run. The below two files did not get deleted:

    c:\windows\Temp\rg4sfay
    c:\windows\Temp\ydf8dk

    Can you delete them yourself? I'm thinking you may have a bootsector infection which these may relate to.

    Also do you know what the below two folders are for?
    Code:
    2009-04-24 04:51 . 2009-04-26 18:02 -------- d-----w C:\TPB_01
    2009-04-04 19:08 . 2009-04-04 19:08 -------- d-sh--w c:\windows\ftpcache
    

    Now let's check for a Master Boot Record problem as mentioned above. Please download the following & save to your Desktop





    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Immediately attach this log to your next message before continuing because the next steps will overwrite it.
    Delete the current mbr.log file and then try to run the below instructions.
    Click Start > Run and copy & paste the following textin the code box into the Run box and then click OK:
    Code:
    [B]"%userprofile%\desktop\mbr.exe" -f[/B] 
    Now double click on the mbr.exe file and attach the new mbr.log


    Are you still having a problem?
     
    Last edited: May 2, 2009
  7. GaryGnu74

    GaryGnu74 Private E-2

    Okay, so you were right about IE as that's what I've been using. Downloaded FireFox, tried completing a purchase in an online shopping cart and did not get the Advanced Credit Card pop-up. Success there!

    Tried deleting files:

    c:\windows\Temp\rg4sfay
    c:\windows\Temp\ydf8dk

    but am unable to, says they are being used by another user or program.

    Folder C:\TPB_01 is where I keep some of my documents so it's fine.

    Folder c:\windows\ftpcache was empty so I deleted it.

    Ran MBR and attached the requested logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my queston at the end of the last procedure:
    How about now after running mbr -f ?
     
  9. GaryGnu74

    GaryGnu74 Private E-2

    Sorry about that. I did mention that once I switched to Firefox, I was not getting the Advanced Credit Card pop-up any longer. That was the major issue I was having. I have not gone back to IE.

    Also, since we began this whole process, I haven't been having problems with my system crashing on me.

    Tried deleting those two files and they came out just fine this time around.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then I would test IE again because you had an MBR infection that was probably the cause of the problem and we removed it.

    Also please attach a new log from MGtools after running the GetLogs.bat program as previously run.
     
    Last edited: May 6, 2009
  11. GaryGnu74

    GaryGnu74 Private E-2

    Tried IE again and am no longer experiencing the Advanced Credit Card Verification pop-up. Everything appears to be working fine.

    Attached MGlogs as requested.

    Thanks!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Okay that's great. Let's just cleanup temp folders and move on to final steps.


    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Eric Campos\Local Settings\temp


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds