Advert Window popup problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by colin.z, Jan 23, 2007.

  1. colin.z

    colin.z Private E-2

    I have 3 main reasons for suspecting that there is malware present:
    1. Attempted communication to Internet by an unknown program deb608??.exe, which I located in c:\Program Files\Common Files\System and also in running processes.
    2. Frequent 'pop-up' Web pages with adverts when accessing links to other Web pages, e.g. from Google
    3. Degrading performance (especially slow system startup after logon)

    Having applied all the steps in your Malware removal guide, I am still getting all three symptoms. I note that there are now two deb608* files in the folder (deb60812.exe and deb60813.exe) and that deb60812.exe is now in my startup processes - this might have been my fault because I was being prompted to allow the startup process to be updated about every 30 seconds and eventually gave in so that I could proceed with this thread.
    Please can you review the uploaded HiJackThis file and advise on what further things I need to do.

    I am running Windows XP (SP2), IE7, Norton Internet Security 2006. Set up for automatic updates on all of these.
    Each family member has their own account. I have had to grant my teenage children Administrator rights because many of their games will not run properly without it.

    We have had various virus/malware issues over the last couple of years, but had been able to resolve the worst of them in July last year - I had wrongly installed Adware instead of AdAware at some point in time, but once that had been sorted things improved a lot. I mention this because BitDefender picked up traces of many of these in old restore files.

    I have been running full NIS and Adaware scans at least once per month - this improves the performance for a while, but then it degrades again. NIS seldom picks up much in the full scans, but in recent days started finding and removing Adware.ZangoSearch, Adware.Hotbar and Adware.180Solutions. Adaware usually finds and quarantines WIN32.ADVERTS.TROJANDOWNLOADER

    I believe that I followed all the steps in the Malware Removal Guide, but note the following possible deviations, just in case they are important for you.

    cCleaner - I ran this as part of step 1, because the instructions recommended running it for all accounts, hence it did not have much to process when I ran it AGAIN in step 5, which is the one that I uploaded. Also, I deliberately stopped it deleting the cookies and recent URLs when cleaning the accounts of other family members.

    Spybot S&D - I cannot confirm whether I used Teatimer or not because I could not see any reference to it. I certainly did not explicitly turn it on.

    CounterSpy - I misread the instructions in 4 and assumed that I had to try running it in order to determine whether I needed to download AVG Anti-Spyware, so I have uploaded 2 logs, one for this original run (CounterSpyOrig.txt) and the other for the correct run as part of step 5 (CounterSpy.txt).

    Apologies if that rambled on a lot, but hopefully some of it was useful.

    Regards,
    Colin
     

    Attached Files:

  2. colin.z

    colin.z Private E-2

    Further files...
     

    Attached Files:

  3. colin.z

    colin.z Private E-2

    and HijackThis file
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to remove (delete) these two files:

    C:\windows\system32\dxvid.exe
    C:\program files\infxp\infxp\infxp.exe

    Please copy the text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select Do a system scan only. Look for the below lines (you may not always find both of them) and select them but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /nocomm
    O4 - HKLM\..\Run: [dxvid] c:\windows\system32\dxvid.exe /nocomm
    O4 - HKLM\..\Run: [mplay64] c:\program files\common files\system\mplay64.exe /noerrorinfo
    O4 - HKLM\..\Run: [gdimx] c:\windows\system32\gdimx.exe /nocomm
    O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)

    After clicking Fix, exit HJT.

    Attach new logs for:
    GetRunKeys
    ShowNew
    HJT
     
  5. colin.z

    colin.z Private E-2

    OK. Followed those steps. I had to kill the processes from Task Manager in order to do the deletes, and after I had run the HJT fix process I started getting attempts to insert deb60812.exe into the startup and I had to keep blocking them and then quickly rebooted - seems to be OK after that.

    Ran the 3 checks again as requested and attached.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note: process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm
     
  7. colin.z

    colin.z Private E-2

    Hi,

    It actually ran through very quickly. File uploaded as requested.

    Regards,
    Colin
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

    * First download AVG Anti-Spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program

    1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
    3. On the main screen select the icon "Update" then select the "Update now" link.
    * Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
    * Select "Automatically generate report after every scan"
    * Un-Select "Only if threats were found"

    Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.

    * Please reboot your computer in Safe Mode by doing the following :

    * Restart your computer
    * After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    * Instead of Windows loading as normal, a menu with options should appear;
    * Select the first option, to run Windows in Safe Mode, then press "Enter".
    * Choose your usual account.

    Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
    Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

    You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

    The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
    The report can also be found at the root of the system drive, usually at C:\rapport.txt

    Warning : running option #2 on a non infected computer will remove your Desktop background.

    * Still in Safe mode,

    IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:

    * Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
    * Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    * AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
    * If you have any infections you will prompted, then select "Apply all actions"
    * Next select the "Reports" icon at the top.
    * Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    * Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the C:\rapport.txt, the AVG Anti-Spyware report scan and a new hijackthis log, please.
     
  9. colin.z

    colin.z Private E-2

    Hi,

    fyi, your link to AVG Anti-spyware download is not working (also those from www.majorgeeks.com download pages for it to Majorgeeks locations, but the Authors link was working so I used that).

    Instructions followed and requested files are attached.

    Regards,
    Colin
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing any indication that you have run Spybot as per the Read and Run Instructions.

    Go to add remove programes in your control panel. Uninstall anything to do with (if there):

    Macrogaming

    Click start/run and type "regsvr32 /u C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll" without the quotes into the run box and press the enter key.


    Run HijackThis and select Do a system scan only. Look for the below lines (you may not always find both of them) and select them but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKLM\..\Run: [infxp] c:\program files\infxp\infxp.exe /nocomm
    O4 - HKLM\..\Run: [ravideo] c:\windows\system32\ravideo.exe /nocomm
    O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = ?
    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

    After clicking Fix, exit HJT

    Locate and delete the following bold files(if there).

    C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    C:\program files\infxp
    C:\windows\system32\ravideo.exe


    Please attach new logs for:
    GetRun
    ShowNew
    HJT

    And tell me how things are running.
     
  11. colin.z

    colin.z Private E-2

    Hi,

    Definitely ran Spybot, but did not upload anything because the READ & RUN ME FIRST instructions did not request it. I have uploaded the fix log for it from 22nd.

    All instructions followed as per your last note, but hit (& circumvented) some small problems as follows:

    1. regsrv32 command failed, but worked OK after I changed "Program Files" to "Progra~1"

    2. HJT fix hit an error (on the 04 - Global Startup I think, because it said it could not find ?.exe), but all the selected items had disappeared from HJT after I re-scanned.

    3. AfterRestart, Desktop background and MS shortcut bar had disappeared, but both were easy to reinstate manually.

    HJT log and current status on next reply...
     
  12. colin.z

    colin.z Private E-2

    I have not encountered any functional issues since applying the first set of fixes that you suggested, i.e. no longer getting attempts to contact IP from deb608??.exe and ho more pop-up advert windows.

    Not really able to comment on performance with confidence yet. Startup is particularly bad at the moment (about 5 mins), but I suspect that this may be interaction between Norton and CounterSpy and AVG Antivirus, which are currently all turned on. Task Manager shows a lot of activity for sunThreatEngine.exe during startup (cpu of up to 50% and memory 150-200Mb at peak, dropping back to about 80Mb steady state when system is idle).

    Regards,
    Colin
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need to uninstall all but one anti-virus. We are finished with Counterspy and it's your choice as to which of the others to keeps (noting that Norton is a real resource hog and may be difficult to uninstall. (Norton Removal Tool).

    As a final clean up ..run HJT and remove these two items:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://edit.europe.yahoo.com/config/login?.intl=uk&.partner=bt-1&.done=http%3a//bt
    .yahoo.com/%3f

    attach new logs for:
    ShowNew
    GetRun
     
  14. colin.z

    colin.z Private E-2

    Hi,

    Sorry for the misdirect. It is AVP antiSpyware that I have (not Antivirus), so only 1 AV tool (Norton). As both CounterSpy and AVG AntiSpyware are limited day trials, I have uninstalled both. Startup time is now back to what it used to be, so I can live with that.

    I note the comment about Norton being a resource hog - it came pre-installed on the PC and I had read that it was hard to remove so decided to live with it. I don't really fancy further SW fights at the present time, so will stick with the known environment for now, but will have a read of your Norton removal link and think about it at the next annual renewal.

    The requested logs are attached.

    Regards,
    Colin
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are looking good.
    Delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\username\Local Settings\Temp\
    C:\Documents and Settings\username\Local Settings\Cookies\

    You will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  16. colin.z

    colin.z Private E-2

    HI,

    OK. All done on 26th and have not had any problems since. Thanks very much for you assistance.

    Regards,
    Colin
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Last edited by a moderator: Jan 28, 2007

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds