Adware AGAIN!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ldfrostbite, Apr 14, 2006.

  1. ldfrostbite

    ldfrostbite Private E-2

    I don't understand it. I have Norton Antivirus, Norton Personal Firewall, Free Surfer, Adaware, Spypot S&D, Windows Firewall, and somehow we've got adware and viruses on this computer AGAIN.

    IE has been running really slow since last night, and I have about 60 running processes that are "verclsid.exe", which I learned through google is some new "security feature" from the latest windows update. Well, I've heard that it's causing problems, mainly with HP computers, which is what I'm running. But I don't know the damage it's causing because we're also being bombarded with popups and weird adware things.

    Every single website has "sponsored links" on random words, that redirect through something called "trafficsector". I'm getting popups from popuppers.com among many others that redirect too quickly for me to name. And for some reason, I can't get IE to go to any websites without typing the "http://www" in front of the website. In other words, if I simply put in majorgeeks.com, nothing would happen. I have to put in http://www.majorgeeks.com for the page to even begin to load.

    I just uninstalled Internet Optimizer using Add/Remove Programs for about the 8th time this year, but I know there are still remnants of it somewhere. And I just got an alert from Norton that I have "downloader.trojan" virus and it was unable to repair and couldn't gain access to the file.

    Please, any guidance? I'm desperate and very sick of the fact that I'm running all this security software and still manage to get attacked with spyware and adware.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I hope you have disable Windows Firewall (Norton probably did it for you but you should check). You must only run one software firewall. Ad-Aware free provides no protection. Spybot does not provide any full malware blocking unless you run Teatime which we do not recommend. What are you running?

    This is not an issue for this forum as it is not malware. But read the below for more info and you may want to just uninstall this update using Add/Remove programs.

    http://www.microsoft.com/technet/security/Bulletin/ms06-015.mspx

    http://www.microsoft.com/windowsxp/expertzone/newsgroups/reader.mspx?dg=microsoft.public.windowsupdate&tid=f836f340-c560-4554-a9e7-6bf3fb7d491d&lang=en&cr=US&p=1


    For you malware problems, see below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. ldfrostbite

    ldfrostbite Private E-2

    Thanks for the reply :)

    I did all the offline scans in safe mode, and I'm currently running the bitdefender scan, but it's been going for 15 minutes and the current estimated time is 37 hours...so that might be a while.

    Spybot S&D and Adaware found some things from E2Give, Internet Optimizer, Popuppers, and Hotbar. I had all of them fixed, but as soon as I rebooted in normal mode and reconnected to the internet, the popups came rushing in, so obviously that didn't solve much. The "sponsored links" are still present on all websites as well.

    And yes, I did have windows firewall disabled, I just thought it would be a good thing to mention that I have both norton and windows firewalls. I have Freesurfer's popup blocker on, as well as Google toolbar and adblocking from norton.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes the starting number is very high, if it actually goes beyond about 3 hours then stop it and run these two scan instead and attach their logs as requested. (These are not online scans!)
    Running Spy Sweeper

    Running Ewido Anti-Malware


    But you don't have the Windows firewall if it is disabled!
     
  5. ldfrostbite

    ldfrostbite Private E-2

    OK, for some reason Spy Sweeper is telling me it's expired, but I did the ewido scan, and now I'm doing the Panda ActiveScan, which is also being really slow.
     

    Attached Files:

  6. ldfrostbite

    ldfrostbite Private E-2

    The ActiveScan finally finished its scan, so I rebooted in normal mode and reconnected to the internet, and the sponsored links and popups are still there. I checked the Special Removal Procedures, it doesn't look like any of them apply to me. So I also ran HJT in normal mode, I attached both reports.
     

    Attached Files:

  7. ldfrostbite

    ldfrostbite Private E-2

    I tried running all the scans from the READ AND RUN ME FIRST thread again just to see if anything would work.

    CCleaner, AdAware SE, and Spybot S&D all found a lot of entries and supposedly fixed them all. Microsoft Windows Defender and Malicious Software Removal both found nothing. I also ran CWShredder and Kill2Me just in case. The Bitdefender scan locked up on me yet again, this time stating 23 hours estimated time left. And this time the Panda ActiveScan wasn't much help either, it froze after scanning only 1206 files. So I have an updated HJT log, that's all I've got for now and I can see the ieBHOs file is still there, so the E2Give thing hasn't been fixed.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a ton of malware installed. You seem to be a malware collector. We need some more info before we can work up a full procedure.

    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  9. ldfrostbite

    ldfrostbite Private E-2

    I figured there was a lot of stuff...as soon as one thing seems to go away, another one shows up.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of Sun Java because you already have the latest 5.0 update 6 installed.
    J2SE Runtime Environment 5.0 Update 2
    Java 2 Runtime Environment, SE v1.4.2_05
    Java 2 Runtime Environment, SE v1.4.2_06

    Also uninstall the below which where mentioned in step 0 of the READ & RUN ME.
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    Also uninstall the below SafeSurfing malware:
    IRISmon

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
    O4 - HKCU\..\Run: [kbdsys] C:\WINDOWS\system32\kbdsys.exe
    O4 - HKCU\..\RunOnce: [kbdsys] C:\WINDOWS\system32\kbdsys.exe
    O16 - DPF: {4FA3D392-9349-4D85-8FB9-18733534CFE3} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/gdownloader.ocx
    O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) - 0
    O20 - AppInit_DLLs: iniwin32.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\apsi <--- the whole folder
    C:\Program Files\Cas <--- the whole folder
    C:\Program Files\DNS <--- the whole folder
    C:\PROGRAM FILES\CasStub <--- the whole folder
    C:\PROGRAM FILES\E2G <--- the whole folder
    C:\PROGRAM FILES\Lycos <--- the whole folder
    C:\PROGRAM FILES\Media Gateway <--- the whole folder
    C:\PROGRAM FILES\sf <--- the whole folder
    C:\PROGRAM FILES\COMMON FILES\Download <--- the whole folder
    C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\vidctrl <--- the whole folder
    C:\TEMP\FLEOK <--- the whole folder
    C:\WINDOWS\system32\iniwin32.dll
    C:\WINDOWS\SYSTEM32\atmtd.dll
    C:\WINDOWS\system32\biU.exe
    C:\WINDOWS\SYSTEM32\bk.exe
    C:\WINDOWS\SYSTEM32\data.~
    C:\WINDOWS\system32\ezPopStub.exe
    C:\WINDOWS\system32\iniwin32.dll
    C:\WINDOWS\system32\InstallerV5.exe
    C:\WINDOWS\system32\kbdsys.exe
    C:\WINDOWS\SYSTEM32\pdrpdb.dll
    C:\WINDOWS\SYSTEM32\tsuninst.exe
    C:\WINDOWS\system32\xmltok.dll.off
    C:\WINDOWS\SYSTEM32\Xcite.dll
    C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho
    C:\WINDOWS\alchem.ini
    C:\WINDOWS\kwv2.dat
    C:\WINDOWS\optimize.exe
    C:\WINDOWS\pf78.exe
    C:\WINDOWS\pi1_36.exe
    C:\WINDOWS\unstall.exe
    C:\WINDOWS\usta32.ini
    C:\WINDOWS\woinstall.exe
    C:\WINDOWS\etb <--- the whole folder[/COLOR]
    C:\WINDOWS\inf\biU.inf
    C:\WINDOWS\T3duZXIA\SWuqQwQlSSxZrItv1J64IcPZfOT.vbs
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Apr 16, 2006
  11. ldfrostbite

    ldfrostbite Private E-2

    I followed the instructions, and things seem to be running much more smoothly now. No more sponsored links and I haven't had a popup yet. Thank you!

    But I do still notice E2Give in the HJT log, and I couldn't delete iniwin32.dll, as it kept telling me the file was in use. I checked to see if it was read-only, and I terminated everything I could in Task Manager, but it still wouldn't allow me to delete this file.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unnstall MS Windows Defender because it may be getting in our way. Then reboot before continuing.

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate.


    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Program Files\E2G\IeBHOs.dll
    C:\WINNT\system32\iniwin32.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Now in safe mode, run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
    O20 - AppInit_DLLs: iniwin32.dll

    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):
    C:\Program Files\E2G <--- the whole folder
    C:\WINNT\system32\iniwin32.dll

    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log and tell me how these steps went.

    Also tell me how things are working!
     
  13. ldfrostbite

    ldfrostbite Private E-2

    Neither HJT nor Killbox could get rid of the iniwin32 problem...HJT gave me an error when trying to fix "O20 - AppInit_DLLs: iniwin32.dll", and told me to contact the developers. And Killbox simply said "Cannot delete file". Apparently it's still in use, even though I booted in safe mode and had absolutely nothing running or open but windows explorer.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you set Killbox to Delete on Reboot? Sounds like you used Standard File Kill!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Go here and download and install Registrar Lite
    • Run it, copy and paste the below line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    • Click the "go" tab
    • You should see the "Appinit_Dlls" value on the right side panel
    • Make sure the Windows key is selected in the left window pane
    • Rename the Folder Windows to NotWindows highlighted as a light blue (some people call it light purple) folder in the left hand pane of reglite. You rename it by right clicking on it and selecting rename.
    • Now Double Click AppInit_DLLs in the right window pane and clear the data value. That is delete the C:\WINNT\system32\iniwin32.dll information from the value box. Now Click Apply and OK to set.
    • Now Rename the NotWindows folder back to its original name Windows
    • Reboot you PC into safe mode and see if you can delete the C:\WINNT\system32\iniwin32.dll file. If you cannot delete it, see if you can right click on it and select rename. Change it to iniwin32.ddd
    • While in safe mode run HijackThis and fix the below line if still found:
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
    O20 - AppInit_DLLs: iniwin32.dll

    • Reboot into normal mode and attach a new HJT log and tell me how these steps went.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds