adware punisher...helpp!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by militaryman, Feb 5, 2006.

  1. militaryman

    militaryman Private E-2

    I somehow managed to get some thing called adware punisher on my computer.(it transfered to all host names I had under profiles also) I have tried downloading hijack this and other programs that help delete it but it redirects me to adware punisher website. Can anyone help me so I can download hijack this and post my thing here for help?
     
  2. militaryman

    militaryman Private E-2

    Forgot to post this earlier, but it is not a full installation of adware punisher... It appears some of it was blocked by norton and winpatrol from installing and running. I tried to delete the registry parts of it, but they just reappeared. This thing is really annoying.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    Also run this and attach the smitfiles.txt log: SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal





    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
    Last edited: Feb 5, 2006
  4. militaryman

    militaryman Private E-2

    I have tried using spyware removal and such and it does not work. Punisher keeps reinstalling whatever I delete.... I am also locked out of my email, any download sites or mirrors and I can't even log into my system specs.... Only thing I know is I am on a inspiron 8600 dell and its windows xp...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run all the steps including something I just added to the steps below and we will get it fixed.
     
  6. militaryman

    militaryman Private E-2

    steps below? I did do the steps in the link you posted before I posted. Except I can not do step3, hijackthis, or the scanning online malware because I am unable to download. I am basicly locked out of pretty much everything. To get access to delete the files or atleast stop them from running. Safe mode would start up then restart back to normal mode...
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then in reality you did not do the steps.

    You need to get the SmitRem program mentioned in the SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal thread onto the PC some how and run the steps. Download it onto another PC (a friends etc) and copy to CD, flashdirve, floppy disk (whatever you can get) and run it on the infected system.
     
  8. militaryman

    militaryman Private E-2

    I have already tried to burn to disc from other computer. It will let me put it on the desktop of the laptop but when i try to run any of the progs from the tutorial it blocks it and brings up adware punisher website...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have unplugged the cable to the internet before trying. Also boot into safe mode and kill all unnecessary processes before running.

    But the key file you need now is not in the normal READ ME. You need the SmitRem.exe program from the SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal link.
     
  10. militaryman

    militaryman Private E-2

    ok I got to the panda thing where you search for the .exe where is the windows explorer at?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Huh???? Could you rewrite that more clearly?

    It does not tell you to use Panda to look for any EXE files. The Panda scan is done after you are finished deleting files using Windows Explorer.

    Are you trying to tell me you don't know what Windows Explorer is?????? Your kidding right!

    Here is one way to open Windows Explorer: Right click Start and select Explore
     
    Last edited: Feb 5, 2006
  12. militaryman

    militaryman Private E-2

    still getting same effects. I did the link you gave me step by step. btw i did mean the step after panda
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to post the smitfiles.txt log!

    The step after Panda is:

    Now please attach the smitfiles.txt and PandaActiveScanlog to your next reply. And also tell us how things are working.
     
  14. militaryman

    militaryman Private E-2

    sorry forgot about that one..
     

    Attached Files:

  15. militaryman

    militaryman Private E-2

    Will I have to do this for each user on my computer?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's possible! But if we find all the files maybe it will not be as bad.

    Here are a few of the problems (and will will have to add these to that link I gave you to be fixed/deleted while running SmitRem):
    C:\WINDOWS\system32\shell386.exe
    C:\WINDOWS\SYSTEM32\intxt.exe
    C:\WINDOWS\adw.htm

    We will fix these below!

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixadt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixadt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\EmpirePoker\EmpirePoker.exe
    C:\WINDOWS\system32\shell386.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
    O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\shell386.exe
    C:\WINDOWS\SYSTEM32\intxt.exe
    C:\WINDOWS\adw.htm
    C:\Program Files\EmpirePoker <-- the folder
    C:\Program Files\MyWaySA <-- the folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  17. militaryman

    militaryman Private E-2

    no more adware punisher background. running faster
     
  18. militaryman

    militaryman Private E-2

    here it is
     

    Attached Files:

  19. militaryman

    militaryman Private E-2

    still getting this thing that says page can not be displayed when I try to download certain anti malware progs like hijackthis and such.I could also not delte the intxt file it was not labeled as read only and no process was running so I dont know what the heck is up with that file. I just siwtched a bunch of things around so instead of running intxt.exe its running stoprunning.exe so it isnt running b/c there is no such file named that it just brings up a error on start up now saying file can not be found.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
    O2 - BHO: winapi32.MyBHO - {B439D5EB-0A61-4ED9-8C8F-EC4148BB23F7} - C:\WINDOWS\system32\winapi32.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\MyWaySA <--- delete the whole folder if still there
    C:\WINDOWS\system32\winapi32.dll

    Additional step to delete intxt.exe:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\SYSTEM32
    attrib -r -h -s intxt.exe
    del intxt.exe
    attrib -r -h -s stoprunning.exe
    del stoprunning.exe
    exit


    Let me know how these deletions go!
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  21. militaryman

    militaryman Private E-2

    here is the new htj. btw I have another computer problem... GRRR ill post it in a new thread since its a new computer prob with a dif computer...
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but have we resolved your issues with AdwarePunisher?
     
  23. militaryman

    militaryman Private E-2

    yes it worked. make sure if anyone else has this problem that they delete the intext with the cmd thing you told me to do. I did some research on it and it runs a hidden process at startup. So ctrl al tdelete doesnt detect it. It is also the one that forwards you to adware punishers site saying this website can not be displayed pop ups blocked 1 download adware punisher/buy adware punisher.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's why I had it in the procedure to be deleted!

    Windows Task Manager is not very useful in displaying all running processes. It also does not tell you where the file is running from (the path to the file). That is why we use the one in HijackThis. An even better one is Process Explorer

    You should work thru the below link:

    How to Protect yourself from malware!
     
  25. militaryman

    militaryman Private E-2

    I am right now:) can you help me in the other thread to. I am starting to learn how to see what things are bad in hijackthis. Its not really hard once u sit down and look at it. I am going home to get a copy of it on my computer and scan and bring abck. Since I dont want to delete something I shouldnt but ill prolly see if i cant find some of the things wrong with it to. Hopefully I can learn about as much as you guys know. This is the first time ive had a malware on.. I usually have firewalls up but I was testing new ones and well it disabled the old ones at the same time so when I dled a file it brought that with it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds