adware punisher

Discussion in 'Malware Help (A Specialist Will Reply)' started by m0_ose, Jan 29, 2006.

  1. m0_ose

    m0_ose Private E-2

    hey everyone, wow having major problems with my pc. all was fine until last nite when i was surfin the net and redirected to an explicit webpage which somehow managed to get passed all my virus and spyware protection. my desktop changed to a yellow background saying 'you have spyware download adware punisher to fix it' as well as pop ups which look like they are legitimate xp messages in the bottom right hand corner if i change my wallpaper it will change back to the yellow screen after 30 seconds or so. my home page changed, and internet explorer keeps opening itslef and trying to get to adwarepunisher.com. ive been reading forums about this problem and have tried adaware, spybot (which gets half way through a scan and then freezes) and cwshredder, as well as attempting to do online scans (which seemed to me as if a virus wasnt letting them run). i have lost all hope, so i downloaded hijackthis and have made a log would really appreciate it if someone could have a look.
    cheers, heres my log:

    ~ IN-LINE HIJACKTHIS LOG ATTACHED ~ TUTORIAL NOT DONE ~ SPD
     

    Attached Files:

    • HJT.log
      File size:
      7.6 KB
      Views:
      3
    Last edited by a moderator: Jan 29, 2006
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Welcome to MajorGeeks.com!

    Please follow forum guidelines and perform cleaning steps in the sticky thread before posting HijackThis logs. DO NOT copy & paste logs into your posts.

    Please follow our standard cleaning procedures which are necessary for us to provide you support.

    - Follow the directions for running Smitfraud, SpySheriff, SpyAxe & PSGuard Removal.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    Update the definitions for SpySweeper and run a full system Scan.

    Post smitfiles.txt from when you ran SmitRem, the BitDefender log, the Panda ActiveScan log, the SpySweeper log and a fresh HijackThis log.
     
  3. m0_ose

    m0_ose Private E-2

    alright il giv it qa go
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    m0_ose, please use capitalization, and proper punctuation when posting. It make it a lot easier to read and understand what you are try to tell us.
     
  5. m0_ose

    m0_ose Private E-2

    Hi, thanks for the pointers, I have done as you suggested. Here are the logs. I still have the desktop changing itself to a yellow screen 'Windows recommends Adware Punisher, Download Now' and balloons in the system tray saying things like 'data miner found' or 'you have spyware, windows will now download the latest protection for you'. My computer seems to be running a little faster though, and internet explorer isnt opening itself and going to random webpages anymore. I spoke to a guy at a local computer store and he reckons it might be spyaxe, but he was going to charge me $66 to fix it, so id rather have another go at it myself. Thanks for your help
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You posted the BitDefender summary; I need the log. The summary only tells me what was found, not where it was found and what action, if any, was taken.

    Scan with HijackThis and fix teh following:
    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Follow the directions for Running Spy Sweeper. Make sure you update the definitions before you do a full system scan.

    Post teh SpySweeper log and a fresh HijackThis log. I also need the BitDefender log.
     
  7. m0_ose

    m0_ose Private E-2

    Wow, thanks for the detailed reply. I did as you said and all seems to be working perfectly. Computer is running much faster, and im not getting any of the symptoms i described earlier. Thanks very much for your time and effort, much appreciated
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please post the logs I asked for in my previous post.
     
  9. m0_ose

    m0_ose Private E-2

    Sorry, did not see the note. Here are the logs... the bitdefender one is in html format for some reason.. thanks
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Empty the contents of the AVG Virus Vault.
    Delete everything in C:\!Killbox.
    Empty the Recycle Bin.
    Run CCleaner.

    Disable System Restore and then enable System Restore. This will flush all your restore points and create a new clean one for your system.

    System Restore
    How to Protect yourself from malware!

    Safe surfing.
     
  11. m0_ose

    m0_ose Private E-2

    thanks again, m0_ose
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds