annoying pop-up ads "by OuterInfo"

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fizz, Jun 27, 2006.

  1. Fizz

    Fizz Private E-2

    Just recently I started getting these pop-up ads only while I browse the web that all say they are by outerinfo in the title bar.

    Ok, first I went through all the steps in the "read and run me first" thread..with little success. Ccleaner and CounterSpy (i'm running windows ME) both had errors trying to start them up. I couldn't download that latest sun java version and both online scans wouldn't run. whew......go me..

    Adaware SE and Spybot I have been using for a long time and they worked fine. Both found some things and I fixed them, but there were two things that Adaware couldn't fix..don't remember what they were tho.

    So, I ran hijackthis with hidden files visable and normal windows start-up, and saw some suspicious things..I don't know if it helps, but when I press ctrl-alt-del to check what programs are running, a few new things that I haven't seen before are "Kotjt", "Userinit", "!update" and "Jgi" (or it might've been Jpi). I don't see the Jgi thing anymore since using Adaware and spybot.

    Anyway, attached is my hijackthis log. Hope someone can help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log ( Make sure you install it properly because you had it incorrecly installed in your first log ):
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. Fizz

    Fizz Private E-2

    I went through all the steps in that sticky in the right order all over again...This is the best I can do. This time tho, Ccleaner and CounterSpy both ran. Adaware and spybot didn't find anything. Still, I couldn't get either of the on-line scanners (Bitdefender or Panda ActiveScan) to load/run.

    I'm still getting occasional pop-ups..but it doesn't seem to be as bad as before. I have the counterspy log below, and as far as hijackthis, I reinstalled it exactly following the directions in the post and ran it after a normal boot..not sure if i was supposed to close any of the programs running in the background so I didn't do that.

    Please try to tell me more specifically what i'm doing wrong.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Educational Note: You should not install programs like this:
    C:\WINDOWS\DESKTOP\MY STUFF\PROGRAMS\SPYWARE TOOLS\SUNTHREATENGINE.EXE
    C:\WINDOWS\DESKTOP\MY STUFF\PROGRAMS\SPYWARE TOOLS\SUNPROTECTIONSERVER.EXE
    C:\WINDOWS\DESKTOP\MY STUFF\PROGRAMS\SPYWARE TOOLS\SUNSERVER.EXE

    You should always install programs into their default folder which is normally under C:\Program Files

    You do not want all this clutter on your Desktop and in addition anything not installed and seen running from the correct folders is always suspected as being malware. Your Desktop should only have Shortcuts that are used to run programs. Not the actual installed programs themselves.

    Here is another example problem of how not to install something:

    C:\MY DOCUMENTS\AAOP\USERINIT.EXE

    This looks like malware to me for two reasons. First because of where it is running from and second because of the userint.exe filename. Is this something you installed? It could be this:

    http://www.sofotex.com/TSEP---The-Search-Engine-Project-download_L27025.html

    Or it could be something else or malware.


    You did not allow CounterSpy to fix anything. You Ignored everything. Please run it again and this time tell it to fix what it found.

    It does not look like you ran step 0 of the READ ME. I see Virtual Bounce (VBouncer) running. Did you look for it in Add/Remove programs and uninstall if found?

    I'll give you some stuff to start fixing while I wait for answers to the above.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\PROGRAM FILES\COMMON FILES\RHSO\WMAOPXQ.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,
    R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {35E76296-DD22-F583-0696-F64A3586A3CF} - C:\WINDOWS\SYSTEM\UFXHNJA.DLL
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O1 - Hosts: 195.13.63.187 irc.westwood.com
    O1 - Hosts: 195.13.63.187 servserv.westwood.com
    O2 - BHO: (no name) - {35E76296-DD22-F583-0696-F64A3586A3CF} - C:\WINDOWS\SYSTEM\UFXHNJA.DLL
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
    O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
    O4 - HKCU\..\Run: [Oyihnvb] C:\Program Files\Common Files\Rhso\wmaopxq.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\WildTangent <--- the whole folder
    C:\Program Files\VBOUNCER <--- the whole folder
    C:\Program Files\Common Files\Rhso <--- the whole folder
    C:\Program Files\AWS <--- the whole folder
    C:\WINDOWS\SYSTEM\UFXHNJA.DLL

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. Fizz

    Fizz Private E-2

    Thanks!

    The C:\MY DOCUMENTS\AAOP\USERINIT.EXE is definitely not something I installed or wanted, and the whole AAOP folder was created just last sunday without me having any idea of it.

    Sorry, I didn't see anywhere in the tutorial or in the program to 'fix' anything for the CounterSpy, but I'll check again.

    I did do step 0 of the READ ME, but there is nothing unusual left for me to uninstall. I did see a Vbouncer thing in there before, but I uninstalled it through this method and still traces of it are seen in odd places. Still, I think I've had that on this pc for a long time. The pop-up problems I get now started happening within a few days to a week ago.

    I'll try step 5-6 again and makes sure to have counterspy fix the problems this time.

    I also made the fixes you told me to make with HJT, hidden files visible of course. However, the following items weren't present this time:

    in hijackthis:
    R3 - URLSearchHook: (no name) - {35E76296-DD22-F583-0696-F64A3586A3CF} - C:\WINDOWS\SYSTEM\UFXHNJA.DLL
    O2 - BHO: (no name) - {35E76296-DD22-F583-0696-F64A3586A3CF} - C:\WINDOWS\SYSTEM\UFXHNJA.DLL

    files:
    C:\Program Files\VBOUNCER
    C:\WINDOWS\SYSTEM\UFXHNJA.DLL

    Here's a new HJT log

    Edit: so far I haven't been seeing any pop-ups, but I also haven't browsed the web a whole lot either yet
     

    Attached Files:

  6. Fizz

    Fizz Private E-2

    ok, I redid steps 5 and 6. Ad-aware found nothing, spyware found and fixed a wildtangent problem. Counterspy came up with a bunch of garbage, fixed all that this time. Now, bitdefender actually ran this time, but only in normal boot mode. Panda Activescan still wouldn't run.

    Below is the bitdefender log and my most recent hijackthis log.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you re-run CounterSpy yet? Did you let it fix what it finds? Attach a new log from CounterSpy after doing this.

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  8. Fizz

    Fizz Private E-2

    Thanks, I still haven't seen anymore of the pop-ups. That aaop folder in "My Documents" still looks suspicious to me tho since I never knowingly put it there.

    Attached is the uninstall list and my second counterspy log (for the scan where I applied the fixes).
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay CounterSpy cleaned up a pile of baddies!

    Oooooh a Command & Conquer player! ;)

    You never truly follow the directions in the READ & RUN ME. If you had, you would not be using a 3 year old version or Spybot. You are running:

    Spybot - Search & Destroy 1.2

    Uninstall it and install the proper version as given in the READ ME. Make sure you get ALL updates and use the Immunize feature.

    You should also uninstall the below very old version of Ad-Aware:
    Ad-aware 6 Personal


    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\MY DOCUMENTS\AAOP\USERINIT.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {2F58C96A-2ED0-5227-A1EC-01D58C2DEA9D} - C:\WINDOWS\SYSTEM\EGW.DLL
    O4 - HKCU\..\Run: [Tsep] "C:\My Documents\aaop\userinit.exe" -vt yazr

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\SYSTEM\EGW.DLL
    C:\My Documents\aaop <--- delete the whole aaop folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. Fizz

    Fizz Private E-2

    Still no pop-ups! :)

    hahahah..OOPS..I was wondering what the hell teatimer was since I never saw any of it. The new spybot version found and fixed some old things that I didn't know about. Also, Ad-aware 6 was the first version I got, then I got SE, and pretty much forgot about 6.

    In hijack this, i couldn't find "C:\MY DOCUMENTS\AAOP\USERINIT.EXE" in the process manager. I guess it wasn't running? Everything else went smoothly.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so how is everything working now?

    You should uninstall CounterSpy and do no install things to your Desktop anymore. CounterSpy is only a 15 day trial which will not work after the trial period. If you are going to buy it, then you should still uninstall it and then reinstall it properly into its default folder which is suggested while running the install program.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link ( you need a Firewall & an antivirus program ASAP).


    How to Protect yourself from malware!
     
  12. Fizz

    Fizz Private E-2

    Everything is fine now. I'll be sure to finish up with those steps. Thanks very much. :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds