Annoying pop-ups

Discussion in 'Malware Help (A Specialist Will Reply)' started by Krissi, Oct 22, 2006.

  1. Krissi

    Krissi Private E-2

    I have read and followed the "Read & Run Me First" file, the various logs requested are attatched here or in the reply to this message (as per in the 3 files/post rule).

    The problem I am having is annoying pop ups when using Internet Explorer to view any websites, even legit ones like this one. The titles of these pop-ups are various, including Passion.com, Party Poker, Sultan Castle casino and various ads trying to sell me anything from watches to camcorders. I am running AVG anti-virus.

    In reply to another post questioning why Sundays are the busiest: Sundays are the only days many of us have time to sit and fix what those around us have corrupted during our absence.

    If there is anything else needed, please let me know.
     

    Attached Files:

  2. Krissi

    Krissi Private E-2

    A new popup accompanied my posting this thread - this one called ClickTones.

    Here's the rest of the logs...
     

    Attached Files:

  3. Krissi

    Krissi Private E-2

    Just noticed this process running on computer: jumpthunkatom.exe - what the hell is this, nobody seems to know what this process is.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Of course we know what it is! ;) It is just one a the files created by the LOP infection that you have.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Mozilla Firefox (1.5)
    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    If you did not add this R1 line setting show below, add it to the list of things to fix with HJT further down in this procedure.
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    c:\docume~1\john-o~1\applic~1\binbib~1\jumpthunkatom.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [regs wait ante move] "C:\Documents and Settings\All Users\Application Data\heart bows regs wait\Scr Slow.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [Glue Body] C:\DOCUME~1\JOHN-O~1\APPLIC~1\BINBIB~1\CopySlow.exe
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Download Plugin\DlPlugin-MSIE_1.5.0.0\setup2.exe
    C:\Documents and Settings\All Users\Application Data\heart bows regs wait <--- the whole folder:
    C:\Documents and Settings\John-Otto Phillips\Application Data\BIN BIB CAMP <--- the whole folder:
    C:\Program Files\BIN BIB CAMP <--- the whole folder:
    C:\Program Files\Download Plugin <--- the whole folder:

    Now run Ccleaner.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Oct 24, 2006
  5. Krissi

    Krissi Private E-2

    Ran all of the above steps, seemed to go OK. And...no more popups!!! Yay!

    Here are the new logs:


    Thanks so much!!!
    You guys rock!!!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You missed (or something blocked the fix) one of the lines I asked you to fix. Fix the below line again and attach a new HJT log:

    O4 - HKCU\..\Run: [Glue Body] C:\DOCUME~1\JOHN-O~1\APPLIC~1\BINBIB~1\CopySlow.exe

    If it does not go away, you will have to shutdown Windows Defender and AVG Antispyware and then fix it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds