Another Popup ad Thread question

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Dichotmist, Oct 22, 2004.

  1. Dichotmist

    Dichotmist Private E-2

    Ok I had done a search and ran HijackThis, SpyBot, and Ad-Aware. I have following the sticky instructions for these. I still get popup ads when I start Internet Explorer so I must be missing something. I am running Win2000 Professional. Any help would be great!!

    Thanks
     
  2. Kodo

    Kodo SNATCHSQUATCH

  3. Dichotmist

    Dichotmist Private E-2

    Thanks for the quick reply. Attached is the HijackThis.txt file.
     

    Attached Files:

  4. Dichotmist

    Dichotmist Private E-2

    I forgot the other symptom was a slower than normal PC (opening programs, internet, etc.). Thanks,
     
  5. Kodo

    Kodo SNATCHSQUATCH

    please follow the instructions EXACTLY.

    you ran HJT from
    C:\Documents and Settings\tfaux\Local Settings\Temporary Internet Files\Content.IE5\CRST4JIZ\HijackThis[1].exe

    it is clearly stated not do run it from an archive, temp folder or any folder in documents and settings. . Place HJT in its' own folder C:\program files\hijackthis ...and run it from there. Close all IE windows, then post a new log file.
     
  6. Dichotmist

    Dichotmist Private E-2

    Sorry about that. See attached.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have an IE process running and you have the wrong version of HijackThis. Get the latest version 1.98.2. It had a link in the READ ME thread. Then shutdown ALL IE process and post a new log with the new version of HJT.

    EDIT: Sorry Kodo didn't see you back here.
     
  8. Kodo

    Kodo SNATCHSQUATCH

    Your version of HJT is too old.. sorry, I didn't notice this the first time around.
    go here
    http://www.majorgeeks.com/download3155.html

    download the new one and post yet another log..lol ;)


    [edit, sorry chas, didn't see ya there]
    [edit 2. lol. ]
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL! There's a bunch of Trojans here and the below line looks like ClearSearch too.
    O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe

    Do you think it would be worth running A-squared?
     
    Last edited by a moderator: Oct 22, 2004
  10. Dichotmist

    Dichotmist Private E-2

    Ok guys thanks for staying with me. Here is the new verision.
     

    Attached Files:

  11. Kodo

    Kodo SNATCHSQUATCH

    That O4 is union way app hunter. stand by Dichotmist.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kodo,

    I think it is ClearSearch also see the missing DLL:
    C:\Program Files\CSBB\CSBB.DLL
    http://www.doxdesk.com/parasite/IGetNet.html
     
  13. Kodo

    Kodo SNATCHSQUATCH

    so much for my reading comprehension today.. it is clearsearch.. I read the wrong part of this search info I found.. *smacks forhead*
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kodo,
    Did you notice that the online scanners were not run? Hmmm! Anything else skipped?
     
  15. Kodo

    Kodo SNATCHSQUATCH

    no.. I didn't get down that far.. I'm going to add pattern for that in LoJackThis so I can nail 'em at first go.
     
  16. Kodo

    Kodo SNATCHSQUATCH

    Ok, we gots lots of problems here with Trojans like Chas said.
    Lets start by running the online scans as suggested (in normal mode) in our tutorial.

    http://forums.majorgeeks.com/showthread.php?t=35407
    READ ME FIRST: Basic Spyware, Trojan And Virus Removal

    Then run the alternative scans listed at the end of the tutorial.

    When you're done with that, then run the WHOLE tutorial AGAIN because malware items that could have cascaded may be removed and the scans may clean up more stuff. Then post a new log.
     
  17. Dichotmist

    Dichotmist Private E-2

    So I've completed all of the below installations/ scans:
    Ad-Aware SE
    Ad-Aware VX2 Cleaner Plug-In
    CCleaner
    Spybot
    SpywareBlaster
    McAfee AVERT Stinger
    CWShredder
    Kill2me
    about:Buster
    HSRemove
    Trend Micro's Online Virus Scan
    Symantec Security Check
    Bitdefender online scan
    RavAntivirus online scan
    TrojanScan online scan
    a-squared
    ADS SPY


    Only ad-aware and spy-bot found anything and promply removed them. I ran ADS SPY, but I'm not sure what is ok to remove and what is not. I have ran HijackThis again and attached the file. Let me know what you guys think. By the way I have ran each multiple times.
    Thanks,
     

    Attached Files:

  18. Kodo

    Kodo SNATCHSQUATCH

    you can remove this one using HiJackThis
    O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\Program Files\CSBB\CSBB.DLL

    A-Squared didn't find anything?

    Ok, try this one

    http://tools.zerosrealm.com/PeperFix.exe
    Peperfix
    if it doesn't find them then see if you can find the files and delete them.

    C:\WINNT\vzwwrt.exe
    C:\Program Files\CSBB\CSV7P070.exe
    C:\WINNT\system32\pxeabn.exe
    C:\WINNT\Meruoq.exe
    C:\WINNT\vzwwrt.exe
    C:\WINNT\system32\gjdxvc.exe
    C:\Program Files\VVSN\VVSN.exe
    laprovau.exe

    I know you probably won't find them, but try anyway

    next
    go to start, run.. type
    REGSVR32.EXE /U C:\Program Files\CSBB\CSBB.DLL
    hit enter and then ok to any prompts
    then
    REGSVR32.EXE /u C:\WINNT\system32\gjdxv.dll
    hit enter and then ok to any prompts.

    Find those two files and delete them..


    remove these in HiJackThis
    O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\Program Files\CSBB\CSBB.DLL
    O2 - BHO: SDWin32 Class - {767BDA7E-5249-4529-AE6B-4E3DB73C3280} - C:\WINNT\system32\gjdxv.dll
    O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe
    O4 - HKLM\..\Run: [ryikflu] C:\WINNT\system32\pxeabn.exe
    O4 - HKLM\..\Run: [Rxagik] C:\WINNT\Meruoq.exe
    O4 - HKLM\..\Run: [viueeim] C:\WINNT\vzwwrt.exe
    O4 - HKLM\..\Run: [gjdxvc] C:\WINNT\system32\gjdxvc.exe
    O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
    O4 - HKCU\..\Run: [cws2RUc8i] laprovau.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/18f9f455c60b096c5414/netzip/RdxIE601.cab

    post new log when done.

    make sure IE is not running when you do this.. close all browsers.
     
  19. Dichotmist

    Dichotmist Private E-2

    OK I followed your instruction and removed:
    C:\WINNT\vzwwrt.exe
    C:\WINNT\system32\gjdxvc.exe

    And the rest of the stuff out of HijackThis. I then ran Giant AntiSpyware. This worked awesome. It found the nine spyware installs that were killing me. I got rid of those and everything seems to work great. I have attached the new HijackThis log file just in case though.

    I think everything we did may have screwed up my Outlook now though. It will not connect to the server to download mail. Any idea what we did that could have caused this?

    Thanks,
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach your log!

    I'm not sure what the problem is with Outlook!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds