Constant Popups

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cami, Aug 29, 2005.

  1. Cami

    Cami Private E-2

    I'm getting constant popups, mostly in IE, though I no longer use IE-- the browser will start up by itself with these endless popups. I run spybot and adaware constantly, scanned with Norton Antivirus 2005, and have tracked down and fixed what I could manually. I get a few popups in my MSN browser (that's what I've been reduced to), but not nearly what I get with IE, even though I don't have it on, as I said. I can't uninstall IE (I have XP, sp2), and if the popup can't bring it up, I just get an IE has enountered a problem, please close error.

    I'm on Windows XP sp2; I'm using MSN browser.

    Any help you can give me would be greatly appreciated.
     
  2. Cami

    Cami Private E-2

    Hijack This log attached. Thanks!

    Cami
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then they must be attachments to your message.

    Please run the steps below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    After doing the above continue with the below:



    - Download this trial version of Ewido Security Suite

    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:


    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report


    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report. And tell me if you are still having any problems. This log could get quite large and you may need to compress it into a ZIP file to upload it.


    Post this Ewido log.

    After posting the Ewido log continue on to my next message!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. Cami

    Cami Private E-2

    I ran all the steps in the sticky thread, as directed. Plus, I did the optional step of removing Microsoft Java. Both the Ravscan and BitDefender found stuff, but wasn't able to fix it all. I'm attaching files with the results of those scans. As I was running those in safemode, I was flooded with popups, and so even more stuff came up in spybot and adware to be fixed.

    I'll do the Ewido stuff now.

    Thanks,
    Cami
     

    Attached Files:

  6. Cami

    Cami Private E-2

    I ran the Ewido scan and it found and fixed a bunch of stuff, but I'm still being flooded with popups. I'm attaching the Ewido report and the HiJack This log that I just ran as directed.

    Thanks so much for your help.

    Cami
     

    Attached Files:

  7. Cami

    Cami Private E-2

    Okay, as of this morning, the situation's much improved. I've been online for awhile now and haven't received any popups, but periodically (every 10 minutes or so) I get a notice of an infected file from Ewido-- it references b.com, TrojanDropper.Agent.pb in the C:\WINNT\TEMP directory. I click to clean it and it goes away for awhile, then comes back up again.
     
  8. Cami

    Cami Private E-2

    Oops, spoke too soon. I just got flooded with popups again, from IE, even though I'm not using IE as my browser.
     
  9. Cami

    Cami Private E-2

    I'm currently also getting another alarm from Ewido for l44dsx.exe in C:\WINNT\system32. TrojanDownloader.Qoologic.ac. I click to Block and Clean, but it comes up every 10 minutes or so anyway.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not post the Ewido log. You posted my directions. Please post the correct Ewido log and also post a log from HijackThis that is run in normal boot mode instead of safe mode.
     
  11. Cami

    Cami Private E-2

    Sorry.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs and tell me if you see any of the below and if so, uninstall them:

    SurfSideKick 3
    E2G
    or E2Give
    Media Access
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also as double check using Windows Explorer for the below files and folders and delete them if found (some of them may already be delete from the tools we ran). Let me know the results. If you have trouble deleting them in normal boot mode, try booting in safe mode to delete them. Make sure your browsers are all closed too!!!!!

    C:\Documents and Settings\Owner\My Documents\download\Morph2022e.exe
    C:\WINNT\system32\nsvsvc <--- the whole folder
    C:\WINNT\system32\vidctrl <--- the whole folder
    C:\WINNT\system32\AUNPS2.dll
    C:\WINNT\system32\wintask.exe
    C:\WINNT\system32\InstallAPS.exe
    C:\WINNT\Temp\ei.exe
    C:\WINNT\Temp\install.exe
    C:\WINNT\Temp\Temporary Internet Files\Content.IE5\4PMPA745\install[2].exe
    C:\WINNT\Temp\Temporary Internet Files\Content.IE5\81Q74TE7\download[1].htm
    C:\WINNT\Temp\Temporary Internet Files\Content.IE5\WPUFSH2J\deliver46860[2].htm


    Now continue with the below:
    Download the following tool and save it where you will be able to find it.

    L2MeFix Tool

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log. You will need to post this log back here later when you come back.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Now reconnect and continue with the below.

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post all three logs as attachments. This will require two messages.
     
    Last edited: Aug 30, 2005
  14. Cami

    Cami Private E-2

    I was able to remove SurfSidekick and Media Access from Add/Remove programs, but not E2Give-- a window just flashed and nothing happened. It's program size is listed as 0MB.

    I'm attaching the L2Me and Qoologic files, I'll attach the RK file in the next message.
     

    Attached Files:

  15. Cami

    Cami Private E-2

    RKTool file.
     

    Attached Files:

    • log.txt
      File size:
      812 bytes
      Views:
      1
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where you able to find and delete that list of files I gave?

    Okay we have some more to do.

    DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.

    Your computer will go crazy for a bit, but just let it run. It should eventually spit out a log in Notepad. Please also attach this log to your next message.

    Please don't run any other files in the L2MFix folder.


    Now continue with the below:

    - Download Pocket KillBox

    Extract Killbox to its own folder - somewhere that you will be able to locate it later. Do not run it yet.

    Reboot in Safe Mode (do not open any other processes)

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Checkmark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.

    C:\WINNT\System32\DATADX.DLL
    C:\WINNT\System32\CONRES.CPL
    C:\WINNT\BROWSER.EXE
    C:\WINNT\icont.exe
    C:\WINNT\RMAgentOutput.dll
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nppc.exe

    When it reboots, please boot back to safe mode again.

    Once in safe mode run KILLBOX again and Run those files through Killbox once more to be sure nothing survived. But this time place a tick by any of these selections if available

    "Standard File Kill"
    "End Explorer Shell while Killing File"
    "Unregister .dll before Deleting"

    Sometimes these files can be stubborn to remove so I just want to run thru this twice.

    After reboot this time, boot to normal mode and let me know how things are working.

    Also attach a new HJT log and new logs from Find-Qoologic.bat and rkfiles.bat. Don't forget the L2MeFix log from above too. This will take two messages to post 4 logs.
     
  17. Cami

    Cami Private E-2

    I was able to delete the files you listed that were on my machine-- they weren't all there.

    I'll get busy on this other stuff and get back to you.

    Thanks again for your help.
     
  18. Cami

    Cami Private E-2

    I followed the steps you recommended, and everything went off without a hitch. When I rebooted back into normal mode, however, I got some Qoologic alarms from Ewido. So far, no popups, though.

    I'm attaching scan results in this message and the next.

    Cami
     

    Attached Files:

    • log.txt
      File size:
      686 bytes
      Views:
      2
    • file.txt
      File size:
      1.2 KB
      Views:
      1
  19. Cami

    Cami Private E-2

    HT and l2me.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not a complete log from L2MeFix option 2. Are you sure you let it run all the way!

    You may need to run it again and make sure after reboot that you let it run to completion.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.

    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service

    Now exit HJT and do not reboot if it asks you to do so.

    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Now restart HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O4 - Global Startup: nppc.exe
    O23 - Service: CWShredder Service - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C0KQAI36\cwshredder[1].exe (file missing)

    After clicking Fix, exit HJT.

    Now run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Checkmark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.

    C:\WINNT\System32\JOOKE.DLL
    C:\WINNT\System32\__DELE~1.DLL

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nppc.exe

    If it does not reboot or you get a Pending file operations error, just reboot the system yourself.

    After reboot do not run anything else until you do the below.

    Run Windows Explorer and look for the below and delete if found (some are double checks):
    C:\Program Files\E2G <--- the whole folder
    C:\Program Files\Media Access <--- the whole folder
    C:\WINNT\System32\JOOKE.DLL
    C:\WINNT\System32\__DELE~1.DLL
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nppc.exe

    Now get a new HJT log. Then come back here and post the new HJT log and tell me how these steps went and how things are working.
     
  22. Cami

    Cami Private E-2

    Hi,

    I'm pretty sure I ran the complete l2me fix-- it rebooted, ran for awhile, spit out some text and popped up a log file. I'm not sure why that one wasn't complete, though.

    I followed all the steps you gave me carefully, and this time Ewido hasn't come up with any warnings, and I haven't gotten any popups. So far so good.

    I'm attaching the HJT file, and I'll keep my fingers crossed.

    Cami
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  24. Cami

    Cami Private E-2

    Thanks! I haven't had any popups or alerts since last night. I ran MS Antispyware and it found 26 entries that it cleaned up. Everything seems to be running smoothly--
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good. But what did MS AS find?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds