Gad network/amaena pop ups can't get rid of

Discussion in 'Malware Help (A Specialist Will Reply)' started by ukkaren, Mar 25, 2007.

  1. ukkaren

    ukkaren Private E-2

    Hi all

    I really hope someone can help me out with this please! I have constant pop-ups from either gad network or amaema.com everytime IE is launched.

    I have followed all the steps in the Read and Run me thread with the following results

    Counterspy - would not run
    AVG (in safe) no results
    BitDefender - found virus log attached
    Panda - would not run
    Getrun - attached
    Shownew - attached
    Spybot S & D (in safe) no result

    I also ran my own anti-virus (McAfee) with no results.

    Looking at the BDscan it looks like whatever it is has come from the kids (how yet to be discovered) downloading message skinner to Windows Live msn. Both have now been uninstalled but the problem is still here :(

    I have also run a HJT log attached separately.

    Can anyone help me out with this one??? I really hope I did all this ok, this is the most advanced stuff I have had to do :eek:

    Thanks!!
     

    Attached Files:

  2. ukkaren

    ukkaren Private E-2

    HJT log here

    thanks again!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not do step 2 of the READ & RUN ME properly. That's also why you have analyse.exe named as analyse.exe.exe (you could not see the extensions before since step 2 was not done. The below registry patch will do it for you.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Did you purchase Spyware Detector or are you using a free version?

    Are CounterSpy and AVG Antispyware the free trial versions from the READ ME? If so, uninstall them now!!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\roagbmjuyv.exe
    C:\WINDOWS\system32\roagbmjuyv.dat
    C:\WINDOWS\system32\roagbmjuyv_nav.dat
    C:\WINDOWS\system32\roagbmjuyv_navps.dat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot double check using Windows Explorer to make sure the below files have been deleted:
    C:\WINDOWS\system32\roagbmjuyv.exe
    C:\WINDOWS\system32\roagbmjuyv.dat
    C:\WINDOWS\system32\roagbmjuyv_nav.dat
    C:\WINDOWS\system32\roagbmjuyv_navps.dat

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. ukkaren

    ukkaren Private E-2

    thanks for the quick reply, sorry for the mess up! :eek:
    will do all that now and let you know

    thankyou!

    Spyware Detector is the purchased version, does this make a difference? the AVG and Counter were from the Read me and have been uninstalled.
     
  5. ukkaren

    ukkaren Private E-2

    :( still got the pop ups.. but not so many

    regfix worked fine
    avg uninstalled no problem
    counterspy (?? is now trying to install every time I reboot)
    Java old uninstalled and new unstalled no problems

    Hoster and Pocketkill both seemed to work fine
    RO - removed
    R1 - did not find this with the next HJT
    04 - HKLM ..[TkBellExe] removed
    04 - HKLM ..[QuickTime Task] ... atboottime removed
    04 - HKCU ..[QuickTime Task] .. atbootime did not find this

    Didn't find system32 files

    on the upside pc is now running a lot quicker

    new files as requested attached

    thanks :)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure how you are looking for them or deleting them but you are missing them. They are still there. Looking in your newfiles.txt log yourself and you will see the below all get listed at a couple locations:


    C:\WINDOWS\system32\roagbmjuyv.exe
    C:\WINDOWS\system32\roagbmjuyv.dat
    C:\WINDOWS\system32\roagbmjuyv_nav.dat
    C:\WINDOWS\system32\roagbmjuyv_navps.dat


    These are the cause of your popups and until you delete them as requested, your popups will continue. Boot into safe mode and run Windows Explorer (right click Start and select Explore) . Navigate to C:\windows\system32 and locate those files and delete them.

    I still see CounterSpy in your installed program list. Did you try to uninstall it? What happens when you try to uninstall or do you not even see it?
     
  7. ukkaren

    ukkaren Private E-2

    I don't doubt you're right for a second :) I looked for them in Windows Explorer after I had run the killbox but it was very late so maybe i missed them; I will go do this now and check back later, thanks for helping.

    Counterspy was there and seemed to uninstall ok, and now I can't see it. However everytime I log on to my account I get a windows installer trying to put it back but it doesn't work. I have no idea how I have managed that .. sorry :eek:
     
  8. ukkaren

    ukkaren Private E-2

    :celebrate

    got them!!!!!!!!!! being in safe mode worked, couldn't see the system 32 files in normal at all. NO MORE POP UPS! yay! *hugs* *smooches* all round thanks for that!

    as for the other thing, Counterspy is still there by I got an error message when I tired to uninstall windows installer could not be accessed and not correctly installed so it won't go ... guess it didn't install properly??

    Do I need to do anything else now?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Sunbelt CounterSpy Antispyware
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSBCSSvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but and reboot if it tells you it needs to.
    After reboot, attach new logs from ShowNew and HJT.

    Are you still getting installer messages about CounterSpy? If so, try running the below tool:

    Windows Installer CleanUp Utility
     
  10. ukkaren

    ukkaren Private E-2

    ok done.

    It would appear that Counterspy has now uninstalled and no I am not getting installer messages anymore.

    New files as requested attached.

    PC is running well and have had no pop-ups.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds good!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. ukkaren

    ukkaren Private E-2

    Yep all was going well til the last bit and it appears that there is a problem with the restore. the rundll32.exe seems to be missing but I'm not sure this is the right forum for this problem?

    so I have done all of it apart from the restore.

    Thanks again for your help with this. I will try and be more careful in future!!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may be able to find another copy of rundll32.exe on your PC that you can restore from. Search for rundll32 without the exe and see what you find.
     
  14. ukkaren

    ukkaren Private E-2

    sorted! :)

    thanks again.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds