Help me get rid of pop-ups

Discussion in 'Malware Help (A Specialist Will Reply)' started by Scoosch, Jul 9, 2006.

  1. Scoosch

    Scoosch Private E-2

    I have followed the proceedures on the READ ME FIRST post and have attatched the bitdefender log and the HJT log. I could not get PandaScan to work properly, even in normal boot mode.

    My laptop has multiple pop-ups and has been running very slowly. I have attatched an Everest report as well.

    Thanks in advance for your help in fixing my computer!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Notice how large your Bitdedender log is! That's because you ignored part of step 0 of the READ ME and did not empty your C:\Program Files\Norton AntiVirus\Quarantine as requested. You should do this now for Norton and anything else that may have a quarantine.

    You also did not uninstall Viewpoint Manager in step 0. Did you even do step 0 at all? Please uninstall it now.

    We need to first work on the line in your log with the AppInit_DLLs on it. See the O20 line.

    C:\WINDOWS\System32\logonui.dll

    Start by downloading a tool we will need

    - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.


    Note: In the event you already have Killbox, make sure you check to see that you are using the version in my link above.
    • Save it to your desktop.
    • Please double-click Killbox.exe to run it.
    • Select:
      • Delete on Reboot
      • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\kybrdb_2.exe
    C:\dfndrb_2.exe
    C:\WINDOWS\algm.exe
    C:\WINDOWS\system32\w00804c1.dll
    C:\WINDOWS\system32\w008418c.dll
    C:\WINDOWS\system32\lwinkqez.exe
    C:\WINDOWS\System32\logonui.dll
    C:\WINDOWS\System32\wucrtupd.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If your computer does not restart automatically, please restart it manually.

    If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.


    Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Windows XP-SP2 FW ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    XP-P2FWD

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (note that some of these lines could already be gone due to above steps):
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdb_2.exe
    O4 - HKLM\..\Run: [defender] C:\\dfndrb_2.exe
    O4 - HKLM\..\Run: [vjj81cf4] RUNDLL32.EXE w00804c1.dll,n 00181cf30000000300804c1
    O4 - HKLM\..\Run: [w008418c.dll] RUNDLL32.EXE w008418c.dll,I2 00181cf30008418c
    O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinkqez.exe
    O20 - AppInit_DLLs: logonui.dll C:\WINDOWS\system32\wucrtupd.dll

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
    You still have a Look2Me infection we need to work on.
     
  3. Scoosch

    Scoosch Private E-2

    I'm sorry about step 0. I thought I had taken care of the Quarantined items... I went back into Norton and followed the steps in the link exactly, I also made sure to manually delete the RECYCLER folder as well just to be sure.

    I also didn't realize that Viewpoint was bad. I should have looked at the list more closely. Where does Viewpoint come from?

    Killbox worked great, I had no errors.

    The Windows XP-SP2 FW service was already stopped, I still changed the startup from automatic to disabled and followed your other directions.

    I checked all of the boxes in HJT except for the
    O20 - AppInit_DLLs: logonui.dll C:\WINDOWS\system32\wucrtupd.dll
    line because it has changed to:
    O20 - AppInit_DLLs: wucrtupd.dll logonui.dll C:\WINDOWS\system32\wucrtupd.dll
    I assume that that line will have to be taken care of, but I didn't want to mess with it unless you tell me to.

    Then when I closed all my browsers I hit fix. Everything worked, then I realized that there was a browser window open. Damn pop ups. They usually pop up and don't show up on the bottom of the screen in my taskbar, so I didn't realize it was open. I hope I didn't mess up too bad there.

    I have attatched my new HTJ log, everything seems ok... I'm still getting pop ups, especially one for win antivirus or something similar... I don't usually wait for it to load before I close it down.

    When I restarted my computer it went smoothly, although I noticed that a windows box opened up when everything was closing down, I couldn't read it because it closed as soon as it opened up, and then my computer was shut down... Not sure if that's important.

    Look2Me is still a problem, as Windows Defender reminds me everytime I get on Windows :)

    Thanks for all of your help so far!
     

    Attached Files:

    Last edited: Jul 10, 2006
  4. Scoosch

    Scoosch Private E-2

    Something new... I just tried using Windows Update and when I do it appears to download everything ok, but the installation fails. Windows Update is telling me that there is something on my computer preventing it from downloading or installing. I was wondering if this was related to a problem here, or should I post this problem somewhere else?

    Ugh. Computers.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With any software from AOL. It is junk and mild malware that no one wants or needs and they do not ask your permission to install it.

    Yes you need to fix this still. Follow the exact same instructions and make sure you have Killbox delete those files.

    You are still going to get popup until we finish fixing all your problems. The above is a major one. Now after redoing the above run the below and attach the log that is requested:

    Look2Me VX2 Removal


    Don't worry about Windows Update yet either. It may or may not be a malware issue but you should not be going there right now unless we tell you to. Normally we would not get any updates while infected but sometimes the nature of a problem may require certain updates.
     
    Last edited: Jul 13, 2006
  6. Scoosch

    Scoosch Private E-2

    I followed all of your instructions, used Killbox to delete the files and HJT.

    Look2Me-Destroyer worked great, I've attatched the log.

    Thanks for everything so far!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now attach a new HJT log so we can see where things stand!

    How is everything working right now?
     
  8. Scoosch

    Scoosch Private E-2

    Everything seems to be working okay, I haven't had problems with any pop-ups.

    I've attatched a new HJT log...

    :)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds