I Want to destroy the programmers of popups.

Discussion in 'Malware Help (A Specialist Will Reply)' started by ::dracula::, Apr 18, 2005.

  1. ::dracula::

    ::dracula:: Private E-2

    hello all, Im infected...and dying a slow death.

    your assistance would be very much appreciated. here is my hijack this

    Unrequested inline log removed
     
    Last edited by a moderator: Apr 19, 2005
  2. SGC_Geek

    SGC_Geek Private First Class

    Those who enjoying helping others request you go through the following tutorial entitled

    This provides a baseline for us to help you. Please, inform us of your results.

    Go forth and conquer your demons. :)
     
  3. ::dracula::

    ::dracula:: Private E-2

    thank you very much for the quick reply, I have however spent time going through the steps and I am still infected. I have all the software on there.

    should one of them fixed my problem? It always says it has found the problem... deletes it. Then on a reboot its back. Im have a few issues with some annoying dll popups saying it cant find the nail.exe on startup etc, its a window message.

    any other ideas?
     
  4. SGC_Geek

    SGC_Geek Private First Class

    1. Power down your system and turn it back on.
    2. Run HijackThis as described in the tutorial and save the log file created.
    3. Attach the file to your next post. Do not copy/paste into the post.

    You may need to make some registry modifications after analysis. Are you confortable with running regedit?
     
  5. ::dracula::

    ::dracula:: Private E-2

    hello again, I have completed wht you said and here it is.

    thank you for looking, I am going nuts.
     

    Attached Files:

  6. ::dracula::

    ::dracula:: Private E-2

    Oh, sorry and just quickly,

    Every time i log onto a profile in normal mode i am give 2 windows prompts..

    " An exception occurred while trying to run "c:\WINDOWS\system32\txpmonui.dll",DLLGetVersion "

    and...

    "windows cannot locate the file nail.exe etc..."
     
  7. SGC_Geek

    SGC_Geek Private First Class

    ::dracula::

    Internet Explorer Settings
    ================================
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://yoursearch.ws/browser/ << suspected to be evil.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yoursearch.ws/ << suspected to be evil.
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/

    Use SpySweeper for the following.
    1. Left panel - select Shields
    2. Right panel - select Internet Explorer tab.
    3. Make sure you have the IE Hijack Shield selected and select Edit IE Hijack Shield Settings
    4. Verify the following data:
    SearchURL = http://yoursearch.ws/browser/ /* Change if not correct */
    Start Page = http://www.google.co.nz/
    5. If the data is correct, select Automatically Restore Default Without Notification.
    ***NOTE*** You can use the Advanced Settings to check other items.

    Before proceeding reboot your system into Safe Mode and disconnect your modem cable.

    system.ini
    ============================
    1. Select Start > Run
    2. Type sysedit and enter
    3. Look for the line "Shell=Explorer.exe C:\WINDOWS\Nail.exe"
    4. Delete this line and save the file.

    Registry Items
    ============================
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    O4 - HKLM\..\Run: [MGKGENC] C:\WINDOWS\MGKGENC.EXE
    O4 - HKLM\..\Run: [ILETDLL] C:\WINDOWS\ILETDLL.EXE
    O4 - HKLM\..\Run: [ybyrlf] c:\windows\system32\mdvccwa.exe

    Use your registry editor.
    1. Select Start > Run
    2. Type regedit and enter

    Skip at your own risk.
    a. Select File > Export Registry File ...
    b. Select a location to export the registry to and provide a name.
    c. At the bottom where you see Select Range, select the All radio button.
    This creates a backup of your registry in it's current state. You may safely delete this later
    after all of your problems are fixed.

    3. Navigate the left pane to the full key displayed above.
    4. In the right pane, select the three items and delete them.
    5. Save the registry and exit.

    Questionable Processes
    ================================
    C:\WINDOWS\MGKGENC.EXE
    C:\WINDOWS\ILETDLL.EXE

    1. Locate the files above using windows explorer or by searching for file.
    2. Delete them.
    3. Empty recycle bin.

    Please post your results with a new HJT log created during normal mode.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SGC_Geek,

    Why are you having the user post a HijackThis log and then not using the capability of HijackThis to delete the registry entries automatically. This is much easier. Also HijackThis will make backups of items changed. You are making this more difficult then it has to be. It is much easier and safer to avoid having people use regedit when it is possible to do so.

    Additional notes:
    1) cannot fix nail.exe the way you are recommending!
    2) If you fix registry entries first and then kill the associtated processes later and then delete the files. There is a very good chance for many problems that it will not work. If the process is running when the registry edits are made, they will just rewrite the registry. The correct order is to kill the processes, fix the registry entries (use HijackThis), boot to safe mode and delete the associated files. Is safe mode always needed to delete the files? No, but quite often it is.
    3) You also missed the below:

    O4 - HKLM\..\RunServices: [IPOT USB Service DRIVER] hpsebc087.exe
    O20 - Winlogon Notify: CSCSettings - C:\WINDOWS\system32\irp0l57m1.dll
    O21 - SSODL: DxqAWQpaQ - {5EEC4A4D-F446-E0E7-3487-8D2A790C27F8} - C:\WINDOWS\System32\mvdg.dll

    The O4 line is a Worm! See: http://vic.zonelabs.com/tmpl/body/CA/virusDetails.jsp?VId=42186
    The O20 line may indicate a VX2 Look2Me infection.
     
  9. ::dracula::

    ::dracula:: Private E-2

    hello again,

    I followed the process to destroy this annoying bug and I reached the stage for the sysedit but was unable to do it.. Windows message gave me this response
    "c:\windows\system32\autoexec.NT. the system file is not suitable for running MS-DOS and Microsoft Windows applications. chose "close" to terminate"

    so I skiped this and finished the process.
    is there another way to get in there?

    here is my new hjt log file.

    BY the way, thank you and I am comfortable editing the registry, no problemo
     

    Attached Files:

  10. SGC_Geek

    SGC_Geek Private First Class

    Ok, thanks for pointing it out. Why didn't you take the next step and correctly identify the removal process. I will not apologize for helping people learn how to use tools already on their systems. I agree with you about editing the registry. But, how did you learn? What the user went through has helped. You could have simply made suggestions on items I missed.
     
  11. ::dracula::

    ::dracula:: Private E-2

    yes, thank you thus far for your help, but Im still having pop up problems and was unable to remove the system.ini thing.

    Is there anything else you could suggest that will help, I very much appreciate what you have done so far,

    fagan
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! And HijackThis is already on the system too and it is much easier to use then manual registry editing. And is also safer.

    And how will you learn if I do everything for you? Do a little searching and provide complete fixes. If you cannot figure out how to fix something by doing a little searching than ask for help. If you wish to help, it takes a bit more initiative. I was just tryng to tell you that your fix would not work so you would not waste anytime trying it over and over again. Search the forums and figure it out that's how you will learn.
     
  13. ::dracula::

    ::dracula:: Private E-2

    enough gentlemen,

    Please help me with the issue at hand, either of you please please please.

    Im checking for updates on here every 10mins
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have multiple issues that still need to be fixed. So first let's get rid of nail.exe


    - Click Start > Run and type: cmd and then click OK! This brings up a command prompt window.
    - At the command prompt opens, type the below command and then hit the enter key:

    nail.exe /FullRemove

    Close the command prompt window and reboot and post a new HJT log attachment.
     
  15. ::dracula::

    ::dracula:: Private E-2

    no can do,

    says...

    "nail.exe" is not recognized as an internal or external command,
    operable program or batch file"
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you complete the previous procedure, continue with the below steps.

    Download L2MeFix Tool

    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the READ ME FIRST tutorial.

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Now reconnect and come back here and post the l2mfix log as an attachment.

    Please DO NOT REBOOT after posting!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is nail.exe still on your PC? Look in C:\windows and C:\windows\system32

    It should be in c:\windows
     
  18. ::dracula::

    ::dracula:: Private E-2

    not there,

    prob why i get the windows pop up message on start up

    "windows cannot find nail.exe etc...
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! The do the below. A couple of the DLL's I point out in the O20 and O21 lines may come back with different names (that is why I mentioned the VX2 Look2Me infection.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://yoursearch.ws/browser/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yoursearch.ws/browser
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yoursearch.ws/
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
    O4 - HKLM\..\RunServices: [IPOT USB Service DRIVER] hpsebc087.exe
    O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\enpsl1771.dll
    O21 - SSODL: DxqAWQpaQ - {5EEC4A4D-F446-E0E7-3487-8D2A790C27F8} - C:\WINDOWS\System32\mvdg.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\hpsebc087.exe
    C:\WINDOWS\System32\mvdg.dll
    C:\WINDOWS\system32\enpsl1771.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  20. ::dracula::

    ::dracula:: Private E-2

    Ok,

    still getting popups, but have done the procedure you requested. however i was unable to find the hpsebc087.exe file and enpsl1771.dll file. I checked everywhere and did a search for them... no luck.

    Here is the 2 files you asked me to upload.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are not done yet! That's why you still have popups!

    Did you fix this: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yoursearch.ws/browser

    Or did you decide to keep it?

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log to your next message and also post another HJT log.

    Again, don't run any other files in the L2MFix folder.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The reason you could not find enpsl1771.dll is because it changed names as I mentioned would happen earlier if your system was rebooted. It is now C:\WINDOWS\system32\ir22l5fo1.dll and my last procedure should help remove it.

    The hpsebc087.exe may be superhidden or HJT removed it while fixing the O4 entry!
     
  23. ::dracula::

    ::dracula:: Private E-2

    ok,

    I have attached the 2 new files, But i was unable to find that file in the system32 folder. it seems as if the winlogon thing is gone now though...

    well your the expert..
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were not suppose to find it. That was the reason for running the L2MeFIx.

    Now run HijackThis and see if you can fix the below line:

    O21 - SSODL: DxqAWQpaQ - {5EEC4A4D-F446-E0E7-3487-8D2A790C27F8} - C:\WINDOWS\System32\mvdg.dll (file missing)

    Then I would expect that you are clean. No more popups now....right?
     
  25. ::dracula::

    ::dracula:: Private E-2

    Im getting the vibe from my computer that there are no pop ups, LIfe is good.

    I want to head to one of those sites and brag about how major geeks squashed their little bug.


    Thanx heaps for you assistance, if you ever need singing lessons, come to new zealand and i will give you some for free :)
     
  26. ::dracula::

    ::dracula:: Private E-2

    This sux, they are still hanging around, its just not as bad.

    What else can i do??? are you sure my hJT is clean?
     

    Attached Files:

  27. ::dracula::

    ::dracula:: Private E-2

    I got some nasty piece of adware that installed a bunch of crap on my system and the only thing remaining now are two pop-ups that seem to come up randomly every 10 mins or so.. from 9ringtone.com and various ads from bundleware.com.

    I'm pretty sure it's using RunDLL32.exe

    So far I've run Ad-Aware, Spybot, trendmicro virus scan, pandascan, registry cleaner... I've also gone into my windows folder and deleted bad files, cleaned out registry keys manually, cleared my history/cookies/temp internet files - windows temp files... So I have no idea where this last piece of junk is that is making these ads pop-up. Nothing else is trying to be downloaded, so I'm pretty sure I got everything except one or two files.

    Anyways... if Anyone has some info on similar problems and can help me solve this, please let me know.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your last log was still clean. I would recommend two things, one of which needed to be done anyway:

    1) disable Windows Messenger using: Disable/Remove Windows Messenger

    2) complete all the steps in the following link. You definitely need to add a software firewall (like Sygate) and disable the one built into Win XP SP since it does not provide sufficient protection:

    How to Protect yourself from malware!
     
  29. ::dracula::

    ::dracula:: Private E-2

    there has to be something else i can do,

    when i do a search for 9ringtone i see a bunch of people with the same problem but no solution.

    sigh
     
  30. SGC_Geek

    SGC_Geek Private First Class

    ::dracula::

    I have been watching on the sidelines. Have you stopped the messenger service as suggested by Chaslang?

    I haven't found anything useful for the ringtones popup.
     
  31. ::dracula::

    ::dracula:: Private E-2

    yeah, but no luck

    the firewall works - zone alert but i really want to kill the pop ups, its working through the rundll file thing suggested earlier.

    I have read alot of search info on the 9ringtone etc and nothing seems clear... have you any ideas?

    I still want messenger to run on my PC
     
  32. SGC_Geek

    SGC_Geek Private First Class

    My suggestion: Don't run the messenger service unless required by network administrators at your office. The messenger services opens you to unwanted solicatations. You can always turn it on when you need it. The main idea behind the service is to allow administrators to request users to disconnect from network resources as needed for repairs, updates, etc.

    On the open internet, it is better to use other communication tools.
     
  33. ::dracula::

    ::dracula:: Private E-2

    is there a way to clean the dll file? I suppose i cant delete it
     
  34. SGC_Geek

    SGC_Geek Private First Class

  35. ::dracula::

    ::dracula:: Private E-2

    ok ok i read it, but it didnt help me to destroy this annoying bug.

    here is the usuall link
    http://www.loadingwebsite.com/normal/yyy47.html

    either that or the 9ringtone, Im sick of it and every time it comes up I feel like smashing the PC. I just dont want them (bastards) to win.

    We must be victorious, the demons are winning here.
    we won the battle but they are about to win the war.....PLEASE ANYTHING ELSE.
     
  36. SGC_Geek

    SGC_Geek Private First Class

    Let's agree you were clean at the point you made the comment, Im getting the vibe from my computer that there are no pop ups, LIfe is good.

    Please post a new HJT log per Chaslangs instructions to see If something new is there.
     
  37. ::dracula::

    ::dracula:: Private E-2

    I spoke too soon, sorry. We did however fix lots of problems, but these other ones seem like they are on a timed basis.

    however I notice some things are popping back up like the yoursearch thing, It wont die

    here is the new log
     

    Attached Files:

  38. SGC_Geek

    SGC_Geek Private First Class

    Because of what we did with SpySweeper, this item is possible being reset.
    Main,Default_Page_URL = http://yoursearch.ws/

    You need to go back to SpySweeper and modify the items there.
     
  39. SGC_Geek

    SGC_Geek Private First Class

    Wait for Chaslang to take a look at your new log. It still looks clean minus the settings in SpySweeper that need to be changed.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I just jump in for a second! I'm pretty busy but I'll keep checking back. Here are a couple things I want to look at:

    Generate a StartupList log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.


    Download: "StartDreck", from here:
    http://www.niksoft.at/_data/startdreck.zip

    Unzip to its own folder and start the program,
    Press 'Config'
    Press 'Unmark All'
    Check the following boxes only:
    Registry -> Run Keys
    System/drivers> Running processes
    Press 'Ok'
    Press 'Save' and select the location to save the log file
    (default is the same folder as the application)

    Please attach the log in this thread.
     
    Last edited: May 20, 2005
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also, look in Add/Remove programs. Do you see any of the below or similar names:

    Ad Behavior
    ShopAtHomeSelect Cash Back


    Now perform the steps below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post both logs as attachments.
     
  42. ::dracula::

    ::dracula:: Private E-2

    thx, post one here you go
     

    Attached Files:

  43. ::dracula::

    ::dracula:: Private E-2

    I remember at some stage seeing those in my programs folder, They are gone now however. Its weird cos no spyware is picking up problems on my PC and I have the zone alert thing on and everything. There is drips and drabs of info on the net but nothing is clear. I have even downloaded the wintask pro thing... no luck. This sucker is getting through somehow.
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I asked for a HijackThis StartUpList log not a HijackThis log. Take a look at my directions again. Don't forget the StartDreck log.

    Did you just download and install the below? If so, uninstall it. It was on a list of rogue/suspect spyware removal tools for quite some time. They no longer classify it as a rogue but it is not very good.
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was a bad idea:
    O4 - Global Startup: WinTasks.lnk = C:\Documents and Settings\Rip thort of Pig\Local Settings\Temp\Temporary Directory 1 for cracked.zip\wintasks.exe

    Downloading cracks for software can put worse problems then we have been fixing onto your PC.
     
  46. ::dracula::

    ::dracula:: Private E-2

    remove?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it is not a legit copy that you purchased, yes remove it.
     
  48. ::dracula::

    ::dracula:: Private E-2

    I put the wrong ones up sorry, here ya go
     

    Attached Files:

  49. SGC_Geek

    SGC_Geek Private First Class

    Rip Thort of Pig,

    Kinda like that. I never suggested downloading Wintask. I only pointed you to information regarding RunDLL32.exe.
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can find the below file:

    C:\WINDOWS\system32\brxcrod.exe

    This seems suspicious to me. You can right click on in and select Properties and then the Version tab to see if we can get more info on it. If there is no Version tab, then right click on it and select Rename. Change the name to brxcrod.xxx. Then reboot your PC and let's see what happens. You may need to do this in safe mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds