I Want to destroy the programmers of popups.

Discussion in 'Malware Help (A Specialist Will Reply)' started by ::dracula::, Apr 18, 2005.

  1. ::dracula::

    ::dracula:: Private E-2

    strange, its not there, or any where to be found.

    Also im on DSL but getting these weird dial up connection prompts. But all requesting i dial up with my old dial up connection.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please double check that you have the below options set:

    Right Click Start.
    Select Explorer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.

    Then look for the file again. Also look for the below files and answer the question in red:
    C:\Windows\system32\locate.com
    C:\Windows\icont.exe
    C:\Windows\tsc.exe Did you ever download Trend Micro's System Cleaner?
    C:\Windows\ukogaaqdf.exe
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ooops! One more that I wanted you to look for:
    C:\DOCUME~1\RIPTHO~1\LOCALS~1\Temp\_iu14D2N.tmp
     
  4. ::dracula::

    ::dracula:: Private E-2

    yeah the files have been un-hidden for a while.

    plus i have all the files you stated.

    I have gone through the trend micro scan etc...

    I will await your command.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was not my question. My question is not about the online scanner. It is about Trend Micro's System Cleaner . That's a different tool.

    I'm going to assume you did not download it.
     
  6. ::dracula::

    ::dracula:: Private E-2

    oh, sorry no I didnt.

    I can if you want. But I wait.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rename the following (use safe mode if necessary)
    C:\Windows\system32\locate.com to locate.ccc
    C:\Windows\icont.exe to icont.xxx
    C:\Windows\tsc.exe to tsc.xxx
    C:\Windows\ukogaaqdf.exe <--- delete this one if it lets you otherwise rename to ukogaaqdf.xxx
    C:\DOCUME~1\RIPTHO~1\LOCALS~1\Temp\_iu14D2N.tmp <--- delete this one if it lets you!

    The reboot into normal mode and tell me the results of the above. Double check to make sure they are still renamed (or deleted). Any improvement in popups?
     
  8. ::dracula::

    ::dracula:: Private E-2

    C:\DOCUME~1\RIPTHO~1\LOCALS~1\Temp\_iu14D2N.tmp

    this one could not be found.
    C:\Windows\tsc.exe - as for this puppy, it seemed to be in quite a few places. in prefetch folders etc.


    have to wait a bit to see if the pop ups disappear. let you now in 10
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So you were able to rename or delete all the others except the _iu14D2N.tmp file?
    Did you reboot?
     
  10. ::dracula::

    ::dracula:: Private E-2

    ok,

    i have rebooted, and re checked all file names,

    they are still how i changed them and the file still cannot be found.

    the pop ups remain.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are all the popups from one address?

    Please do the below:
    1) go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me exactly what you see in the Value field:
     
  12. ::dracula::

    ::dracula:: Private E-2

    think i found a weird folder in the program files the name is

    folder name = 81u7acxb

    79983450.exe IEhook

    there is 1 other file called control.dat


    beats me what it is. also is there a easy way to uninstall the wintask eg dos?

    I cant find a uninstall or in the add/remove
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    IEhook is a keylogger. Delete that folder and any files in it.

    How did you install wintask? If installed, it should have an uninstall in Add/Remove programs. But since it does not we may have to use HJT to fix the registry entry and then delete the file.
     
  14. ::dracula::

    ::dracula:: Private E-2

    says "value not set"
     
  15. ::dracula::

    ::dracula:: Private E-2

    ok will use HJT,

    I should be able to work out the process
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should dump SpyHunter too.

    Have you run Microsoft® Windows AntiSpyware yet! If not download it, install it, and update it. Then run a full system scan. Let me know if it finds anything. If that does not help, try the following:

    Download this virus checker and tool from eScan Mwav.exe (Use Download Link 3)

    1. Save it to a folder.
    2. Reboot into safe mode
    3. Double click the Mwav.exe file.(This is a stand alone tool and NOT just a virus checker......so it won't install anything)
    4.Select all local drives, scan all files, press SCAN and when it is completed, anything found will be displayed in the lower pane.
    5. In the Virus Log Information Pane......
    Left click and Highlight all the info in the Lower pane--- Use "CTRL C" on your Keyboard to copy all found in the lower pane and save it to a notepad file

    *Note* If prompted that a Virus was found and you need to purchase the product to remove the malware, just close out the prompt and let it continue scanning.

    We just want to use it to try to identify anything that is bad.

    Once you copy that to a notepad file, highlight the text and copy as an attachment.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just to keep you going (I have to disconnect - need sleep). After doing what was in my previous message. Do the below:

    Please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Exit all browser sessions and then run the below steps
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Now let me know if there is any change.
     
  18. ::dracula::

    ::dracula:: Private E-2

    I have both and have run them but will do again to see what happens. brb
     
  19. ::dracula::

    ::dracula:: Private E-2

    I ran both the programs and it said in microsoft antispyware that there was a possible browser hijack but had no info on it.

    I will post 2 logs from the mwave scan. one is the proper log, the other is just the virus log i copied into notepad.

    good luck and thanks thus far.
     
  20. SGC_Geek

    SGC_Geek Private First Class

    Chaslang,

    Earlier you had ::dracula:: rename tsc.exe to tsc.xxx. I also have the tsc.exe file on my system. You get it as part of the download required to run Housecall.

     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you read message number 52?

    That was the reasoning behind renaming it rather than deleting it. There are also malware files named tsc.exe. We can check the properties on the file later and rename it back to tsc.exe if it belongs to Trend Micro (which it this case it probably does).
     
    Last edited: Apr 21, 2005
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not post any logs! Did you run Hoster?
     
  23. SGC_Geek

    SGC_Geek Private First Class

    Did you read message number 52 and 55?

    Yes, I did.

    The following files are delivered in hctsc.zip
    tsc.exe
    tsc.ini
    tsc.ptn
    hcextoutput.dll
     
  24. ::dracula::

    ::dracula:: Private E-2

    Hello there, sorry for the slow reply.

    Here I have a virus scan log for you from the mwave scan, and a new HJT log.

    I have returned to find my entire desktop covered in shorcuts to casinos and antispyware. No worry we will get there.

    Here are the new logs gentleman, oh and yes I have used hoster but there seems to be new hosts everytime i run it. :(
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not post the log from Mwav.exe .
    What address are appearing in your hosts file?

    What did Microsoft Antispyware find? Did it fix what it found?

    You have a firewall from Zonelabs and you have Symantecs AV.
    But exactly what do you use C:\Program Files\ewido\security suite\ewidoctrl.exe for.
     
  26. ::dracula::

    ::dracula:: Private E-2

    ok, the log seems always too big so i just copied the virus log info onto notepad for you. sorry been at a funeral but back now.
     

    Attached Files:

  27. ::dracula::

    ::dracula:: Private E-2

    that is another security thing, its safe. I have like 3 on there now.
    as for the hosts file here you go...

    attached is the host file
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you post that log with carriage returns so it is readable.

    What is in the rest of the log that makes it too big?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also please download the following tool: L2MeFix Tool

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Now come back here and post the l2mfix log as an attachment.

    Please DO NOT REBOOT after after posting this log!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.

    I know we did this back in message #16 but you appear to have some of those problems back again.
     
  30. ::dracula::

    ::dracula:: Private E-2

    L2me fix tool.

    here you go, but i get a 16bit dos subsystem error when running it... dont know what it means but it spits out the report anyway.

    I have fixed up the mwave log a little. but yeah the original log is 12mb big.
     

    Attached Files:

  31. ::dracula::

    ::dracula:: Private E-2

    I keep getting interupped with my dail up connection even when my dsl is connected. does this have anything to do with it do you think?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean? Why are you using dial-up and DSL at the same time?


    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log to your next message and also post another HJT log.

    Again, don't run any other files in the L2MFix folder.
     
  33. ::dracula::

    ::dracula:: Private E-2

    I have a dial up account on the computer but dont use it, some times i am on google and it just pops up. dont know why.

    here is the logs you requested though :)
     

    Attached Files:

  34. ::dracula::

    ::dracula:: Private E-2

    Microsoft Spyware Scan Details
    Start Date: 28/04/2005 1:51:58 PM
    End Date: 28/04/2005 1:57:29 PM
    Total Time: 5 mins 31 secs

    Detected Threats

    Unclassified.Spyware.61 Spyware more information...
    Status: Removed
    Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

    Infected files detected
    C:\Windows\system32\Cache\mgsSetp.exe
    C:\Windows\system32\Cache\mswinstall.exe
    c:\windows\iletdll.exe
    c:\windows\mgkgenc.exe


    Possible Browser Hijack Browser Modifier more information...
    Details: Possible Browser Hijack redirects Internet Explorer.
    Status: Removed
    High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.


    Begin2Search Browser Plug-in more information...
    Details: Begin2Search installs third party spyware, displays pop-up advertisements, and redirects Internet Explorer.
    Status: Removed
    High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

    Infected files detected
    C:\Windows\system32\Cache\tool5-fran-one.exe
    c:\windows\system32\nsx591.dll


    Detected Spyware Cookies
    No spyware cookies were found during this scan.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! L2MeFix delete a load of bad stuff.

    Now run Hoster again and make sure that this time the bad lines do not come back.

    Now boot into safe mode and make sure viewing of hidden & system files is enabled.
    Now run Windows Explorer and delete the below files:
    C:\WINDOWS\icont.exe
    C:\WINDOWS\icont.xxx
    C:\WINDOWS\iconu.exe
    C:\WINDOWS\wnunan.exe
    C:\WINDOWS\system32\advapi32.exe
    C:\WINDOWS\system32\hletcfg.dll
    C:\WINDOWS\system32\Process.exe
    C:\Windows\system32\Cache\mgsSetp.exe
    C:\Windows\system32\Cache\mswinstall.exe
    c:\windows\iletdll.exe
    c:\windows\mgkgenc.exe
    C:\Windows\system32\Cache\tool5-fran-one.exe
    c:\windows\system32\nsx591.dll

    Then reboot an post a new HJT log and tell me how things are working.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must have something setup in your connections to dial a connection.
     
  37. ::dracula::

    ::dracula:: Private E-2

    seems to be working better now, the odd pop up but very few and far between.

    Here is the latest HJT what do you think?
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  39. ::dracula::

    ::dracula:: Private E-2

    Hello again,

    I just would like someone to check my HJT one last time to see if there are any infections as my noadware picked up some vx2 infections.

    thank you
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis logs do not show everything that could be on your PC. They only show certain registry locations that it was designed to look at. It would be much more useful to us if you told us exactly what NoAdware is finding (the filenames and paths or registry keys). It has been known to give false detections. Do any other scanners detect it? Did you buy NoAdware? If so, does it fix the problems it reports? If it does not fix them and you bought it, ask them why not.

    You should check out the below two programs. They are much better and will fix problems. Sometimes a safemode scan is better.

    Microsoft® Windows AntiSpyware
    Spy Sweeper
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds