IE Forced Pop-Ups/Rebooting Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by mutant, Oct 6, 2006.

  1. mutant

    mutant Private E-2

    Hi, I have followed the steps in the Read & Run Me First
    and currently have reached a problem at Step 5, preventing me from proceeding.

    Microsoft Windows Defender - After installing it it said my definitions haven't been updated in 254 days and need to be updated.

    The problem here is that whatever malware I currently have is
    rebooting my computer after about 10 minutes online.
    I am on dialup, so when I try to update my defender definitions through the programs interface, it appears to be downloading the definitions (although there is no download status bar etc.) but after about ten minutes online my computer reboots and I am unable to complete the definitions update download.

    I therefore did a Scan using defender in Safe Mode yet it apparently did not detect anything. However when I looked under Tools -> I saw the following startup obvious malware which I have disabled but not yet deleted:

    See Attached Text File-



    My problem history is as followed: I initially had the Red Pop-Up 'Phony' Virus task Bar warning Malware which stated how 'my computer is infected and I need to download Antimalware' etc. I ran SmitfraudFix and it seemed have to removed that.

    Yet I still keep getting pop-ups and my computer keeps rebooting and constantly trys to connect to the internet.
    I cannot update my definitions for defender or anything and will be unable to scan online because of this rebooting/popup/forced-connection malware issue.

    Is there possibly a way to manually download and install the latest Defender definitions?
    However since it didnt detect anything yet without them anyways I doubt it would find something new with them updated anyways.


    I am just trying to look for help or advice as to which direction to possibly procede on with.

    I currently have no anti-virus software - I used to have AVG free
    but since recently upgrading to WIn XP I cannot run it. Therefore I am now going to re-download it again using another computer and save it to my external drive (hopefully along with any manually downloaded AVG Free updates) THEN install it on my infected computer.

    At this point basically my issue is the popups and forced connections and the forced rebooting issue.
    I am unable to stay online long enough to download any updates for virtually any scan software or also even attempt to scan online due to this.

    Any advice is GREATLY appreciated.

    Thank you very much everyone.
     

    Attached Files:

  2. mutant

    mutant Private E-2

    Hi again, I just wanted to update my issues:

    I managed to remove several trojans and viruses using the AVG Malware scan software. These were not detected by anything until this software did so. It seems as though my system is stable now as the recurrent popups and forced connecting as well as forced rebooting, has appeared to stop for the time being. Therefore as per the instructions here I toggled Restore points and rebooted . I am now going to download the additional AVG FREE Anti-Virus software as well.

    However, in searching the web for one of named trojans/viruses which the AVg Malware scanner found, I came across what sounds like a rather serious one found on my system among sevral other (no quarintined) : Hijacker.small

    From reading the Mcaphee forum it appears as though this is whats known as a rootkit type of virus which apparently puts a driver in the device manager which allows the virus to return.

    Perhaps if anyone may be familair with this one they may offer some information. On the Mcaphee forum they are suggesting that one needs to go into the device manager and remove or disable this driver which allows the virus to return on a timed basis each week.

    So for me now my system appears to be stablizing, but I would like to keep this thread open just in case someone may reply or offer any further advice.


    Thank you.
     
  3. mutant

    mutant Private E-2

    Hello again.

    Although since my last post I removed several Trojans and Viruses using AVG Malware Remover and although upon startup the forced connection prompts to the Internet have seemed to have stopped, upon attemtping to go online I soon got a taskbar icon and popup leading me to some phony anti-spyware site.

    Upon immediatley disconnecting from the internet I have discovered more malware. I have now also used SYSINTERNALS autoruns and process explorer and have found and currently disabled items such as ishost.exe which apparently is termed 'SpywareQuake'. However the previously used tool AVG Malware scanner: is not finding this. I also ran SmitFraud Fix and although it said it detected and removed ishost.exe and another similairly named imon.exe or something, ishost.exe appears still present as located by SYSINTERNALS autoruns and process explorer so I dont know if SmitFraud Fix actually has removed this aspect.

    As I have mentioned in my last post I beleive that according to some of the initial items AVG Malware Scanner found such as 'Hijacker.small' that I most likely suspect I have some type of 'rootkit' virus here which is re-downloading more malware as soon as I go online.

    Therefore I am now currently trying to use the instructions located here: http://forums.majorgeeks.com/showthread.php?t=88420 to hopefully remove this SpywareQuake aspect (ishost.exe) as i understand it.

    Again if anyone may ever find a moment here to offer any advice I would greatly appreciate it.

    Thank you.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Apparently you did not run SmitFraudFix properly.

    I'm going to post two messages! This is the first! Complete this procedure completely including attaching the requested log before doing the second procedure.

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is my second message. Make sure you have follow the first procedure before doing the below.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.


    At this point if you are still have problems, you will need to run the below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  6. mutant

    mutant Private E-2

    HI, thank you for your help. l will follow the R&R steps and post the logs as asked. However I am concerned that when I go online to to do any definition updates of the various programs as well as the two online scans that whatever Malware possibly still on my system at that point will breed and download even more. This due to the fact that i am on dialup and everything takes a long time. A long time to download the ACtive x required for online scanning as well as any time it takes to do any aforementioned definition updates for the various programs. Initially my computer was rebooting after ten minutes online due to the Malware. However although I 'think' that symptom seems to have been removed from some of the previous scans.

    But I appreciate the help sincerely and will follow the steps completely and post my logs hopefully soon or report of any problems I may have reached in attempting to complete them all.

    Again, thank you.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about getting malware! That s why we are here. We will fix anything you get. Make sure you run the SmitFraudFix procedures and attach the logs from it. You must attach the one in message number 4 before you start message number 5.
     
  8. mutant

    mutant Private E-2

    Hi, I have followed the steps. Attached is:

    1.) SAFE MODE SmitFraudFix Search
    2.) Normal Mode SmitFraudFix Clean
    3.) Bitdefender Online Scan

    Notes: None of these really found anything. Bitdefender- Only found quarintined stuff from both my AVG FREE Antivirus & AVG Anti-Spyware.

    However - Spysweeper reports:
    Adware found: enbrowser
    Adware found: ezula ilookup
    Adware found: trafficsolution
    Adware found: rx toolbar
    Adware found: cydoor peer-to-peer dependency

    Yet I have to purchase Spysweeper to have it remove these. Also AVG Anti-Spyware claimed to have already removed 'rx toolbar'.

    Also- In my System32 folder I notice the following bad things:
    awvtq.dll,awtss.dll,cd_clint.dll,ddccb.dll,jrs531b0.sys,mlnmp.ini
    mllmj.dll,mllmm.dll,rqtss.ini,sttss.ini,sstts.dll,sstwa.ini,wrlzma.dll

    I have tried two different versions of 'Vundo Fix' I believe, running these from C:WIndows/ -One simply has a button Stating 'Search for Vundo' - It removed a dlll named winn32.dll etc? The other Vundo Fix asks for you to enter the absoulute path to the bad System32 .dll then enter its file name again backwards then opens Hijack this- where you are to then see the dll entry mark it for fix -reboot then open Hijack This again and remove it?
    I used this second Vundo tool to succesfully remove two dlls from the system32 folder named 'jkkjj.dll and jkkgg.dll' etc. Upon reboot they WERE removed yet i never saw any corresponding entry in Hijack this for them.

    I also now have several programs loading for startup space: AVG antivirus, Avg Anti Spyware, Spyseeper, Windows Defender, Zonealarm.

    My system appears extremly slow upon startup, with often times the flashlight icon searching as i even attempt to open START/Control Panel etc.

    Each of these programs have a 'Resident shield' and I am wondering if they are collectively slowing startup down? Also When I click on the desktop icon for IE6 it takes nearly 30 seconds before loading very very slowly.

    Also Defender had no new updates yet claiming they were 245 days old.
    I scanned, it removed a 'Twain' Trojan.

    In Defender under Startup Tools- It lists among other things -
    Startup Value: RUNDLL32.EXE w007415c.dll,n 005531ab00000002007415c
    Startup Value: C:\WINDOWS\win3206513940513.exe
    Startup Value: "iexplore.exe" "http://iesettingsupdate"
    Startup Value: C:\WINDOWS\elitepop06.exe
    Startup Value: "C:\Program Files\Common Files\{380F18E9-063F-1033-0217-060314050001}\Update.exe" mc-110-12-0000272


    Which I have disabled yet not delted in Defender/Startup. I think previous scans/fixs that i have already removed most of these- elitepop.exe,win32065 etc.

    I also have sysinternals.com Autoruns-
    It lists these startup items which i have also disabled-
    ishost.exe File not found: ishost.exe
    Power Policy Settings File not found: setupx.dll
    Display Panning CPL Extension File not found: deskpan.dll
    Tune-up Application Start.job File not found: walign
    gel90xne File not found: C:\DOCUME~1\mutant\LOCALS~1\Temp\gel90xne.sys
    viagfx File not found: system32\DRIVERS\vtmini.sys
    rqrrqop File not found: rqrrqop.dll


    Again, thank you very much for any help.


    View attachment SAFEMODESCAN2CLEANMODErapport.txt

    View attachment NORMALMODESCAN1rapport.txt

    View attachment BITDEFENDER.txt
     
  9. mutant

    mutant Private E-2

    Here are the rest of my reports, I was unable to correctly load PandaScan as it came back with a browser error with ; Page cannot be loaded- interface/component-something' etc I enabled Active X and have Installed Java 5.0

    Thank you
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall this free version of Spy Sweeper since it will only get in our way an is of no use to you. Do this now before continuing unless you plan on buying it?

    Without the logs from VundoFix, I have no comment.

    We already said to uninstall Spy Sweeper (unless you are going to buy it). Since AVG AntiSpyware is only a scanner (unless you BUY it), it will not provide any active protection, so you can either keep it as an addition scanner or uninstall it. That's up to you. You do need active antispyware protection, and the only program you have that does this is Windows Defender.

    Uninstalling Spy Sweeper and AVG Antispyware will speed things up.

    SUGGESTIONS!!!! :
    1. Cleanup all the junk out of your root folder (C:\ is the root folder). Why is all this stuff here? Malware likes to hide in this folder and you are making it very easy for a malware file to hide in this long list of files in the root folder.
    2. The same as item 1 but for your Desktop! Cleanit up and save things elsewhere. A cluttered Desktop is a haven for malware. DO NOT save EXE and ZIP files on your Desktop as a long term storage. Save them in appropriate folders for Downloaded files or similar. Give them folder names that make sence.
    The two items above are making much more difficult and time consuming than it should be to read your logs and figure out what is good and what is bad. Normally I would just tell a person to delete all that junk because if it was important, it would not be save in places like this.

    You did not install the version of Spybot as requested in the READ ME. You are using a version of Spybot that has not been used in 2 years. Uninstall Spybot - Search & Destroy 1.3, reboot, and then install the proper version from the READ ME. Follow the directions given in the READ ME.

    You are also using a very out of date FireFox. Uninstall Mozilla Firefox (1.0.2) and then install the current version of FireFox from: Mozilla Firefox

    Did you install the below programs like this? This is not an acceptable way to run programs. They should not be install in Temp folders!! Delete them/stop them from loading etc. If you need them, then install them and run them properly.
    F:\NEWSCAN\LOGS\New Folder\drweb-cureit.exe
    C:\DOCUME~1\mutant\LOCALS~1\Temp\RarSFX0\_start.exe

    The second one from above actually looks like a Worm and my fixes below will delete it.

    Did you put the below proxy settings on your PC yourself?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8088
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = dynhost.inetcam.com;register.inetcam.com

    Start by downloading two tools we will need- Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\asdf.txt
    C:\WINDOWS\SYSTEM32\justin.exe
    C:\WINDOWS\SYSTEM32\adrot-uninst.exe
    C:\WINDOWS\SYSTEM32\ssqpn.dll
    C:\WINDOWS\SYSTEM32\awvtq.dll
    C:\WINDOWS\SYSTEM32\mllmm.dll
    C:\WINDOWS\SYSTEM32\sstts.dll
    C:\WINDOWS\SYSTEM32\pmnlm.dll
    C:\WINDOWS\SYSTEM32\ddccb.dll
    C:\WINDOWS\SYSTEM32\mllmj.dll
    C:\WINDOWS\SYSTEM32\awtss.dll
    C:\WINDOWS\SYSTEM32\qtvwa.ini
    C:\WINDOWS\SYSTEM32\mlnmp.ini
    C:\WINDOWS\SYSTEM32\sttss.ini
    C:\WINDOWS\SYSTEM32\rqtss.ini
    C:\WINDOWS\SYSTEM32\sstwa.ini

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete it if found:
    C:\Documents and Settings\mutant\Local Settings\Temp\RarSFX0

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\mutant\Local Settings\Temp\

    Now attach a new HJT log and tell me how the steps went.
    Also attach a new log from ShowNew and a new log from GetRunKey.
    Make sure you tell me how things are working now!
     
    Last edited: Oct 11, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds