I'm still getting pop-ups after the removal procedure

Discussion in 'Malware Help (A Specialist Will Reply)' started by blast7, Apr 22, 2006.

  1. blast7

    blast7 Private E-2

    I followed the procedure for removal and while the freqency of pop-ups has decreased they are still present. I have attached the appropriate files per the procedure stickied.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please run the below procedure and attach the requested log.

    Look2Me VX2 Removal

    Then run the new E2Give procedure below

    E2Give Removal Procedure

    Attach the C:\avenger.txt log and then a new HijackThis log.
     
  3. blast7

    blast7 Private E-2

    Thanks for the guidance so far! I can't believe I never knew about this site before. What a wealth of knowledge. Here are my attachments from the above procedures.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - -{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [Sen] "C:\PROGRA~1\WNSXS~1\wuaclt.exe" -vt ndrv
    O4 - HKCU\..\Run: [Paxvpg] C:\WINDOWS\?ymbols\arpa.exe
    O4 - HKCU\..\Run: [wowpmo] C:\WINDOWS\system32\wowpmo.exe
    O4 - Global Startup: strings.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O15 - Trusted Zone: *.media-motor.net
    O15 - Trusted Zone: *.mmohsix.com

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\WNSXS~1\wuaclt.exe <--- you will have to figure out what WNSXS~1 is the abbreviation for. Tell me what you find.
    C:\WINDOWS\?ymbols\arpa.exe <--- you will have to figure out what ?ymbols is the abbreviation for. Tell me what you find.
    C:\WINDOWS\system32\wowpmo.exe
    C:\WINDOWS\SYSTEM32\mmxp2passion.exe
    C:\WINDOWS\optimize.exe
    C:\WINDOWS\pop06ap2.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. blast7

    blast7 Private E-2

    I can't thank you enough. Here is the information you were curious about.
    -WNSXS ~1 was a folder inside of the folder WinSxS.
    -?ymbols was actually the folder titled symbols.
    The one thing downside, although I'm not sure if this is bad or not, is that there was no wowpmo.exe to delete. I even searched for it with no results found. So far I have not had one pop-up but sometimes it takes some time. I have attached my HJT log. Thanks again!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My steps are a secondary check. Bitdefender removed it earlier but the line was still in HJT so I was double checking to make sure it did not come back.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  7. blast7

    blast7 Private E-2

    Thanks! I do have one question on the procedure for protecting myself. I put the script in the run box and when I clicked okay a message came up stating my comp could not locate my INF java file. I do have sun java installed but does that mean my old java is gone? Can I uninstall at the control panel?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What script and in what run box are you referring to? Are you talking about step 8 with uninstalling Microsoft Java?

    You do not have MS Java installed so there is nothing to uninstall.

    You are already running Sun Java and it is the current version.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds