internet explorer pop ups out of no were

Discussion in 'Malware Help (A Specialist Will Reply)' started by valesspot, Mar 28, 2007.

  1. valesspot

    valesspot Private E-2

    hello, i have followed all procedure from READ & RUN ME FIRST list to clean my computer from any malware. i have included the following post below to be examined. i will appreciate anyu help i can get here. thank you


    i have not yet run HijackThid log file but if its neccessary please let me know and i will post this next.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must attach all of the logs requested in the READ ME. You are missing the below logs (but don't post them yet, read the whole message):
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
    However before getting the above logs, please run this: Virtumonde aka Trojan Vundo Removal

    Then attach the log from VundoFix along with the above 3 requested logs.
     
  3. valesspot

    valesspot Private E-2

    Hello, and thank you for your help. well i have followed the previews instructions and i have the new file that u have requested. please let me know what else i need to do.

    The Trojan Vundo Remover file will be in my next post.
     

    Attached Files:

  4. valesspot

    valesspot Private E-2

    This is the VundoFix File Below.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You missed part of Step 0 and part of step 6 in the READ & RUN ME. The below should take care of this.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 2
    Java 2 Runtime Environment Standard Edition v1.3.1_04
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now let's continue by removing a malware service.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to ieupdater21
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteMicrosoft IEUpdater21 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
    O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
    O2 - BHO: (no name) - {150bda0f-76d4-453c-9e82-63058c0dde6a} - C:\WINDOWS\system32\digmem.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [cds] C:\Program Files\cleardisk\cds.exe
    O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\System32\lsasss.exe
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\nnkiff.dll",setvm
    O4 - HKLM\..\Run: [syswin] C:\WINDOWS\v6.exe
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\System32\lsasss.exe
    C:\WINDOWS\nnkiff.dll
    C:\WINDOWS\v6.exe
    C:\WINDOWS\system32\update71941842.exe
    C:\WINDOWS\system32\update26313404.exe
    C:\WINDOWS\system32\update92620748.exe
    C:\WINDOWS\system32\digmem.dll
    C:\WINDOWS\system32\ws2_32.dll
    C:\WINDOWS\system32\main.sys
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\cleardisk

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. valesspot

    valesspot Private E-2

    hello. i have followed all procedures in the above post. Everything came out fine with no errors. i have the following logs that i will post. there are no more pop ups. one thing i also did a spyboot search and destroy scan and it still detected smitfraud virus.

    thank you and please let me know if there is something else i can do.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why were the below running when you got your HJT log? They should not be running.
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\calc.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders if they still exist:
    C:\Documents and Settings\Administrator\Application Data\Viewpoint
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    A few files seem to have come back and I noticed another one we need to delete. Use Pocket Killbox to delete the below files. Use the same kind of procedure as last time.
    C:\wmplayer.dll
    C:\WINDOWS\system32\ws2_32.dll
    C:\WINDOWS\system32\main.sys


    If Spybot is still detecting problems, attach a log from Spybot. I suspect it is just a couple of stray registry keys it is not deleting for some reason.

    Also download the current version of ShowNew from the link in the READ ME and attach a new log.


    You need to get an antivirus and a firewall installed ASAP!!! You can get them from links give in the below procedure:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds