Major Popups...

Discussion in 'Malware Help (A Specialist Will Reply)' started by swalsh19, Sep 22, 2006.

  1. swalsh19

    swalsh19 Private First Class

    I had a major popup problem. I have run all the scans and it appears better. I'm wondering however if there is more that should be removed. I did the Panda scan last and it was still saying there was 75 items that could be removed...

    Anyways here are my scans... Please let me know if I should worry about this or not....
     

    Attached Files:

  2. swalsh19

    swalsh19 Private First Class

    Here are the Online Scan results...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Then uninstall the below software (some of which is malware):
    J2SE Runtime Environment 5.0 Update 6
    MediaTickets by OIN
    Mozilla Firefox (1.5.0.3) <--- this may no longer appear after updating above to 1.5.0.7
    Search Bar


    Start by downloading a tool we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\Documents and Settings\Wes or GOUCHIE\Local Settings\Temp\mc-110-12-0000904.exe
    C:\Documents and Settings\Wes or GOUCHIE\Local Settings\Temporary Internet Files\Content.IE5\W9IF01EV\install[1].exe
    C:\Documents and Settings\Zack\Local Settings\Temp\b116.exe
    C:\Documents and Settings\Zack\Local Settings\Temp\mc-110-12-0000904.exe
    C:\Documents and Settings\Zack\Local Settings\Temporary Internet Files\Content.IE5\59QIQYYC\MTE3NDI6ODoxNg[1].exe
    C:\Documents and Settings\Zack\Local Settings\Temporary Internet Files\Content.IE5\7XDN8YAD\install[1].exe
    C:\Program Files\?ystem\msiexec.exe
    e:\939c59e152e98067830c8ba2\mrtstub.exe
    C:\deskbar.exe
    C:\deskbar_e10.exe
    C:\dfndrff_e11.exe
    C:\DXC1205b.exe
    C:\Installer4.exe
    C:\kybrdff_e10.exe
    C:\kybrdff_e11.exe
    C:\MTE3NDI6ODoxNg.exe
    C:\MTE3NDI6ODoxNgnew.exe
    C:\ucmoreiex.exe
    C:\warebundlenewer.exe
    C:\WINDOWS\alfa.exe
    C:\WINDOWS\ms042181481550.exe
    C:\WINDOWS\srvgjjlmfx.exe
    C:\WINDOWS\srvvrbgnyy.exe
    C:\WINDOWS\sys015502181481.exe
    C:\WINDOWS\uninst108.exe
    C:\WINDOWS\uni_e6h.exe
    C:\WINDOWS\system32\repairs303169590.dll

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Program Files\Deskbar
    C:\Program Files\InetGet2
    C:\Program Files\PrintView
    C:\Program Files\SurfSideKick 3
    C:\Program Files\webHancer
    C:\Program Files\?ystem"
    C:\Program Files\Common Files\Companion Wizard
    C:\Program Files\Common Files\WinAntiVirus Pro 2006
    C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
    C:\Program Files\Common Files\{5C6673A4-0639-1033-1024-030602030002}

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Root Family\Local Settings\Temp



    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now!
     
    Last edited: Sep 24, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds