malware popups.hijackthis log attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by charliespcisdead, Mar 27, 2008.

  1. charliespcisdead

    charliespcisdead Private E-2

    spyware software popups trying to sell me software.please help me rid this problem.i have a good understanding of working with my pc.
    files i have that are suspicious:-
    c:\windows\wml.exe
    trojandownloader.xs
    i read and followed the read and run first but it keeps coming back.
     
    Last edited: Mar 27, 2008
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!


    As the Read Me guide states please do follow it to the letter and attach the logs as it requests as your Hijackthis log was not run following the guide steps ( location saved shows this ) as all we are wishing to do is help you to remove the malware on your PC, but we do need you to help us helpp you achieve this and by skipping steps it not only takes longer for our malware experts to get the information needed to remove this pest but takes longer to get around to assisting you as malware is a growning problem and many others are infected, so getting to everyone in turn takes a fair amount of time.


    Logs needed from the guide are:

    • SASlog.txt log from SuperAntiSpyware.
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. charliespcisdead

    charliespcisdead Private E-2

    attached the 3 logs you requested.thankyou.
     
  4. charliespcisdead

    charliespcisdead Private E-2

    logs attached

    can someone help please.software selling pop-ups keep coming up.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: logs attached

    Welcome to Major Geeks!

    Let see if we can take care of all of your problems in one shot. ;)


    Uninstall the below old versions of software:
    Java(TM) 6 Update 3

    Please C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis. And click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\rwranelu.exe
    C:\WINDOWS\system32\bxuwxfvq.exe
    C:\Program Files\Wyzo\wyzo.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    R3 - URLSearchHook: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
    O2 - BHO: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
    O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [bxuwxfvq] C:\WINDOWS\system32\bxuwxfvq.exe
    O4 - HKLM\..\Run: [lrhzajwi] C:\WINDOWS\system32\lrhzajwi.exe
    O4 - HKLM\..\Policies\Explorer\Run: [jJGgOlmQ8q] C:\WINDOWS\rwranelu.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O20 - Winlogon Notify: dumtil - dumtil.dll (file missing)
    O21 - SSODL: WinComponent - {35768046-12db-4ee8-b609-c3ffe851411b} - C:\WINDOWS\Installer\{35768046-12db-4ee8-b609-c3ffe851411b}\WinComponent.dll (file missing)
    O21 - SSODL: aflqfkw - {94F87A56-1DF0-410D-BC26-F9A542045520} - C:\WINDOWS\aflqfkw.dll
    O21 - SSODL: btpqkmo - {40639831-A388-4934-BC13-25FD4B883A10} - C:\WINDOWS\btpqkmo.dll

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  6. charliespcisdead

    charliespcisdead Private E-2

    thankyou for your help.no more pop up selling ads.all quiet here.you are a genius.everybody:major these guys put their own time into helping others.thankyou.
     
  7. charliespcisdead

    charliespcisdead Private E-2

    the two logs you requested.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks much better. I just have two files in your Windows folder you should delete as they look like Vundo related files. Delete the below:
    Code:
    "C:\WINDOWS\"
    sstvvw.ini    29 Jun 2007         585  "sstvvw.ini"
    yacdfe.ini    29 Jun 2007         525  "yacdfe.ini"

    After doing the above, if you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds