OMG >..Pop ups and very slow...HELP

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jenn80, Oct 30, 2007.

  1. Jenn80

    Jenn80 Private E-2

    Have this computer (Dell Dimension 2400 ~ Windows XP Home) at work that started getting pop-ups left and right. I tried to uninstall IE and started using Firefox. Use CCleaner regularly and did the major windows updates. Purchased Nortons 360 as well. Also running AdAware. Still having pop-ups. Even getting them in IE which I thought I had uninstalled. Our internet settings are constantly reset and as of today, I am no longer able to go into any settings folders or even our add/remove folder. Says I do not have permission...WTF ?! :confused

    I ran a scan a while back and it came back with Virtumundo. Here's the log file I ran today with Hijack This :




    Please help.......I'm at a loss here. I'm usualy the one that my friends come to for computer help but I'm in alien waters here. Thank you so much !!
     
    Last edited by a moderator: Oct 30, 2007
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Jenn80

    Jenn80 Private E-2

    Thank you so much. Will do the steps as instructed as time allows here at work. Will post back soon :)
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    While you are working thru the instructions ...
    Download this file - Combofix.exe
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    When you come back ...attach that log also.
     
  5. Jenn80

    Jenn80 Private E-2

    :banghead So little time to do this at work.....frustrating. I am still going through the standard steps as suggested........these are the steps I have done....

    Step 1. Cannot go into "Add/Remove" programs. Get this message when I try : "Restrictions. This operation has been
    canceled due to restrictions in effect on this computer. Please contact your system administrator." Note....this
    computer only has one main user account set up on it.

    Step 2. Msconfig....was already set in "normal startup"

    Step 3. Set computer to show all hidden files.


    I stopped in the middle of this and followed the steps for ComboFix and I am attaching the log file. I thank you for ALL of your help. Sorry this is taking me so long. They do not understand here at work , how long this can take and they expect me to fix this computer and get my work done all at the same time.......go figure *L*. I will keep you posted on my progress........oh........and hope you all have a great Thanksgiving :drink
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't worry about what you can't do ....you have a lot of problems, some of which COmboFix has addressed.

    Please do this:
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
     
  7. Jenn80

    Jenn80 Private E-2

    Alright.....I followed your steps and only had problems with Avenger. I pasted the info and so on.......ran it and rebooted. After reboot, there was no avenger.txt to be found. Not sure what I did wrong :confused. So I did a search for the log and still came up with nothing. Last resort I deleted avenger. Reinstalled as instructed and ran it again. This time I got an "error" log, which I saved. Sending more replies now to attach the logs.
     
  8. Jenn80

    Jenn80 Private E-2

    Avenger Log.....(avenger.txt)

    ShowNew Log...(newfiles.txt)

    GetRunKeys Log....(runkeys.txt)
     

    Attached Files:

  9. Jenn80

    Jenn80 Private E-2

    Last one................

    HijackThis Log.......(HJT.log)


    Also......I'm wondering how their computer got this bad. Can you see why just from these logs ? As I said, I know my basics but this is all Greek to me :D. Thank you :wave
     

    Attached Files:

    • HJT.log
      File size:
      6.7 KB
      Views:
      2
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2
    PartyPoker
    PokerStars
    Viewpoint Media Player

    Reboot and install:
    Java Runtime 6

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
     
  11. Jenn80

    Jenn80 Private E-2

    At the beginning, when I ran HijackThis..(system scan only)..I was unable to locate the following files to check and fix :

    O2 - BHO: (no name) - {4F711DB9-F9D9-42BA-9710-ABB51C4649B3} - C:\WINDOWS\system32\jkkji.dll

    O2 - BHO: {47818d9c-2efd-ddd8-a644-f67967c6c2cb} - {bc2c6c76-976f-446a-8ddd-dfe2c9d81874} - C:\WINDOWS\system32\mycibfoq.dll

    O4 - HKLM\..\Run: [486157dd] rundll32.exe "C:\WINDOWS\system32\npdixhcl.dll",b

    I saw a few that were similar but exact as typed here. :confused

    I will be off Saturday and Sunday but will be back on Monday. :)

    Attaching Logs :
    Show New (newfiles.txt)
    GetRunKeys (runkeys.txt)
    Avenger (avenger.txt)
     

    Attached Files:

  12. Jenn80

    Jenn80 Private E-2

    Last one....

    HJT (hijackthis.log)

    Thank you :wave
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all active anti-virus and anti-spyware programs while you do the following.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
     
  14. Jenn80

    Jenn80 Private E-2

    In HJT I was able to find and fix all files except this one :

    O4 - HKLM\..\Run: [486157dd] rundll32.exe "C:\WINDOWS\system32\xvfwhdme.dll",b :confused

    Here are the log files for :
    ShowNew (newfiles.txt)
    GetRunKeys (runkeys.txt)
    HJT (HJT.log)

    Adding Avenger log on next reply.......
     

    Attached Files:

  15. Jenn80

    Jenn80 Private E-2

    Thank you !! :wave

    Avenger (avenger.txt)
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  17. Jenn80

    Jenn80 Private E-2

    Thank you so so much for all of your help !! So far, we have not had any problems :celebrate. You're a genius !!!!!!!!!!!!!!!!! I hope your holidays are great !

    Again, thank you for EVERYTHING ! :wave
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're quite welcome ...safe surfing.:)
     
  19. Jenn80

    Jenn80 Private E-2

    Hello again........sure you didn't want to be hearing back from me so soon. Similar problem........different computer. My desktop at home that I use once in a while (mainly use laptop). I am ashamed to admit that I know this problem must be my fault. It happened yesterday when I was using a file sharing program that I have had on here.....which is no longer as I uninstalled it that same day. Upon rebooting the program would start itself up.......over and over. Then followed by messages from my avast anti virus, warning me of virtumundo and such. Had this computer for a few years now and never had this problem before. Always been careful in the past but made my mistake by not making time to follow the guides on your "protect yourself form malware" page that you suggested I read for my work computer. Smacking my head for it now. So, I know with the holidays here, the forums are not priority. I will keep this computer shut down until I hear back from you to avoid making my situation worse. I apologize to bug you once more with this since I should have went through the steps to protect this one at home after repairing the one at work. Been so busy but it's no excuse. So I must once more beg for your help :eek:. Thank you for your time and happy holidays :D
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do the same initial steps as we did on the other computer:
    follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  21. Jenn80

    Jenn80 Private E-2

    Hey, I'm attaching log for ComboFix. Went to "read & run me first" page and didn't see the information for ShowNew, GetRunKeys and Avenger (to download). I'll dig around for it as I am doing the steps. I have installed HJT already. Thank you :D
     

    Attached Files:

    Last edited: Dec 22, 2007
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is a new Read and RUn since you were last here ..follow the links for your system (Win XP) and download the MGTools ....that will install all the needed utilities on your system including HJT (so uninstall the one you just downloaded.) ....:)
     
  23. Jenn80

    Jenn80 Private E-2

    Hopefully I didn't screw this up but here's where I am so far.....

    Finished ComboFix and including the log.

    Ran SpyBot.

    Installed and ran AVG.....followed instructions but did not get a report afterwards :confused. It identified and quarantined the following :
    1. "Not-A-Virus.PSWTool.Win32.FirePass.a" in C:\Documents and Settings\Jennifer\f.exe
    2. "Not-A-Virus.PSWTool.Win32.FirePass.a" in C:\Documents and Settings\Cody\f.exe
    3. "Adware.Minibug" in C:\Program Files\Common Files\Real\Weatherbug\MiniBug Transporter.dll
    4. "Trogan.Agent.cmn" in C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP854\A0082512.exe


    Ran MGTools and including the logs here.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You also have a very nasty form of Vundo infection which is proving difficult to deal with...let's try:

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 3"
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java(TM) 6 Update 2"
    Java(TM) SE Runtime Environment 6 Update 1

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:


    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    • Download and save to RenV.exe from following link to Desktop (must be on the Desktop)
    • Doubleclick RenV.exe
      • When finished, it will produce a new log named Log.txt on the Desktop.
      • Attach this log to your next reply and the Avenger log.
     
  25. Jenn80

    Jenn80 Private E-2

    Everything went smooth accept I did not see this file in HijackThis to delete :

    O2 - BHO: (no name) - {EDA1CA1C-6933-4057-9556-76710314C9DB} - C:\WINDOWS\system32\vtsqr.dll

    Thank you !!! :wave
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as Log.txt to your desktop.
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log. Attach the new Log.txt to your next reply.
    * Run ComboFix
    * Run C:\MGtools\GetLogs.bat by double clicking on it.
    * Attach the below new logs:
    o Log.txt
    o C:\ComboFix.txt
    o C:\MGlogs.zip
     
  27. Jenn80

    Jenn80 Private E-2

    K.......finished getting the logs. Just noticed that my date and time have been set to Thursday on here now rolleyes........vundo...what fun !
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Viewpoint Media Player

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Doubleclick RenV.exe
    • When finished, it will produce a new log named Log.txt on the Desktop.
    • Attach this log to your next reply and the Avenger log.
     
  29. Jenn80

    Jenn80 Private E-2

    Alright......here are the logs for avenger and RenV.
     

    Attached Files:

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet ....are you having any other problems?

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  31. Jenn80

    Jenn80 Private E-2

    Sooo happy........was really stressed about this. Thank you so much....you ARE The Man !!!!!! I haven't noticed any more problems so far.......not with this one at least *L*. Now my laptop on the other hand still has issues but it's not malware. Haven't had it for long. You can be surfing one minute and then the screen goes blank with a few colored lines across it (it did this since the first day I got it). My friend (a computer programmer) says he thinks it is a hardware issue. So lucky me I get to call Dell and work it out with them. Not looking forward to it as I already had to send back the battery which held less than a 30 minute charge right when I got it. I have bad luck ! Yeah.........good times :p.

    Hope you have a great weekend and I can't thank you enough for everything !

    P.S. For anyone who runs through this thread........I strongly recommend "TimW"'s help !!
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good luck with the laptop ....and you're welcome...:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds