partypoker and other add pop up

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tukko, Aug 19, 2006.

  1. Tukko

    Tukko Private E-2

    Hi,

    my PC was infected by the file located in c:\windows\dGhobw\command.exe.

    I manage to remove it using various tools like Look2Me removal etc.

    Right now when I scan with spybot, hijack this and microsoft Malicious Software Removal Tool the result is clean.

    I have even ran the Qoofix and VundoFix. But i am stll getting popups, especially from partypoker. i am at lost at the moment.

    Please assist.

    Thanks
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Post thw logs from Bitdefender Online and Panda ActiveScan
     
  3. Tukko

    Tukko Private E-2

    Hi

    I was only able to complete bitdefender scan. When I ran the panda active scan my pc keep rebooting in the middle.

    Please advice on my next steps. As even after the bitdefender scan and removal infected files the popups still appears.

    Thank
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    HijackThis is not in the location specified. Right-click on the underlined text and Save Link as to your Desktop. Move_HijackThis.vbs

    Double-click Move_HijackThis.vbs on your Desktop. This script will move HijackThis to the proper location. DO THIS before you continue with my instructions. Once HijackThis has been moved to C:\Program Files\HJT rename hijackthis.exe to analyse.exe.

    Your HijackThis log is very incomplete, if you are editing it don't.

    Post an unedited, fresh HijackThis log from Normal mode.
     
  5. Tukko

    Tukko Private E-2

    Hi,

    When I right click and try to save the File or open it I get a file not found. Is the link right?

    I have moved my hijack to Programs Flies\HJT manually and rerun it and the result is the same.

    No I am not editing my HijackThis log file. If I do we won't beable to fix the problem.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You did not rename hijackthis.exe to analyse.exe. This is very important, there are infections that hide from hijackthis and detect its running by name.

    Do so now and post a fresh HijackTHis log.
     
  7. Tukko

    Tukko Private E-2

    Hi,

    I did. I have both files. One name analyse.exe and the other hijackthis.exe

    And I ran it again using analyse.exe and below is the fresh log file.
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Using Add or Remove Programs in the Control Panel; uninstall the following:
    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop. DO NOT run it as this time we will do that later in Safe Mode.
    Close Notepad.

    Run HijackThis, choose "Open the Misc Tools Section", choose "Process Manager", Highlight:
    Choose Kill Process. Click on the "Back" Button

    Click the 'Scan' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files

    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  9. Tukko

    Tukko Private E-2

    Hi,

    When I click on the remove/change for search bar in add and remove programs. Nothing happens. Is there a mannual way to get rid of this?

    Or can I continue if this is not removed?

    Lastly, When can I get a copy of the Pocket Killbox? Or what is Pocket Killbox?

    Thank you
     
  10. Tukko

    Tukko Private E-2

    Hi,

    I am unable to uninstall the search bar from the add remove programs. Do I continue with the rest of the steps or must this remove occur before I can continue?

    Thank you
     
  11. Tukko

    Tukko Private E-2

    Hi,

    Below are my actions

    >>Using Add or Remove Programs in the Control Panel; uninstall the following:
    Search Bar

    Failed. Unable to remove


    >>Now run Pocket Killbox:
    >>Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

    No error message was obtain here.


    >>Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)

    Most of the files were not found at the speficify location. Presume deleted. But on later inpection found it located at c:!KillBox

    Do I manually delete the files here?

    Did all steps as instructed. Reboot to normal mood but popups still appears. Below is the latest hijack log file

    Thank you
     

    Attached Files:

  12. Tukko

    Tukko Private E-2

    Hi,

    Ah... what happen? I am waiting for any help
     
  13. Tukko

    Tukko Private E-2

    Hi

    I am still waiting for your next advice?

    More info. I discover that there was a bloodhound virus in my Norton anti virus quarantine. I removed that mannually. Right now my anto virus is unable to complete a scan of my PC. I believe it goes into some infinite loop.

    Please advice
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry Shadow has not been available much in the last day and the rest of us have been very busy!

    Use Your Uninstaller! 2006 to uninstall it.


    Downloading it here: Pocket KillBox

    [Edit} I see you have already found Pocket Killbox! Just make sure you have the correct version! [/EDIT]

    You HJT log is clean! Are you still having problems?
     
  15. Tukko

    Tukko Private E-2

    Hi,

    Thank you for your uninstaller. I managed to uninstall the search bar and ran autofix and remove another corrupted software :- yahoo.

    I ran hijack again and this line keeps reappearing even after removing it.

    >>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    Right now I still get the popups. below is a copy of my latest hijack.log.

    I am going to run the bitdefender scan again.

    Thank you
     

    Attached Files:

  16. Tukko

    Tukko Private E-2

    Hi

    Each time I do a bitdefender scan I get this same result

    C:\Documents and Settings\..Local Settings\Temporary Internet Files\Content.IE5\SPGL4107\popup[1].htm
    C:\Documents and Settings\......\Content.IE5\..\send_car_int[1].htm


    Detected with: Application.JS.ForcePopup.A
    Infected with: Exploit.Html.Codebase.Exec.Gen

    And there are also lots of popups.

    How do I permenatly remove all this virus?

    Thank you
     
  17. Tukko

    Tukko Private E-2

    Hi,

    bitdefender scan was not able to complete as the PC reboots. And popups reappears.

    Please assist. I am waiting for any advice.

    Thank you
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you running Bitdefender in safe mode or normal boot mode. Try the other mode and then please attach a properly formatted full log from Bitdefender as requested in step 6 of the READ ME (just like you did in message # 3)

    Also run this:Disable/Remove Windows Messenger to Remove Windows Messenger.

    Also please install and configure and run Spybot Search & Destroy as requested in the READ ME.
    Also install and run Windows Defender as requested in the READ ME and if for some reason you cannot install it, you are suppose to install and run CounterSpy and attach the log from it. Make sure you fix whatever is found (do not ignore bad items).

    Now go to the below link and install one of the firewalls listed in step 3:

    How to Protect yourself from malware!


    Now attach new logs from GetRunKey and ShowNew.
     
    Last edited: Aug 23, 2006
  19. Tukko

    Tukko Private E-2

    Hi,

    I ran bitdefender in save mode and obtain the below results.

    I than ran the panda scan in normal mode. Below is also the log files

    I also ran the windows defender in normal mode and the scan is clean.

    I have remove all the files in the cookies directory. What about the rest of the files?

    What is this line that keeps appearing in my hijack logs even after fixing it
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    What is my next steps not do I reboot? or must I disable the system restore before I reboot.

    Please advice. Waiting for your advice
     

    Attached Files:

  20. Tukko

    Tukko Private E-2

    Hi,,

    Ps :
    I have also ran Spybot in save mode
    >>Also please install and configure and run Spybot Search & Destroy as requested in the READ ME.

    And it reports no error

    Thank you
     
  21. Tukko

    Tukko Private E-2

    Hi,

    I forgot to post this2 files. GetRunKeys and ShowNew.

    Can someone just work with me to resolve this than me guessing and deleting stuff from the cache and cookies directory? I am still getting those popups. But I think we have made some progress.

    Thank you.
     

    Attached Files:

  22. Tukko

    Tukko Private E-2

    Hi,

    I am still waiting for your advice.
     
  23. Tukko

    Tukko Private E-2

    hi,

    Please reply on my next steps to take
     
  24. Tukko

    Tukko Private E-2

    Helo,

    Please help
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are basically clean other than a few things.

    Bitdefender found some strangely named file it could not delete. You will have to figure out what this is and delete it:
    F:\disk\01\yanhan001\NaomiÖ®÷ÈÁ¦»¤Ê¿.txt


    Pand found the below two file you should delete:
    C:\WINDOWS\keyboard1.dat
    C:\z-winzip\39 p2 ARMY SURVIVAL MANUAL CD\ccoud.dll.bak
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The above is
    This is not malware!


    Are you still getting popups? If so, what is in the popups? Is there a URL given? If so, what?
     
    Last edited: Aug 25, 2006
  27. Tukko

    Tukko Private E-2

    Hi,

    thanks for yor reply.

    I have deleted the below files

    >F:\disk\01\yanhan001\NaomiÖ®÷ÈÁ¦»¤Ê¿.txt
    >C:\WINDOWS\keyboard1.dat
    >C:....CD\ccoud.dll.bak

    Yes I am still getting ad popsup and come from various places.

    Strange thing is after eachtime I scan and clear the
    1. Internet Temporary directory
    2. Cookies directory

    when I reboots. The same stuff get back there and bitdefender always reports this
    C:\Documents and Settings\..Local Settings\Temporary Internet Files\Content.IE5\SPGL4107\popup[1].htm
    C:\Documents and Settings\......\Content.IE5\..\send_car_int[1].htm

    Detected with: Application.JS.ForcePopup.A
    Infected with: Exploit.Html.Codebase.Exec.Gen

    It is like something is installing it self on reboot and adware, and the rest of the software is unable to clean it.

    Thank you.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Way back in message number 18, I instructed you to do the below BEFORE attaching new logs from GetRunKey and ShowNew:
    When are you going to follow this instruction?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds