Partypoker.com pop-ups

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vancouverite, Jul 17, 2006.

  1. Vancouverite

    Vancouverite Private E-2

    Hi, I've followed your instructions under "READ & RUN ME FIRST Before Asking for Support" and I still can't seem to get rid of these pop-ups. Every few minutes, I keep getting windows advertising anything from Partypoker.com to Screensavers.com.

    I would really appreciate some help. I really don't know what to do anymore. :rolleyes:

    Thanks. I've also attached my HijackThis log.
     

    Attached Files:

  2. Vancouverite

    Vancouverite Private E-2

    I just realized I forgot to include the results of step 6. I've attached the reports from steps 6 & 7 below.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Next time please follow the directions in step 6 for obtaining a Bitdefender log. What you posted in not HTML log file that we requested. You posted a Word document and it is only a log summary and is not useful.

    You have a lot more problems than Party Poker! Here are a few of your problems

    • a bunch of different malware problems
    • a way out of date Windows 2000 OS. You MUST get updated after fixing malware.
    • you are running P2P programs (ALL the time) and one of them (eDonkey) is bundled with malware. Goto Add/Remove programs and uninstall eDonkey

    Let's first fix your E2Give infection. Download this E2TakeOut

    • Extract the file to your Desktop
    • Double click E2TakeOut.exe
    • Click the Begin Removal button
    • Wait until the program is finished scanning
    • Once done, it will produce a popup stating that the infection has been found and you need to reboot you computer to complete the removal
    • Reboot your computer
    • Once your computer has rebooted E2TakeOut will open and produce a report
    • Attach this report to your next message.
    Now continue with this next step!

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Command Service... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    cmdService

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    After reboot, run Windows Explorer and look for the below and delete them:
    c:\program files\E2G <--- the whole folder
    C:\WINNT\QkJU <--- the whole folder
    C:\Documents and Settings\BBT.BBT-UIN7WRE7PEI\Application Data\??curity\?hkntfs.exe
    C:\Downloads\backups\backup-20060716-195824-601.dll
    c:\winnt\system32\atmtd.dll
    c:\winnt\system32\data.~
    c:\winnt\system32\IDE21201.VXD
    c:\winnt\system32\WinNB58.dll
    c:\winnt\system32\wnscpcc.exe
    C:\WINNT\system32\cloudsim.exe
    C:\WINNT\system32\locsec.exe
    C:\WINNT\system32\mee.dll
    C:\WINNT\system32\wuauboot.dll
    C:\WINNT\uninstall_nmon.vbs
    c:\winnt\unstall.exe

    Now attach a new HJT log and tell me how things are running.
     
  4. Vancouverite

    Vancouverite Private E-2

    Thank you so much for your reply. I followed your instructions but there were a few problems. After I used E2TakeOut and rebooted my computer, it did not open a report and I can't seem to find one. When I clicked on E2TakeOut again, it just generated a pop-up window stating that the "fix has been applied."

    Secondly, there is no c:\winnt\system32 directory in my computer. The closest one is c:\winnt\system, but it did not contain the files that I should delete.

    I was also unable to find the following:
    C:\WINNT\QkJU
    C:\Documents and Settings\BBT.BBT-UIN7WRE7PEI\Application Data\??curity\?hkntfs.exe

    I've run HJT again and attached the log below. I also managed to locate the original BitDefender log and attached it. The forum won't let me upload an html file so it's a word document.

    Thanks again. I really appreciate this.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes there is a system32 folder on your computer. You just did not follow the directions in step 2 of the READ ME. If you had no system32 folder your PC would not even boot. You must make sure that you follow directions properly. Even your second Bitdefender log is still not what we ask for. We tell you exactly how to upload the HTML file. You just rename the file to have a .txt extension instead of .html. I don't need another one though.

    Again possibly because you did not follow the directions in step 2 of the READ ME.

    Use HJT to fix the below line:

    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)

    Now after following step 2 of the READ ME, go back and double check for all those files you were supposed to look for and delete. Some may still be there.

    Now reboot your PC and get a new HJT log and attach it.

    How are things running now.
     
  6. Vancouverite

    Vancouverite Private E-2

    Thanks again for the response.

    I've managed to delete more of the system32 files except two which I still couldn't find (cloudsim.exe; locsec.exe).

    I followed the rest of your instructions and I've attached the HJT log.

    The popups for Partypoker.com are still coming up though. Is there anything else I should do?

    I really appreciate this.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you now running HJT like this?????

    C:\DOCUME~1\BBT~1.BBT\LOCALS~1\Temp\Rar$EX00.117\HijackThis.exe

    You had it in an acceptable (but not what we requested) location before. You MUST FOLLOW DIRECTIONS. Third time saying this!

    Have you rebooted your PC since running E2TakeOut? I still see items from it in your HJT log that should have been removed after a reboot. Please reboot if you have not. If you have rebooted, run HJT and fix the below lines (seems like you did not fix one like I requested in my last message)

    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
    O4 - HKCU\..\Run: [E2TakeOut] C:\DOCUME~1\BBT~1.BBT\LOCALS~1\Temp\Rar$EX00.241\E2TakeOut.exe /finishremoval
    O20 - AppInit_DLLs: inicfg32.dll[Disabled by E2TakeOut, Please Reboot]

    You MUST remember to exit ALL browsers before running HijackThis and you must make sure you are selecting each line and then you must click Fix checked.

    You may have a hidden Vundo or winlogonhook infection! The below will help me find it!

    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.

    I will be on vacation until 7/31/06. One of the other Mods or Admins here may be able to pickup where I leave off.
     
  8. Vancouverite

    Vancouverite Private E-2

    I did reboot my computer after E2TakeOut, but as I mentioned in an earlier post, it never opened up a report when I rebooted. When I tried to use it again, it just generates a pop-up stating that the "fix has already been applied."

    I also have the new logs as requested below.

    Thanks.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log is now clean! You probably have a hidden Virtumonde or winlogonhook/conhook infection. The below scan will show us if they are present once we get them to work.

    You must make sure you have follow the directions for using GetRunKeys and ShowNew. There is not info in the logs that should be there. These happens for one of two reasons:

    1) all files were not extracted from the ZIP files

    2) your OS has some files missing


    If you are sure you extracted all the files from the ZIP, then do the below to correct problem number 2:

    Download and run which ever item from below matches you Windows XP version:

    For Windows XP Pro: download and run XPproFix
    For Windows XP Home: download and run XPHomeFix

    Then get new logs from GetRunKeys and ShowNew and attach them.


    I will be on vacation until 7/31/06. One of the other Mods or Admins here may be able to pickup where I leave off.
     
  10. Vancouverite

    Vancouverite Private E-2

    I'm embarassed to say that I'm still using Windows 2000. I don't have XP on my computer. Is there something else I can use?
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  12. Vancouverite

    Vancouverite Private E-2

    Thanks! I unzipped the file and clicked on "command" but all I'm getting is a DOS window. Am I supposed to type in a command?
     
  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You don't Unzip the file. You double click the exe, accept the default directory location, click Unzip and close the file. This will place 3 files in the System32 folder, that may be needed by GetRunKeys and ShowNew.

    Once you have run W2kFIles.exe, reboot.

    Then run GetRunKeys and ShowNew; and post the logs.
     
  14. Vancouverite

    Vancouverite Private E-2

    Okay, I followed all the steps and here's the logs. :eek:
     

    Attached Files:

  15. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop. DO NOT run it as this time we will do that later in Safe Mode.
    Close Notepad.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  16. Vancouverite

    Vancouverite Private E-2

    Okay. Done.

    Just a note, all the files I was supposed to delete with ExplorerXP couldn't be found.

    I've attached the most recent HJT log.
     

    Attached Files:

  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    That's a good thing.

    Your HijackThis log is clean.

    How is your computer running?
     
  18. Vancouverite

    Vancouverite Private E-2

    Unfortunately, I'm still getting those annoying Partypoker.com pop-ups. Is there anything else I can do?
     
  19. Vancouverite

    Vancouverite Private E-2

    Incidentally, I don't know if this information is helpful. But around the time I started getting the pop-ups, I also had Mirar "anti-popup" software automatically install into my computer without my knowledge.
     
  20. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Rename hijackthis.exe to analyse.exe. Do this now, before proceeding.

    Post a fresh HijackThis log.
     
  21. Vancouverite

    Vancouverite Private E-2

    Okay. Here is the new log.
     

    Attached Files:

  22. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  23. Vancouverite

    Vancouverite Private E-2

    Okay. Here is the WinPFind log.
     

    Attached Files:

  24. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I'm not seeing anything in theh logs to explain this behavior. Run teh BitDefender and Panda ActiveScan Olines scanners again and post the logs. I may be overlooking something.
     
  25. Vancouverite

    Vancouverite Private E-2

    Sorry for the delay in reply. Here are the reports.

    Incidentally, I've noticed the pop-ups seems to have decreased in the last two days. Do you think we've finally got rid of it?
     

    Attached Files:

  26. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    PandaActive Scan is finding some things in the registry, but not telling me where.

    Install CounterSpy , update the definitions. Run a full system scan and post the log.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also delete the one file that Panda did flag: c:\winnt\system32\atmtd.dll._
     
  28. Vancouverite

    Vancouverite Private E-2

    Shadow Puter Dude, my computer won't seem to install CounterSpy. It keeps getting interrupted by an error message: "Error 1606. Could not access network location %USERPROFILE%\Desktop\."

    chaslang, I think that file has been deleted.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was in your Panda log! And Panda did not delete it. Did you delete it yourself?
     
  30. Vancouverite

    Vancouverite Private E-2

    I'm not sure but it's no longer in the directory. I might have deleted it.
     
  31. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  32. Vancouverite

    Vancouverite Private E-2

    Sorry for the delay. Here is the Ewido report.
     

    Attached Files:

  33. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Ewido found mostly Cookies, and some Adware; that was removed.

    How is your computer running?
     
  34. Vancouverite

    Vancouverite Private E-2

    It's running alright. Sporadically, I would get a barrage of pop-ups. This time around, it seems to be for anti-virus software. What's strange is that I'm currently using Firefox, yet the pop-ups would be in Internet Explorer.
     
  35. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download ShowNew and GetRunKey again, run the tools and post the logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds