Please help army of pop-ups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Baselerd, Sep 14, 2004.

  1. Baselerd

    Baselerd Private First Class

    I have just completed the "READ ME FIRST BEFORE POSTING" process, and I hoped this would work. But it didn't. My internet is much faster now, but I still have problems with pop-ups. Whatever I have (dont know), it isn't detected by any of the recommended programs. Here are some of the URL's in the pop-ups to help u identify (hopefully) what it is thats bugging me (pun intended):
    http://www.inklineglobal.com/adsales/ads/sbdetect.gif
    http://wildwabbit.com/3MegaPix_02.gif
    http://66.230.172.14/click.php?c=bgK3DYs4O878CnaGkj8xmD9J00hCa8xwdCui%

    Please help me. Thanks.
     
  2. Baselerd

    Baselerd Private First Class

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    And then post your HijackThis log as a .txt file attachment. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  4. Baselerd

    Baselerd Private First Class

    Here it is:
     

    Attached Files:

    • log.txt
      File size:
      7.2 KB
      Views:
      5
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are these lines something you put in:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = /4.3.8 FrontPage/5.0.2.2634a mod_ssl/2.8.19 OpenSSL/0.9.7a

    What is your expected home page? http://www.dell.com ??
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hit CTRL-ALT-DEL to bring up Task Manager and select Processes. Look for the below processes and if found end them:
    jmzmbst.exe
    ojkp.exe
    Jx.exe
    KHost.exe
    winyri32.exe
    sjter40m.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R3 - URLSearchHook: (no name) - {05CACBB9-A276-12EB-A863-CDCE65DA245E} - C:\WINDOWS\Mcvvmqyv.dll
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81C3A} - C:\WINDOWS\EliteBar\EliteBar version 50.dll
    O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA880F} - C:\WINDOWS\EliteBar\EliteBar version 50.dll
    O4 - HKLM\..\Run: [jmzmbst] C:\WINDOWS\jmzmbst.exe
    O4 - HKLM\..\Run: [ojkp] C:\WINDOWS\ojkp.exe
    O4 - HKLM\..\Run: [Jx.exe] C:\documents and settings\sunfish\local settings\temp\Jx.exe
    O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winyri32.exe
    O4 - HKLM\..\Run: [sjter40m] C:\WINDOWS\System32\sjter40m.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
    O16 - DPF: {68BCE50A-DC9B-4519-A118-6FDA19DB450D} (Info Class) - http://www.wow-europe.com/en/wowbeta/Si.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
    O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab


    Make sure you have enabled viewing of hidden files and folders per the READ ME FIRST tutorial.
    Boot in safe mode and delete:
    C:\WINDOWS\EliteBar <---- the whole directory
    C:\WINDOWS\Mcvvmqyv.dll
    C:\WINDOWS\jmzmbst.exe
    C:\WINDOWS\ojkp.exe
    C:\documents and settings\sunfish\local settings\temp\Jx.exe
    C:\WINDOWS\kdx\KHost.exe
    C:\windows\system32\winyri32.exe
    C:\WINDOWS\System32\sjter40m.exe

    If you have problems deleting any of these, hit CTRL-ALT-DEL to bring up Task Manager and select Processes. Look for the process in the list and end it. Then try deleting the file. Let me know if any of these could not be found or were found but could not be deleted.

    Reboot in normal mode and tell me how things are working and post a new HJT log attachment.
     
  7. Baselerd

    Baselerd Private First Class

    Those processes are not on my task list. I have observed that there are several processes that are always new and some old that dissapear. To put it bluntly, I am suspicious that the spyware changes the process names, of course you are the expert. And my home page is google, but it often redirects me to searchmiracle.com when i open <a target="_blank" href="http://searchmiracle.com/text/search.php?qq=Internet">internet</a> explorer even though my homepage is still google. Heres my log file (again), see if anything changed. Should I go ahead and delete those items anyways?
     

    Attached Files:

    • log.txt
      File size:
      7.2 KB
      Views:
      1
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand why you posted another log. You did not run the steps I requested. If you do not see the processes running just continue to do everything else.
     
  9. Baselerd

    Baselerd Private First Class

    Okay I did all of that, and the following files were not there:
    C:\WINDOWS\jmzmbst.exe
    C:\WINDOWS\ojkp.exe
    C:\documents and settings\sunfish\local settings\temp\Jx.exe
    C:\WINDOWS\System32\sjter40m.exe

    Other than that I did everything you requested. Here's my log, but I still see the links, not active but the script to link is still there, such as: "<a target="_blank" href="http://searchmiracle.com/text/search.php?qq=Internet">internet</a>" for internet on the post below.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what these lines are:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = /4.3.8 FrontPage/5.0.2.2634a mod_ssl/2.8.19 OpenSSL/0.9.7a
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = /4.3.8 FrontPage/5.0.2.2634a mod_ssl/2.8.19 OpenSSL/0.9.7a
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = /4.3.8 FrontPage/5.0.2.2634a mod_ssl/2.8.19 OpenSSL/0.9.7a

    You did not fix:
    C:\windows\system32\winyri32.exe
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winyri32.exe

    I'm not sure what you mean by,

    "but the script to link is still there, such as: "<a target="_blank" href="http://searchmiracle.com/text/search.php?qq=Internet">internet</a>" for internet on the post below."
     
  11. Baselerd

    Baselerd Private First Class

    Okay, I fixed those, and as far as you dont know what that meant, the spyware will find commonly searched words in text on html, and edit the code so where it will be a link. I copied the source of a page and it inserted the link into words like internet.
     

    Attached Files:

    • log.txt
      File size:
      4.6 KB
      Views:
      1
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This line is still in your HJT log:
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winyri32.exe

    You need to find this file and delete it. Go thru the below again:
    Click Start.
    Open My Computer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Make sure you uncheck Hide extensions for know file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.
    Click OK.

    Tell me if you are able to do this correctly or not.

    Then boot into safe mode and USE Windows Explorer to locate (this is not Windows search) the below file and delete it:
    C:\windows\system32\winyri32.exe

    Tell me if you find this and are able to delete it. If you find it and cannot delete it, look for it using Task Manager. If found end the process and then delete the file.

    While in run HijackThis and fix:
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winyri32.exe

    Now reboot normal and let me know how all that works.
     
  13. Baselerd

    Baselerd Private First Class

    I already had those settings on. I went back to double check and those files aren't there. It is not on my task manager either.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you look for the file? What procedure?

    Did you try looking in safe mode?

    Did you delete the line in HijackThis in safe mode?

    Is it still in your log? Just run a new scan for yourself and look. And just tell me.
     
  15. Baselerd

    Baselerd Private First Class

    Okay ill walkthrough what i did:
    -Deleted ththe stuff via Hijack THis (closed all other windows)
    -booted in safe mode
    -opened my computer, the view options had already been set to what u specified
    -looked for files, they weren't there

    It is still in my log =(
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read what I posted again! I wanted you in safe mode already when you used HijackThis.

    And what did you use to look for the file? (Just double checking.)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If doing what I asked in the previous post from safe mode does not get rid of that line from HJT. Try this:

    Download killbox here:

    KillBox

    Unzip the file to your desktop (or someplace else you can find it):

    Start Killbox.exe

    When it is open, enter C:\windows\system32\winyri32.exe into the field labeled "Full path of file to delete".

    Select the Delete on reboot option.

    Then press the button that looks like a red circle with a white X in it.

    Your computer will reboot and check to see if the file is gone.

    Then fix this with hijackthis, reboot then fix the below line again:

    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winyri32.exe

    Now run another scan with HJT and tell me if it is really gone.
     
  18. Baselerd

    Baselerd Private First Class

    Well, i did that and its gone for now =). I could not manualy find the file though, but i ran the program you specified.
    I still didnt find these:
    C:\WINDOWS\jmzmbst.exe
    C:\WINDOWS\ojkp.exe
    C:\documents and settings\sunfish\local settings\temp\Jx.exe
    C:\WINDOWS\System32\sjter40m.exe

    Does that matter?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a new HijackThis log attachment.
     
  20. Baselerd

    Baselerd Private First Class

    okay here
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log looks clean. Anymore hijacks to SearchMiracle?
    What about words being changed to links?
     
  22. Baselerd

    Baselerd Private First Class

    I havent run into any problems so far. . No redirections to search miracle, and now words are being linked. =)

    Thanks alot
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I hope you meant 'no' word are being linked?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds