Pop-up and Redirection in yahoo mail, even after running Read & Run Procedure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by malmsteen, Nov 18, 2007.

  1. malmsteen

    malmsteen Private First Class

    Hi there !!!
    Today morning when i logged in my yahoo mail, a pop-up appeared and redirected me to a certain page. It then recommends me to download certain tools. If it helps, the page im directed to is this : tryggpcverktyg.com (Note : Its a swedish site, since im from sweden). I've googled it and found that its some spam and bogus site.

    So, i go on doing the Read And Run procedures. After finishing all the steps, i log onto my yahoo mail to check if i've solved the problem, but just after a few minutes of my loggin in, i get this pop-up again, and it redirects again.

    Im attaching my scan reports, please check and let me know what precautions should i take to fix it.
     

    Attached Files:

  2. malmsteen

    malmsteen Private First Class

    The remaining :
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That site you mentioned is discussed here:

    http://www.siteadvisor.com/sites/tryggpcverktyg.com?domain=tryggpcverktyg.com&ref=safe&

    The above link also references the below links. Do you see any of the below stuff on your PC. I did not notice any malware issues in the logs you posted

    http://research.sunbelt-software.com/threatdisplay.aspx?threatid=139319
    http://research.sunbelt-software.com/threatdisplay.aspx?threatid=139105


    Here are a few things you should do anyway even though unrelated to your problem.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. HJT
    I would also like you to run the below scan for rootkits and then attach the log:
    Using Sophos Anti-Rootkit
     
  4. malmsteen

    malmsteen Private First Class

    Hi again.
    Did all the above procedures, however Sophos Anti-rootkit didnt find anything.
    I should also mention that, yesterday after running all the scans, when i still got that pop-up thing, i decided to change the hosting country of my yahoo mail. Since then, i guess i havent been hit once., but im very sceptical, so i would rather be sure.

    Heres the logs u asked for :
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:

    1. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    2. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    3. After doing the above, you should work thru the below link:
     
  6. malmsteen

    malmsteen Private First Class

    Havent had any pop-ups today, so i hope im clean. Might as well do the Disable System Restore step now.

    Thanks for the help !!!;)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds