Pop Up Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Peterd, Jan 30, 2006.

  1. Peterd

    Peterd Private E-2

    Having got my computer sorted, I am now trying to sort out my daughter's which is heavily infected with pop ups and running very slowly. I have run all the checks - Adaware and Spybot seem unable to delete CoolWebSearch. I also ran CWShredder but it says there is no CoolWebsearch problem! I attach the bitdefender, Panda and Hijackthis logs.

    My daughter's pc is normally connected to a router, but I have had to install Outpost as I am not at her house. Am I correct in thinking that the router is a physical firewall so that a firewall program is not also needed? Does the router in some way need updating?

    Any help will be great.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Peterd

    Peterd Private E-2

    I have run the various programs you suggested and now attach the Buster, Ewido and HJTlogs. IE still seems to be running slowly, although I haven't seen any pop ups.

    Am I now ready to do the system restore bit?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs and uninstall the below (I'm not sure exactly what they may have named it). it is not a very useful application to use and at one time was even considered a rogue tool.
    Acceleration Software or StopSign or eAcceleration Stop-Sign or WebScan

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {2566FCEB-BCBE-B30A-35B9-518DEE38C367} - C:\WINDOWS\system32\wincg.dll (file missing)
    O2 - BHO: (no name) - {368522E6-DCE8-EC39-B6BD-A6FA508764AB} - (no file)
    O2 - BHO: (no name) - {9E062B93-7461-E8CC-5B90-D252F1EC2121} - (no file)
    O2 - BHO: Class - {A7595DD0-954D-787A-73FC-769C95DF9F01} - C:\WINDOWS\system32\addtn32.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (they may already be gone):
    C:\WINDOWS\system32\wincg.dll
    C:\WINDOWS\system32\addtn32.dll
    C:\Program Files\Acceleration Software <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. Peterd

    Peterd Private E-2

    I could not find any of the programs you mention in your first paragraph, nor can I remember seeing them when I looked in Add/Remove Programs.
    I attach the latest HJT log having taken the steps you listed. Hopefully we are now bug free?

    Can I go back to the end of my initial posting about the router. Does my daughter need a firewall as well as a router and can routers be updated like software?

    In case I don't need to post another reply, many thanks from me and my daughter.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First let's address your question. Some routers contain firewalls (this is a hardware firewall) and some do not. Most of today's new routers do have a built-in firewall. Router firmware (not software) is normally upgradable but you only get this when the manufacturer releases it for download and installation. You still really should have a software firewall on your PC for the added protection and flexibility that it provides. Hardware firewall (since they are not updated that often) just cannot know about every possible aspect of malware that exists and thus are not as flexible as software firewalls which update frequently. Also for many people, they can have other network elements (like a switch) in between the router and many PCs in a home or small business network. The hardware firewall does not provide any protection when these local PC are communicating with each other because the info (packets) are switched by the switch and never get to the router. Thus a software firewall again would help protect in this case.

    Multiple layers of protection is always the best solution as no single item provides ultimate protection.


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link (where you will notice step 3 is a firewall):

    How to Protect yourself from malware!
     
  7. Peterd

    Peterd Private E-2

    Thanks for your reply. When I posted my last thread it was nearly midnight here in England and I automatically, without thinking, turned off the pc. I am not sure if that created the problems in para. 3

    Today I disabled System Restore, rebooted and enabled System Restore. I have installed AVG anti virus and uninstalled Norton as I have read that it is bloated and slows down computers. Also the Microsoft Security Center kept saying it could not determine the anti virus status.

    I ran AVG and it came up with 2 problems:
    C:\Windows\lrjrk.dll
    C:\Windows\system32\pdpma.dll
    and fixed them. I then ran Adaware and it came up with our old enemy CoolWebSearch (I think 8 items) which it fixed. I disabled System Restore, rebooted and enabled System Restore. I then ran AVG and Adaware again and neither found any problems.

    I attach a further HJT log and wonder if you can confirm that we now appear to be bug free?
     

    Attached Files:

  8. Peterd

    Peterd Private E-2

    Further to my recent post, can you please let me know if it possible to get bugs via MSN Messenger which my daughter uses, also AOL Instant Messenger?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Malware can arrive from anywhere. That does not mean you must stop using everything. You just need to be more careful what you click on and what you download and run (this is discussed in the How to protect thread).

    If you have good protection in place and use a lot more common sense and a browser like FireFox instead of IE (where possible), you are much safer but there is no perfect solution.
     
  10. Peterd

    Peterd Private E-2

    Thanks for that advice. Can you please look at my previous post when I attached a further HJT log and asked are we now free of bugs.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were already clean in message # 5. Nothing has changed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds