Pop Ups from hell

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheVicChick, Apr 8, 2008.

  1. TheVicChick

    TheVicChick Private E-2

    My mom has issues! Every time you log onto her computer a bunch of command prompt screens start up and then disappear very quickly. Idid a trend micro scan of her computer and there is all kinds of pop ups. Every time you go to another website it opens another pop up in place of the one you want to go to. I am going to go through the steps in the read me first section and will post the files needed... PLEASE HELP??!

    Thank you!
    Vic
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. TheVicChick

    TheVicChick Private E-2

    OK, I have done all the steps in the read me first section and here are my log files. I hope someone can help me! Sadly, after doing these things it is running slower than ever :( I hope I get this soon... Without having to format.

    Thanks if anyone can help me...

    I also have a whole bunch of files called sqmdataXX.sqm up to like 19... does anyone know what these are? and are they safe to delete?
     

    Attached Files:

  4. TheVicChick

    TheVicChick Private E-2

    And just fyi... because of how slow the computer is going, it has literally taken me 3 days to get these reports... *sigh*
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well....there was numerous items removed by the two scans that you ran ...and there are just a few left overs:

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  6. TheVicChick

    TheVicChick Private E-2

    OK, hopefully this is done... I will do a housecall scan later and let you all know! THANK YOUU!!!!
    My mom says THANK YOU!!!! :D

    Lets hope it worked, keep your fingers crossed and here are the last 2 logs...
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type combofix /u in the runbox and click OK.
    * Note: The space between the X and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  8. TheVicChick

    TheVicChick Private E-2

    Sadly, it is not clean. :( My mom did a housecall scan and it is still showing the trojan dropper. I am not sure exactly of the name and right now I am not at her house... but I will go over there tonight and find out the exact name of it. :cry I am so sad...
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-infection? Please let me know the exact path that it is reporting.
     
  10. TheVicChick

    TheVicChick Private E-2

    I don't know what the exact path is... I did a trendmicro online scan because for some reason her avast is not detecting it. Anyway, I am not sure how to find out the exact path. I read the info on it on trend micro and it just says that it drops infections where ever it wants, which would explain the mess earlier. Please help me find it? the actual name from trend micro is TROJ_DROPPER.EUO

    Ugh... also, thank you so much for all the help you have already provided me! :)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The name of the virus does not tell me where it is.....please rescan with MWB's and attach that new log with a new MGLogs.zip from running the C:\MGtools\GetLogs.bat file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds