Pop ups - scanned & cleaned but still have pop up

Discussion in 'Malware Help (A Specialist Will Reply)' started by martinacan, Mar 3, 2007.

  1. martinacan

    martinacan Private E-2

    Hi
    I have tried to clean out the malware in my computer.
    I have not suceeded. I still get random pop-ups when using internet explorer

    Please view the hijack this file & help me if you can.

    Edit: Removed inline HJT log

    Thanks in advanced
     
    Last edited by a moderator: Mar 4, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. martinacan

    martinacan Private E-2

    Ok I followed the instructions
    I am still having problems - BIG time with pop ups
    Please help!!!
    I have up loaded the 1st 3 files
     

    Attached Files:

  4. martinacan

    martinacan Private E-2

    The final 3 files
    As stated below, still having problems
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have some Virtumonde problems. Run this: Virtumonde aka Trojan Vundo Removal and attach the requested log. This will help get us started but we will still need to do some manual removal afterwards.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 2
    Java 2 Runtime Environment Standard Edition v1.3.1_04
    Mozilla Firefox (1.5)
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox



    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Also make sure to attach the log from VundoFix.
     
  6. martinacan

    martinacan Private E-2

    Thanks for the help!
    Sorry about missing the removal of the viewpoint manager.

    I have followed the steps provided.
    I had some problems with the “Vundo Removal”. Part of the problem could be that I tried to perform the removal while in safe mode.
    After the 3rd attempt, the files were removed.

    I have removed the programs as requested & installed the latest Java & FireFox

    Requested files are attached:
     

    Attached Files:

  7. martinacan

    martinacan Private E-2

    The HJT file
     

    Attached Files:

    • HJT.txt
      File size:
      10.2 KB
      Views:
      1
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - C:\WINDOWS\system32\xxyaawu.dll (file missing)
    O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\system32\awvbhdfk.dll (file missing)
    O2 - BHO: (no name) - {FD4F61F1-688E-4D37-AA99-CEBDD3BE096E} - C:\WINDOWS\system32\ssqrp.dll (file missing)
    O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot in normal mode

    Now run Windows Explore and navigate to the below folder and delete it if found:
    C:\Program Files\VSAdd-in

    Now run Windows Explore and navigate to the below files and delete them:
    C:\WINDOWS\system32\lessybro.ini
    C:\WINDOWS\system32\nfwlvjqc.ini
    C:\WINDOWS\system32\siwfqpta.ini
    C:\WINDOWS\system32\yybeg.ini
    C:\WINDOWS\system32\yybeg.ini2

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew - FIRST PLEASE download the new version of ShowNew just updated today and use it.
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. martinacan

    martinacan Private E-2

    I have followed the instructions

    The computer seems to be working better. I have not seen any pop ups since the previous set of instructions.

    However, I do have SpyBot immunize feature operating. I turned the feature off – no pop ups appeared while testing a few sites. Before, without the feature, I would be flooded with pop ups.

    I have attached the requested files

    Thank you for your help
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm happy I had you download the new version of ShowNew. It revealed two more bad files to delete. Delete the below files:
    C:\WINDOWS\system32\yybeg.bak1
    C:\WINDOWS\system32\yybeg.bak2


    Other than those, your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. martinacan

    martinacan Private E-2

    Re: Pop ups - scanned & cleaned & gone

    Thank you very much for your help.

    I have performed the final tasks & I have installed spywareblaster. I have also kept the SpyBot immunize feature operating.
    So I hope these programs will keep the computer clear of malware

    Thanks
    Martin:)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Pop ups - scanned & cleaned & gone

    You're welcome. Just remember the most important piece of your computer security is you! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds