Pop-ups, viruses and search bar changes

Discussion in 'Malware Help (A Specialist Will Reply)' started by DJW72, Aug 14, 2005.

  1. DJW72

    DJW72 Private E-2

    Hi there.

    I have been having a lot of problems (pop-ups etc).

    I have had Spybot and Ad-Aware for some time. Spybot hasn't been detecting anything for a while but Ad-Aware is always detecting lots of things. I have Norton's anti-virus (which doesn't seem to think there is anything wrong) and also ran Trend Micro yesterday which came up with 50 viruses. I have also installed SpywareGuard, SpywareBlaster and CounterSpy in the last few weeks, but things just seem to be getting worse.

    I have followed the steps outlined in your "do not post until you have read this "thread". Bitdefender came up with over 100 finds. The others didn't find much apart from HSRemove which removed 8 items. Now that I'm back in Normal mode the same problems are happening again.

    The latest annoyance over the last day or so has been SpywareGuard constantly saying that my IE search bar has been changed and asking me to restore to previous or keep the new value (where the new value is just a lot of jumbled letters, different every time). I just keep restoring.

    I have run Hijack This and can post a log.

    Hope you can help.

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you follow the directions below and then post your HJT log:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. DJW72

    DJW72 Private E-2

    Attached is my latest log file.

    Since I posted the first message I ran the scans again.

    Bitdefender has identified 3 files with "Trojan.Html.Startpage.I" which it can't remove and were quarantined in Nortons.

    I also had something called "Dumbgrin.exe" which I figured didn't sound good so I fixed in HJT and seems to have gone.

    The only problem I have at the moment (at least that I know about) is the repeated messages about search bar changes being notified by Spywareguard and Spybot.

    Thnaks in advance for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {99BCEBF1-0A49-BBD2-B23E-74E308E59C59} - C:\PROGRA~1\MOREST~1\Five blue.exe (file missing)
    O4 - HKLM\..\Run: [Book mail anti does] C:\Documents and Settings\All Users\Application Data\vc regs book mail\fordsect.exe


    The below item (StopSign) should be uninstalled. See this: http://www.spywarewarrior.com/rogue_anti-spyware.htm#ss_note
    O4 - HKLM\..\Run: [webscan] C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe -k


    Also fix the below left over items from BitDefender.
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\Program Files\MOREST~1\Five blue.exe
    C:\Documents and Settings\All Users\Application Data\vc regs book mail\fordsect.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. DJW72

    DJW72 Private E-2

    New log attached.

    Am still getting the Spywareguard pop-up about search bar changes.

    Also noticed when I went to c:\windows that the first 50 entries were in blue and were like "$ntuninstallKB824105$".

    Cheers
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot the log. I need to see if first but, does SpywareGuard give you more info?

    Those folders in C:\windows are valid. They are from your Windows updates.
     
  7. DJW72

    DJW72 Private E-2

    sorry... here's the log

    Sample Spywareguard message:

    An attempt to change Internet Explorer setting has been detected

    WARNING! Your default search url has been changed!

    (then says what from and to)
    .....


    Spybot message

    Spybot has detected an important registry entry that has been changed

    Category: Browser page
    Change: Value added
    ENtry: Search bar

    New data http://zzyrtatxsqz.net/s/EGFwEklu_BG
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to disable Spybot's Teatimer and disable SpywareGuard's protection or uninstall it while we fix this problem.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    Then reboot and tell me where things stand.
     
  9. DJW72

    DJW72 Private E-2

    OK, have made those changes to Spybot and uninstalled Spywareguard.

    Can't notice any problems, although IE seems a bit slower than usual.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you having any malware related problems right now?

    Post a current HJT log from normal boot mode.
     
  11. DJW72

    DJW72 Private E-2

    Log attached.

    I rebooted again and ads1.revenue made a reappearance when I started up IE along with some unwanted Favorites.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Part of your problem looks like a LOP infection. Print of copy these instructions because I'm going to have you kill ALL Internet Explorer sessions (iexplore.exe) in the next step using HijackThis.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    The below items are the same program even though they look slightly different. Kill any processes you see that have iexplore.exe in them. DO NOT kill explorer.exe.
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ytftttbrmkjlfusatpqemb.com/s/EGFwEkIu_BQf3M7jHwGIlyPQdF1fP5go0Nkq/a1V/9B6aMcR/KaxFkRmUNyXOv.htm
    O4 - HKCU\..\Run: [1 Amen] C:\DOCUME~1\Damian\APPLIC~1\FRAGSI~1\Dumbgrim.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\Doucments and Settings\Damian\APPLIC~1\FRAGSI~1 <--- Delete the whole folder. This is an abbreviated path. You must look to determine the full path. For example APPLIC~1 is probably Application Data.


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Aug 16, 2005
  13. DJW72

    DJW72 Private E-2

    Am back on line now.

    With SPywareGuard and Spybot disabled, CounterSpy (which I have on a trial) has taken up the reins telling me that start-up programs are trying to load and asking me whether I want to block things. Should I disable that as well before I do what you have suggested?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run my fixes and we shall see. If CounterSpy pops up when you try to make my fixes, just say yes to allow the changes to proceed.
     
  15. DJW72

    DJW72 Private E-2

    As far as I can tell everythign is OK.

    When I tried to kill the two i-explore processes they kept just reappearing at the end of the list with different numbers in the left column, so I kept on deleting them as they reappeared. After playing that game about 50 times I just moved on and followed the rest of the instructions.

    The R1 reference in the scan had actually changed to a different jumble of letters to that in your note, but I fixed it. Had no trouble deleting the fragsite folder.

    Have attached a new log.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you still have an R1 line. Try fixing it with HJT now:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jygogpsizgeflocv.com/s/EGFwEkIu_BQf3M7jHwGIlyPQdF1fP5go0Nkq/a1V/SotKf5s57pxFkRmUNyXOv.htm


    Make sure something like it does not come back. Also do the below:

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  17. DJW72

    DJW72 Private E-2

    Done. New log file attached. Everything seems to be running smoothly.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. DJW72

    DJW72 Private E-2

    Excellent.

    Thank you so much. You're a legend!!!!!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds