Popuper.exe and other issues unresolved

Discussion in 'Malware Help (A Specialist Will Reply)' started by philliphart, Apr 30, 2005.

  1. philliphart

    philliphart Private E-2

    Hi all.

    I wanted to start by saying that though I just registered on the site, that it has been a longtime resource of comp maintenance for me.

    I have been through the complete spyware removal process 3 times. My machine is still plagued.

    The only step in the process I was unable to do was update windows, as apparently, the XP pro key I installed under (from my old office) is pirated (not likely).

    Nonetheless, here is the synapsis of my efforts:

    -I use firefox, so I began by running Trend Micro's scan in safe mode. I found 138 objects and deleted them all.
    -I ran Ad-Aw SE, Spybot (with plugins), stinger, CC cleaner, spyware blaster, CWshredder, kill2me, about:buster, HSRemove, HiJackThis and MSJVM Removal Tool.
    -Rebooted in regular XP mode, tried to run Win update and was stopped by the verification process. I do not have the key to make a legitmate complaint.

    At first, my computer was problem, popup, and virus free (it seemed). Without my running ANY programs, when I woke up this morning, nearly all of the symptoms have returned:

    -Flashing sys-tray icon telling me I have 4 threats to take my machine
    -Popups (assumingly from the running process called popuper.exe, which XP will not allow me to delete if not in safe mode. When i do delete, it immediately regenerates itself).
    -Network error messages that seem oddly unrelated to popuper.exe. Network failure messages and such that are either real or disguised (I cant even tell anymore)

    I'd be happy to post any log or information. I sincerely thank you for taking the time to read and consider my trouble.

    -Phillip
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are going to need to get a valid licensed version of Windows. Running without update capability is just not safe. While you copy may not be pirated in your eyes, it is to Microsoft. It belongs to the company you used to work for and was probably only licensed for one PC. Any others that installed it will have the same problem.

    Please follow the steps below so we can address you malware problems. To address your Windows update probably you will need to purchase your own valid license.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. philliphart

    philliphart Private E-2

    thank you for responding so quickly to my post.

    It is unfortunate that my XP key doesn't work, as it only used 4 of 10 available installs. I might do the investigation to see if my former boss wouldn't mind giving me the key again to verify what seems to be a hacked key.


    Nonetheless, I've attached my hijackthis log file and ran it at your suggested specs.

    Again, thank you for your time and efforts.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you must disable Spybot's Teatimer function because it could make fixing this difficult.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    E:\WINDOWS\System32\msole32.exe
    E:\WINDOWS\popuper.exe
    E:\WINDOWS\System32\intmonp.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    F2 - REG:system.ini: Shell=explorer.exe, msmsgs.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    E:\WINDOWS\System32\msole32.exe
    E:\WINDOWS\popuper.exe
    E:\WINDOWS\System32\intmonp.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. philliphart

    philliphart Private E-2

    Wow. You really did the trick. I went to bed skeptical of the results that might come, but in fact, when I woke up, my machine is spam free. I don't even see the blinking sys tray icon.

    Thank you.

    I've attached my HJT log in case you see anything that still needs to be addressed.

    Prospecting my use of the computer, should I altogether avoid using IE? Sometimes Firefox's security prevents sites, like my bank for instance, from working properly. I usually just use IE for those instances, then go back to FF. I typically use the medium security settings in IE with a bias towards not allowing any active X. What is your advice?

    Again, thank you for your help. I had given more than a dozen hours to this problem over the last week and had no luck.

    -Phillip
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. But I have to ask, are you loading Windows Messenger or MSN Messenger at startup? Do you want this to run at startup? What I'm referring to in your HJT log is:
    F2 - REG:system.ini: Shell=explorer.exe, msmsgs.exe

    You are also in serious need of getting your Windows Updates. This is a major security risk. You should perform all the steps in the below thread, the first of which is Windows Update:

    How to Protect yourself from malware!

    You will also see in the above link, the recommended use of FireFox. Use it in place of IE where ever possible.
     
  7. philliphart

    philliphart Private E-2

    I do have MSN messenger on my computer, but rarely use it. If it is running, it is unintentional.

    In fact, I noted that you had me delete that line while in safe mode and it returned nonetheless.

    I do need a windows update. I'm just a little flustered about my key. I dont want to spend the money on a copy of XP Pro (which I have now). Will buying and installing a copy of XP home overwrite XP Pro without causing trouble? If so, I'd be much more inclined to buy it.

    Thanks again.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do a file search for msmsgs.exe and tell me where you find it. Configure search as given below.

    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter msmsgs.exe
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.

    Also when you find it, right click on the one in c:\windows\system32 and select Properties and then the Version tab. Let's find out who it belongs to. The only valid one should be in c:\Program Files\Messenger (and maybe a software distribution folder too).

    What is your problem with just downloading the upgrades to Win Xp online? Are you saying you do not have a valid license for XP? As for you question about installing Home over Pro....you would be better off asking that in the Software Forum. At anyrate remember one thing, not getting the patches to your OS leaves you very vulnerable.
     
  9. philliphart

    philliphart Private E-2

    I found msmsgs.exe in the windows\system32 folder.

    Secondly, popuper.exe has arisen again. I again have popups on my computer. Though I repeatedly go into safe mode and run the spyware group (stinger, adaware, spybot, etc...) and delete popuper.exe (which sits in the windows folder), It manages to get back onto my machine within about 24 hours.


    Should I delete the msmsgs.exe file?
    Is there any way to ban a file from being placed on my computer? If I create a file named popuper.exe, when it come back to infect my PC, will that successfully interfere with it?


    Thanks as always. You are the guardian angel of spyware.

    -phil
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, try to delete that msmsgs.exe file that is in system32 but it may be refused if it is running. If so, try it from safe mode and make sure the process is not running (like we did in message # 4 using HijackThis to kill the process).

    Use the same steps as previously posted to get rid of popuper.

    This is the problem with not upgrading and also you are running without and AV and without a firewall. You need to do ALL of the steps in the below link ASAP.

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds