Popups everywhere

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bubbakeg, Dec 7, 2007.

  1. Bubbakeg

    Bubbakeg Private E-2

    About two days ago I was browsing and began getting popups. I have run through the Windows XP Cleaning Procedure, and have attached my logs here. I have run trough some of the other cleaners that were recomended in other threads on MG. After I ran the tool thimgs seemed good until I restarted my computer after I deleted all of my restore points. The Popups have slowed but they still come. Also when I am using google it seems that it freezes up dor a few seconds after I hit enter.

    Any Help is greatly apreceated.
     

    Attached Files:

  2. Bubbakeg

    Bubbakeg Private E-2

    These are the other requested logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below software:
    iWin Games (remove only)
    Java(TM) 6 Update 2
    Java(TM) SE Development Kit 6 Update 2
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp



    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now let's stop a malware service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to DomainService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: {35e46a90-6ebd-08f8-eaa4-1d45d6caeb34} - {43beac6d-54d1-4aae-8f80-dbe609a64e53} - C:\WINDOWS\system32\etgwdahr.dll
    O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL (file missing)
    O2 - BHO: (no name) - {8E3FBDE2-7DBD-4040-85D9-29BBC559C129} - C:\WINDOWS\system32\yaywuts.dll
    O2 - BHO: (no name) - {B6792A38-D32B-4D2F-A528-D6821BBBA378} - C:\WINDOWS\system32\ssqrq.dll
    O2 - BHO: (no name) - {E710AD60-A6CC-44F0-85FC-871566AB814F} - C:\Program Files\Windows NT\homeqybinC:\WINDOWS\system32\v2\swdrv83122.exe.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.iwin.com/global/premium/gamehouse/luxor/mjolauncher.cab
    O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://www.iwin.com/global/premium/gamehouse/tumblebugs/axhost.cab
    O16 - DPF: {A0D43FB0-116B-47AB-80FB-6DCFA92A03E3} (Utility Class) - http://video.deepmarinetech.com/nvUtility.dll
    O16 - DPF: {A6F36F3F-3AE0-458B-AFC4-AA82565E0BF8} (AUnifiedControl Class) - http://video.deepmarinetech.com/nvUnifiedControl.dll
    O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.iwin.com/global/premium/sprout/feedingfrenzy/SproutLauncher.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.iwin.com/global/premium/popcap/popcaploader_v6.cab
    O20 - Winlogon Notify: yaywuts - C:\WINDOWS\SYSTEM32\yaywuts.dll

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  4. Bubbakeg

    Bubbakeg Private E-2

    Thank you for your help I still keep getting popups but the google problem seems to be better. These lines on HJT were not there.

    O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL (file missing)

    O2 - BHO: (no name) - {E710AD60-A6CC-44F0-85FC-871566AB814F} - C:\Program Files\Windows NT\homeqybinC:\WINDOWS\system32\v2\swdrv83122.exe.dll (file missing)

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    I have attached MGlogs.zip that you requested, but I was unablle to locate the avenger log is there another name that it could be under.

    I really appreciate the time you have taken to help me wth this. Also is there anyway I can Donate to the MG site. you guys really do a great service.

    Thanks agian
    BK
     

    Attached Files:

  5. Bubbakeg

    Bubbakeg Private E-2

    Also if this helps most of the popup are from SST
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you did not get the fix to work. You must get Avenger to run properly. Shutdown all browsers and antivirus/antispyware programs and run the previous procedure again. If Avenger does not create the C:\Avenger.txt log, or if it is empty, that means it did not work. You also may notice other messages from it. Watch for them and report any that you see.
     
  7. Bubbakeg

    Bubbakeg Private E-2

    I have run avenger, several times, and after I click the traffic light avenger closes and doesnt prompt to rerstart. I have waited as long as 30 min for the promt (just to make sure I gave it time to run) then restart with out any success. No messages or anything, and no log.

    I know this must be frustrating for you and I really do appreciate all of your help.

    BK
     
  8. Bubbakeg

    Bubbakeg Private E-2

    I don't know what I did different this time but avenger worked. I now have both logs and haven't had a popup since I ran avenger.

    Thank You
    BK
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's much better but we still have some more to do. Also note that you did no installed the current version of Sun Java yet. You should install this from the link I gave you.

    We are going to use Avenger again to delete some files. If it gives you any problems again, just boot into safe mode and refer to the filesI listed in the Avenger fix and delete them yourself.



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {8E3FBDE2-7DBD-4040-85D9-29BBC559C129} - C:\WINDOWS\system32\yaywuts.dll (file missing)
    O2 - BHO: (no name) - {B7B06F3D-FBA0-46DA-A96B-E7F9072E195A} - C:\WINDOWS\system32\ssqrq.dll (file missing)
    O4 - HKLM\..\Run: [ec73a7fc] rundll32.exe "C:\WINDOWS\system32\kjpeneiv.dll",b
    O20 - Winlogon Notify: yaywuts - yaywuts.dll (file missing)

    After clicking Fix, exit HJT.

    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. Bubbakeg

    Bubbakeg Private E-2

    Working great not a popup one since yesterday.

    Here are the logs you requested.

    Thanks
    BK
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds