popups

Discussion in 'Malware Help (A Specialist Will Reply)' started by bjclem, May 16, 2005.

  1. bjclem

    bjclem Private E-2

    Help I keep getting these and I have try Adware,Spybot and Microsoft beta version . They Keep Coming
    it is A popup for Spyware Warning
    I uploaded a PDF file for it .
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. bjclem

    bjclem Private E-2

    Okay ran All the Stuff did find some stuff , But after turning on the backup again Started getting popups as bad as before even if explorer is not open enclosed is my hijack file.

    Thanks for all your help
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean you enabled System Restore? If so, you must not enable it until ALL problems have been fixed. It must be disabled and remain that way until we have decided that your PC is clean.

    I see no indication in your log of the Symantec and Trend Micro online scanners being run
    Not sure if it is still an issue but have you read the below info about Altiris:
    http://www.osvdb.org/displayvuln.php?osvdb_id=11031

    I assume you need the below setting:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://rain.ra.rockwell.com/proxy/mke
    I'm wondering what the below repairs.dll file it for. Do you know? Can you get Properties/Version info on this file to find out who it belongs to.
    O20 - AppInit_DLLs: repairs.dll

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [qnodyrux] C:\WINDOWS\qnodyrux.exe
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitesae32.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\qnodyrux.exe
    C:\windows\system32\elitesae32.exe <-- also delete all other filenames beginning with elite and ending with exe in the system32 folder.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. bjclem

    bjclem Private E-2

    Okay did everything you said ran both Virius Problems , they did find some problems , here is the new Hijack file , so far no popups , will let run it see if some of them come up
    Thankyou
    for your help
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer any of my questions from my last post. Also you did not get below item fixed:
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitesae32.exe

    Run the procedure again for all steps related to that item. Make sure you do what I said last time:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds