POS Malware trouble...

Discussion in 'Malware Help (A Specialist Will Reply)' started by 0range, Mar 25, 2006.

  1. 0range

    0range Private E-2

    I've done the steps in the "Read Me First" thread, and it hasn't fixed the problem.

    What seems to be happening is a program trying to create popups, then IE telling me that what I'm trying to open presents a security risk, resulting in endless IE popups. I located a bogus process running, and went into safe mode to delete it from system32, which I figured would solve it, but it looks like it just went ahead and made a new .exe to run the same thing, with a different name.

    The processes that run are "tmp3a.tmp" "logonui.exe" and "avifcint.exe".

    Attached are a HijackThis and BitDefender scan.
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Windows Defender and HijackThis are both installed incorrectly. Uninstall both applications and reinstall to their proper locations.

    Whatever you are disableing with MSConfig, don't. We need to see everything that could be effecting your system. Re-enable all process and startup items in MSConfig.

    Reboot.

    Post a fresh HijackThis log after HJT has been properly installed.
     
  3. 0range

    0range Private E-2

    Alright, I think I have it right this time...
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Using Add or Remove Programs in the Control Panel. Uninstall the following:
    WildTangent
    Zango Toolbar


    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  5. 0range

    0range Private E-2

    Wow, looks like it's all gone. Thank you!
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Windows Messeger is running in the background, and represents a security risk. Disable Windows Messenger by running Shoot The Messenger. If you are using this as your IM client then replace it with MSN Messenger.

    Your HijackThis log is clean.
     
  7. 0range

    0range Private E-2

    Done and done.

    Thank you very much.
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds