Problems with Pop-Ups in Internet Explorer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MrTim, Oct 10, 2004.

  1. MrTim

    MrTim Private E-2

    Hey everyone,
    I recently installed Windows XP and since then I've been having kind of big problems with pop-ups, especially when I'm actually using Internet Explorer. Even when I don't open up Explorer, I get pop-ups coming up every once in awhile. Sometimes I get so many that it slows down my computer or freezes it, etc. A lot of the pop-ups refer to Spyware and how to delete it, etc., I've also gotten easytickets.com (I think that's what it was?) and other various types. I've read and done everything in the Sticky threads you posted at the top (microtrend, search and destroy, ad-aware, and all the rest) and that didn't stop this. Then I ran Hijack This and had it fix some of the things that I could tell should be fixed, some of the more obvious things. But this still hasn't fixed my problem. I see you don't want us to post Hijack This logs without being asked, so I haven't, but I'd be happy to post it however you'd like if that could help someone figure this out for me, since I'm not able to. Thanks in advance for any help!

    --Tim
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Post your log as a .txt file attachment.
     
  3. MrTim

    MrTim Private E-2

    Hey! Here's my HijackThis log, attached as a text file. Thanks in advance!

    --Tim
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure system restore is disable and viewing of hidden file is enabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them if found:
    MFCN3057.exe
    AutoUpdate.exe
    tcmcconf.exe
    tpprmap.exe
    mcao.exe
    CxtPls.exe
    ?ttrib.exe
    PalrgYwG.exe
    Tbx3gPf.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\SearchBar.htm
    O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} - C:\Program Files\CxtPls\CxtPls.dll
    O2 - BHO: (no name) - {34A74D2C-9A15-56E7-8754-61557CF0291B} - C:\WINDOWS\System32\kja.dll
    O2 - BHO: (no name) - {6CFE152C-C044-06E0-8754-61557CF02A1F} - C:\WINDOWS\System32\pfb.dll
    O2 - BHO: (no name) - {91692D04-0779-8A9B-B239-8F471ABECC6D} - C:\WINDOWS\Jnunqsgu.dll
    O3 - Toolbar: Search - {FB5F664A-EC04-B0CD-FCD9-5B05D8B13AD2} - C:\WINDOWS\Jnunqsgu.dll
    O4 - HKLM\..\Run: [Faoeu.exe] C:\documents and settings\tim\local settings\temp\Faoeu.exe
    O4 - HKLM\..\Run: [vb.exe] C:\documents and settings\tim\local settings\temp\vb.exe
    O4 - HKLM\..\Run: [c70e91fe5dc0] C:\WINDOWS\System32\DBMSSPXN.exe
    O4 - HKLM\..\Run: [a9a389282ff5] C:\WINDOWS\system32\MFCN3057.exe
    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
    O4 - HKLM\..\Run: [rs3W36g] tcmcconf.exe
    O4 - HKLM\..\Run: [47LJYSL3P9@4L3] C:\WINDOWS\System32\Gwf524W7.exe
    O4 - HKCU\..\Run: [aBs6RWMne] tpprmap.exe
    O4 - HKCU\..\Run: [Sacr] C:\Documents and Settings\Tim\Application Data\rmsa.exe
    O4 - HKCU\..\Run: [Stmu] C:\Documents and Settings\Tim\Application Data\mcao.exe
    O16 - DPF: ChatSpace Full Java Client 3.1.0.235 - http://205.177.13.60/Java/cfs31235.cab
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=ec608128e2ad8f54737eb7b602fec8de8a8bd4a94fdc797de43ead5088c0a7684bdbcf75a4aa956db74a9ba101cfe00ab573b3a7:207ac61af97ce07411e61a49d18a3129
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/220b5e354957ad2f3e15/netzip/RdxIE601.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab


    Boot in safe mode and use Windows Explorer to delete:
    C:\Program Files\CxtPls\CxtPls.dll
    C:\WINDOWS\System32\kja.dll
    C:\WINDOWS\System32\pfb.dll
    C:\WINDOWS\Jnunqsgu.dll
    C:\WINDOWS\System32\DBMSSPXN.exe
    C:\WINDOWS\system32\MFCN3057.exe
    C:\Program Files\AutoUpdate <--- the whole directory
    C:\WINDOWS\system32\tcmcconf.exe
    C:\WINDOWS\system32\tpprmap.exe
    C:\Documents and Settings\Tim\Application Data\mcao.exe
    C:\Documents and Settings\Tim\Application Data\rmsa.exe
    C:\documents and settings\tim\local settings\temp\Faoeu.exe
    C:\documents and settings\tim\local settings\temp\vb.exe
    C:\Program Files\CxtPls\CxtPls.exe
    C:\WINDOWS\SYSTEM32\?ttrib.exe <--- do not delete attrib.exe
    C:\WINDOWS\System32\PalrgYwG.exe
    C:\WINDOWS\System32\Tbx3gPf.exe


    Now boot in normal mode and post a new HJT log and tell me how things are working.
     
  5. MrTim

    MrTim Private E-2

    Hey there,
    So far things are working well, but it's only been 5 minutes. But then again, I'd get pop-ups as soon as I started Internet Explorer before, and nothing so far. So it looks good so far!
    As for your instructions, I followed them all, except for these things:
    After fixing the things with HijackThis and rebooting in safe mode, I went to look for the things you told me to delete. I was unable to find the following things to delete:

    C:\Documents and Settings\Tim\Application Data\mcao.exe
    C:\Documents and Settings\Tim\Application Data\rmsa.exe
    C:\documents and settings\tim\local settings\temp\Faoeu.exe
    C:\documents and settings\tim\local settings\temp\vb.exe
    C:\WINDOWS\SYSTEM32\?ttrib.exe
    C:\WINDOWS\System32\PalrgYwG.exe
    C:\WINDOWS\System32\Tbx3gPf.exe

    However, I did delete files called Faoeu.dll and vb.dll instead of the corresponding exe's. And I did manage to find these 2 items, which I deleted:
    C:\WINDOWS\Prefetch\PALRGYWG.EXE-161DFC58.pf
    C:\WINDOWS\Prefetch\TBX3GPF.EXE-1ADE68A2.pf

    But I couldn't find anything like mcao.exe, rmsa.exe, or ?ttrib.exe after the reboot in safe mode.

    But anyhow, I'll post the new HJT log, and I'll let you know if anything does go wrong in the next few days, or I'll at least post again tomorrow sometime if NOTHING goes wrong (hopefully!). So let me know what else I should do at this point, if you could. Thanks very much so far!

    --Tim
     

    Attached Files:

  6. PhilliePhan

    PhilliePhan Guest

    Hi Tim,

    This looks like a Peper trojan:
    O4 - HKLM\..\Run: [47LJYSL3P9@4L3] C:\WINDOWS\System32\WuaT.exe

    C:\WINDOWS\System32\KexvAC.exe
    C:\WINDOWS\System32\SxbV5wGL.exe


    Try running this tool: http://downloads.subratam.org/PeperFix.exe

    Also try the Trojan Scan online scan and a-squared in the Additional Steps portion of the tutorial if the PeperFix doesn't work.

    - - - Other than that, your log looks OK (Of course, it's late and I'm sleepwalking ;) )

    Best luck,

    PP the Insomniac
     
  7. MrTim

    MrTim Private E-2

    OK, I did end up having a few troubles after my last post, but I just tried your advice about the Peper Trojan, etc., and again, so far so good. I fixed WuaT.exe, then I rebooted in safe but I couldn't find KexvAC.exe or SxbVSwGL.exe anywhere on my drive. I also ran the Peper Fix application, and it found and fixed some files, I ran it again after reboot and it didn't find anything....soooo....I'll just wait and see again, and for now, I'll post my latest HJT log so you can see if there's anything else wrong with it now. Thanks for your help so far, both of you!

    --Tim
     

    Attached Files:

  8. PhilliePhan

    PhilliePhan Guest

    Hi Tim,

    Sorry to say, it's still there:
    O4 - HKLM\..\Run: [47LJYSL3P9@4L3] C:\WINDOWS\System32\Gwf524W7.exe

    I suggest you try the online trojan scan and a-squared as I previously suggested. You could also try PeperFix again.

    You could try this as well:http://www.memorywatcher.com/uninst.exe

    I'm going to crash. Good luck :)

    PP
     
  9. MrTim

    MrTim Private E-2

    Hey there,
    Okay, I fixed that last thing you told me to fix, I ran the PeperFix again, I did a-squared (which found a few things) and the online trojan scan (which didn't find anything) and i ran that last program you told me to try. Sooooo....it really does look like it might be fixed now, I left the computer on with Internet Explorer open all last night, and I didn't see a single pop-up when i woke up this morning. I'll post my latest HJT log now, in case you guys might see anything left over. But it's looking pretty good!

    --Tim
     

    Attached Files:

  10. PhilliePhan

    PhilliePhan Guest

    Hey Tim,

    Your HJT log looks good. As long as those 016 entries (other than the online scans) are ones you want.

    I imagine Chas will follow me on your log to doublecheck, but it looks like you guys got everything. Chas has pinned some excellent recommendations that you should look at:
    http://forums.majorgeeks.com/showthread.php?t=44525

    Best,

    PP
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tim and PP,

    Looks nice and clean to me too.

    Good job!
     
  12. MrTim

    MrTim Private E-2

    Okay guys, it's been working perfectly for me today! Thanks so much for all your help! And I did go ahead and follow a couple of those other suggestions that I hadn't done yet, like installing the ZoneAlarm firewall. And I guess I have one final question, about that. Since I installed it earlier this afternoon (say, 7 hours ago or so?) it says that it's blocked 2066 intrusions since install, and 62 of those have been high-rated. Is that a normal number, or is it high enough that I might still have something on here that's just being blocked a lot? I use DSL, me and my roommate are both connected to a router, if that info helps at all.

    But again, thanks a bunch! You guys have been great!! :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. That's a lot of intrusions. Were the outgoing or incoming? Is there a name or IP address associated with them?
     
  14. PhilliePhan

    PhilliePhan Guest

    Hey Tim,

    You should be OK behind a router and ZA. Now, if ZoneAlarm starts to notify you that it is blocking STRANGE things trying to CALL OUT from your computer - then you might have a problem! ;)

    ***Didn't see Chaslang (as usual)

    PP
     
    Last edited by a moderator: Oct 12, 2004
  15. MrTim

    MrTim Private E-2

    Hey,

    Out of the high-rated intrusions, at least some of them had an IP address associated with them, but all those other ones, it never told me where they were from or if they were associated with anything. And all of these intrusions are listed under the "Inbound Protection" category....does that mean they were all in-coming, then? Let me know what you think. So other than that, everything's still working perfect! Thanks again!

    --Tim
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, Inbound means something is trying to come in. So your firewall is doing its job.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds