Ran all tests, still getting popups, when nothing was really found

Discussion in 'Malware Help (A Specialist Will Reply)' started by Krayzie993, Nov 3, 2006.

  1. Krayzie993

    Krayzie993 Private E-2

    I was recently hit with like 4 viruses: Trojan.Galapoper.A, Trojan.popper, Trojan.Elitebar, and Trojan.Adclicker....Though i have no more detections of any of those viruses anymore after running several scans on the computer. My problem now seems to be whenever I go to a search engine I receive pop ups, and whenver i click on a link in a search engine, my entire screen flashes white for a split second. I have all the required files for someone to look at, except for the panda scan which for some reason didn't want to run today, but I had run it several times in the past. Also it seems as though spyware is continuing to be installed on my computer because Spybot search and destroy will eliminate the same threats over and over again, even if the scans are minutes after each other. If you need anymore information just ask, but my big concern is doing away with the popups as the computer is only a month old.

    Attachments below.
     

    Attached Files:

  2. Krayzie993

    Krayzie993 Private E-2

    and one more....and must I mention I am new at this whole HI Jack this thing, first time user. So please bare with me if i am an idiot
     

    Attached Files:

  3. Krayzie993

    Krayzie993 Private E-2

    here's one that keeps reoccuring when I run spy bot....Smitfraud-C.Toolbar888, other ones that get picked up at every scan vary, it keeps reinstalling itself to the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    • Save it to your desktop or a place easy to find.
    • Do not run it yet
    Please look in Add/Remove Programs for the following and uninstall them if found:

    Viewpoint
    (Anything Viewpoint)


    Now, scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,wbmmykq.exe

    O2 - BHO: (no name) - {0BDB22C0-BD18-4A40-9A9D-71F314BB75DB} - (no file)
    O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - C:\WINDOWS\system32\aiarybma.dll

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall Class) - http://morpheus.res.wsc.ma.edu/nav/webinst.cab

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\Program Files\Viewpoint Delete this whole folder if it exist!

    Next, run CCleaner to clean up cookies and temp files.

    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\system32\aiarybma.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:

    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and then scan with HijackThis and attach the new log.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  5. Krayzie993

    Krayzie993 Private E-2

    Followed all instructions, here's the new log file, so far things seem good, but you'll probably know better by looking at the log.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log looks good, are you having any current problems?
     
  7. Krayzie993

    Krayzie993 Private E-2

    nope, not as of now, search and destroy does not find anything, when i click on a link it does not put the key back into the registry like it used to....all seems to be good, if i have have any problems i will be sure to repost in this thread. Thank you so much!!!
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds