Ran CCleaner & other tools, just get 30 min popup now.

Discussion in 'Malware Help (A Specialist Will Reply)' started by d4hess2614, Mar 26, 2008.

  1. d4hess2614

    d4hess2614 Private E-2

    My daughter downloaded a music video supposedly and then my PC was hit with the virus and adware viruses. WinXP Pro SP2 w/ Symantec anti-virus.
    Ok I ran the PC cleanup process the recommended tools and have the logfiles.
    All seems to be removed except the every 30 minute popup stating I have a virus and links to buy some anti-virus and ad-aware products.
    Like: http://antispyware-reviews.biz/?wmid=4663&pwebmid=R3n1c2Bg8A

    Please help, and thanks for all the great advise you guys give out.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm looking at your logs now! What are the below and who save them in these folders?
    Code:
    2008-03-21 22:23 . 2008-03-21 22:23 <DIR> d-------- C:\Documents and Settings\djhe\Desktopvirii
    2008-03-21 22:23 . 2008-03-21 22:23 4,096 --a------ C:\Documents and Settings\djhe\DesktopTrojan.Win32.BlackBird.exe
    2008-03-21 22:23 . 2008-03-21 22:23 4,096 --a------ C:\Documents and Settings\djhe\DesktopFWebdEditor.exe
    2008-03-21 22:23 . 2008-03-21 22:23 4,096 --a------ C:\Documents and Settings\djhe\Desktopfwebd.exe
    2008-03-21 22:23 . 2008-03-21 22:23 4,096 --a------ C:\Documents and Settings\djhe\Desktopfkwp2.0.exe
    2008-03-21 22:23 . 2008-03-21 22:23 4,096 --a------ C:\Documents and Settings\djhe\Desktopfkwp1.5.exe
    2008-03-21 22:23 . 2008-03-21 22:23 4,096 --a------ C:\Documents and Settings\djhe\Desktopfilemanagerclient.exe
    2008-03-21 22:23 . 2008-03-21 22:23 4,096 --a------ C:\Documents and Settings\djhe\DesktopEditorFKWP2.0.exe
    2008-03-21 22:23 . 2008-03-21 22:23 4,096 --a------ C:\Documents and Settings\djhe\DesktopEditorFKWP1.5.exe
    2008-03-21 18:20 . 2008-03-21 18:20 <DIR> d-------- C:\Documents and Settings\Sierra\Desktopvirii
    2008-03-21 18:20 . 2008-03-21 18:20 4,096 --a------ C:\Documents and Settings\Sierra\DesktopTrojan.Win32.BlackBird.exe
    2008-03-21 18:20 . 2008-03-21 18:20 4,096 --a------ C:\Documents and Settings\Sierra\DesktopFWebdEditor.exe
    2008-03-21 18:20 . 2008-03-21 18:20 4,096 --a------ C:\Documents and Settings\Sierra\Desktopfwebd.exe
    2008-03-21 18:20 . 2008-03-21 18:20 4,096 --a------ C:\Documents and Settings\Sierra\Desktopfkwp2.0.exe
    2008-03-21 18:20 . 2008-03-21 18:20 4,096 --a------ C:\Documents and Settings\Sierra\Desktopfkwp1.5.exe
    2008-03-21 18:20 . 2008-03-21 18:20 4,096 --a------ C:\Documents and Settings\Sierra\Desktopfilemanagerclient.exe
    2008-03-21 18:20 . 2008-03-21 18:20 4,096 --a------ C:\Documents and Settings\Sierra\DesktopEditorFKWP2.0.exe
    2008-03-21 18:20 . 2008-03-21 18:20 4,096 --a------ C:\Documents and Settings\Sierra\DesktopEditorFKWP1.5.exe
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Apparently you logged out before seeing my question about those files. I'm going to assume they are part of your infections and that you do not know what they are. Thus the fix below will remove them. If this is not a valid assumption, do not run the below fix.


    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {837A022B-C2C0-4EE3-B2AC-6B896C38B030} - (no file)
    O3 - Toolbar: (no name) - {59397D6E-61F5-4BD1-8A69-9B754DDE9324} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [awzrrtmk] C:\WINDOWS\system32\awzrrtmk.exe
    O4 - HKLM\..\Run: [uqvwqxgb] C:\WINDOWS\system32\uqvwqxgb.exe
    O4 - HKLM\..\Run: [qowwmnrb] C:\WINDOWS\system32\qowwmnrb.exe
    O4 - HKLM\..\Run: [kjtanhxk] C:\WINDOWS\system32\kjtanhxk.exe
    O4 - HKLM\..\Run: [luxntgxv] C:\WINDOWS\system32\luxntgxv.exe
    O4 - HKLM\..\Policies\Explorer\Run: [v1lGqLs9CK] C:\WINDOWS\pqnwfqhw.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. d4hess2614

    d4hess2614 Private E-2

    Yeah I must have just logged out, no problem as I am not sure where those files came from anyway and actually deleted the ones under djhe already since my first post, so I removed thoise lines only from the script text.

    C:\Documents and Settings\djhe\DesktopTrojan.Win32.BlackBird.exe
    C:\Documents and Settings\djhe\DesktopFWebdEditor.exe
    C:\Documents and Settings\djhe\Desktopfwebd.exe
    C:\Documents and Settings\djhe\Desktopfkwp2.0.exe
    C:\Documents and Settings\djhe\Desktopfkwp1.5.exe
    C:\Documents and Settings\djhe\Desktopfilemanagerclient.exe
    C:\Documents and Settings\djhe\DesktopEditorFKWP2.0.exe
    C:\Documents and Settings\djhe\DesktopEditorFKWP1.5.exe

    Here are the new logs after performing the new steps you suggested, Thanks again!
    Doug
     

    Attached Files:

  5. d4hess2614

    d4hess2614 Private E-2

    So far so good, no popups! U Dah Man!!!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    2. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    3. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    4. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    5. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds