Random Internet Explorer Windows Pop Up

Discussion in 'Malware Help (A Specialist Will Reply)' started by PenAll, Jan 17, 2008.

  1. PenAll

    PenAll Private E-2

    Ok, Well A few days back. I had this Problem with Privacy checker and i followed a couple of guides on the internet, That seemed to work fine. It was taken care of. my comp worked fine. Woke up this morning and i had like 10 windows in internet explorer to just random websites like security checker or some garbage like that. i restarted my computer. and now only every once in a while they pop up. or sometimes a internet explorer window will just flash up for a second.

    i use norton 360

    any help would be appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. PenAll

    PenAll Private E-2

    Here Are the logs you requested.

    I couldn't Produce a log from AVG Anti virus, if that is absolutely necessary i will do it again, But it took quite a while to complete.
     

    Attached Files:

  4. PenAll

    PenAll Private E-2

    Sorry I didn't Understand that you wanted the whole zip file. Here it is. Im Still working on the AVG Files ill upload when they complete.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We did not ask you to run AVG Antivirus. We ask you to run AVG Antispyware and that should have been done before MGtools was run.


    You have too many antispyware programs installed and they are going to get in the way of removal of malware. Uninstall SuperAntiSpyware and AVG AntiSpyware now (yes right now before continuing).

    Is your copy of SpySweeper a paid version or free trial?
    • If free, uninstall it now.
    • If paid, keep it, but uninstall Windows Defender and Spyware Doctor.
    Is your copy of Spyware Doctor a paid version or free trial?
    • If free, uninstall it now.
    • If paid, keep it, but uninstall Windows Defender and Spy Sweeper.
    If both Spyware Doctor and Spy Sweeper are paid versions, you must only keep one installed.

    Address the above before continuing.



    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2
    Java(TM) 6 Family
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {C45D6442-BD97-49B5-86E9-88FDCD278380} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {CC4B2067-D903-427A-854B-632735A570D9} - (no file)
    O4 - HKLM\..\RunOnce: [fmt] c:\docume~1\admini~1\locals~1\temp\pmt.exe
    O4 - HKCU\..\Run: [Iw06RWc5g] C:\Program Files\asdfe57\SPBS.exe
    O4 - HKCU\..\Run: [RamCleaner] C:\Documents and Settings\Administrator\Desktop\ramcore.exe -s
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {85e1f530-48f4-11d9-9629-08ff2ffc9f67} - (no file)
    O20 - Winlogon Notify: ssqrs - C:\WINNT\
    O21 - SSODL: agrlmvp - {CBA8605C-85B7-4287-831D-4B7DBC9E3FED} - C:\WINNT\agrlmvp.dll
    O21 - SSODL: bmlvqkn - {B6BCDA13-8E43-487A-B694-5A83E9556E35} - (no file)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  6. PenAll

    PenAll Private E-2

    Thanks For you quick and easy response!!

    Well First of all I am very sorry for the misunderstanding. I meant to type AVG Antispyware but i typed Anti virus My BAD!rolleyes

    I did everything you asked for and i think it is working better. So far we will see tho. But i attached both the logs you requested and so far i am Extremely pleased with the service of this site. thanks again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are basically clean. You just need to delete the below file:
    C:\WINNT\system32\REN6290.tmp

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds