Remove Malware causing popups

Discussion in 'Malware Help (A Specialist Will Reply)' started by Robbi, Sep 26, 2008.

  1. Robbi

    Robbi Private E-2

    Greetings,

    I have a Toshiba Satellite A305 running Windows Vista Home Premium with a 64-bit operating system. I stupidly clicked on a link I received in an email and now I have Chinese popups appearing and sometimes my internet explorer goes to Chinese websites.

    I have tried to follow the directions given at http://forums.majorgeeks.com/showthread.php?t=35407
    I installed and ran SuperAntiSpyware, Spybot, and Malwarebites Anti-Malware. They did not identify any problems. I tried to run combofix.exe, but it gave an error message that it did not run on a 64-bit system. I had the same problem with MGtools.exe. I still had popups so I downloaded and ran Hijack This. I have attached the log.

    Thank you for your help.
    Robbi
     

    Attached Files:

    Last edited: Sep 26, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your HJT log shows no problems. Please attach the SAS & MBAM logs as was requested even if nothing is found.

    Please run MGtools as was requested in the READ & RUN ME. It did tell you that it would still run some scans on an x64 system.


    Also please describe your problem in more detail.
    • What popups?
    • To what website?
    • What do the popups say?
    • When do they occur?
    • Do they occur if no browser is open?
    • Do they occur if you physically unplug your cable to the internet (or shut down your wireless connection if using wireless)?
    • What browser are you using?
    • Do they occur in safe boot mode?
     
  3. Robbi

    Robbi Private E-2

    Greetings Chaslang,

    Thank you for your help.

    I have atteched the logs.

    -What popups?

    All of the popups are in Chinese and look like advertisements. Some had penguins (I think this may be the ICQ messenger). When I tried to close some of them, a new explorer window opened to a Chinese website that also looked like an advertisement.

    -To what website?
    They are all Chinese websites (Sorry, I cannot read them, but they appear to be advertisements). Two of the sites I have be taken to are:
    http://www.sddfnk.com/yydt/20080924/16455245.shtml
    http://www.sdwjzx.com/china/

    -What do the popups say?
    Sorry, I don't know.

    -When do they occur?
    When I am surfing the web and often when I am searching from Google. In searching for help with this problem I clicked on
    http://stylez.wordpress.com/2006/10/15/a-guide-to-removing-chinese-popups-www3721com/
    The address in the browser is correct, but the site was all in Chinese.

    -Do they occur if no browser is open?
    No.

    -Do they occur if you physically unplug your cable to the internet (or shut down your wireless connection if using wireless)?
    No.

    -What browser are you using?
    Internet explorer

    -Do they occur in safe boot mode?
    I do not know. I was unsure if it was safe to shut my computer down after making all the changes in the "Read and Run Me First" posting. Should I change things back before rebooting in safe mode?

    It is possible that my computer was infected by a flash disc instead of the website.

    Thanks again!
    Robbi
     

    Attached Files:

    Last edited: Sep 27, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run MGtools again and make sure you accept the TrendMicro HijackThis license agreement by click ont he Accept button twice. Also make sure that you do not close the command prompt window until the scans finish running. They did not finish last time.

    Update your SUPERAntiSpyware program. There are new definitions available. Run a new scan just to be safe.

    In Internet Explorer, click Tools, Manage Addons and disable ALL addons. Do you still get popups?
     
  5. Robbi

    Robbi Private E-2

    Greetings!

    I hope you had a nice vacation.

    I have attached the new logs. I hope I allowed the MGtools to finish this time.

    I disabled all the add-ons and still saw the popups.

    Thank you again for your help.
    Robbi
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks! It was great.

    No! It is very incomplete. Shut down ALL protection sofwtare and try again. You should refer to the snap shot in the below link which shows you what it looks like when it finishes. Did you see this? Did you see the license agreement from Trend Micro? Are you getting any of the error messages mention in the below link? I would bet you are having an error of some kind since the tool is not running properly. I suggest you run the fix given for Error Message Type 1

    Using MGtools
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks! Are these last two messages for another PC? If so, they belong in another thread of there own. Let me know and I will move them to a new thread for you because you will not be able to post the same logs.

    In this current thread you need to work on only the same PC we have been working on and get me the new log.
     
    Last edited: Oct 12, 2008
  8. Robbi

    Robbi Private E-2

    Greetings!

    Yes, you are correct. It is a different computer and should be a different thread. I'm sorry. I use the HP computer as a backup and both computers are now infected with the popup malware. I think I transferred it with my USB flash drive.

    I tried updating all the programs and running all the scans again on my Toshiba. The logs are attached. On the HP in XP I had no problems with the scans. With the Toshiba in Vista I had trouble with ComboFix and MGtools.

    With ComboFixI was able to open the command prompt window in the Vista Recovery Environment, but then did not know what to do to run ComboFix.

    With MGtools as soon as I double click on the icon, I start getting an error message that this program cannot run on a 64-bit system. I close this and it immediately reopens. This repeats several times until I close the window. I do not see the licensing agreement from Trends Micro. I can navigate to the GetLogs.bat and run as an administrator. Then the error message begins again. I read the Error Fix 1, but did not see a fix for Vista. Can I run the XP fix?

    Thanks again for your patience.
    Robbi
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'm going move those posts to another thread now. The new thread is: http://forums.majorgeeks.com/showthread.php?t=171802

    Since we cannot get all of our tools to run on your Vista x64 system, we don't really have enough information to properly fix it. I would like you to try using System Restore to return your PC to a day before when your problems began. This may just solve the problems you are having. Let me know what happens when you try to use System Restore.

    If necessary, perhaps we can use some of the infor from Windows XP system to guess at what some of the issues may be.
     
  10. Robbi

    Robbi Private E-2

    Greetings!

    This was a great idea. I am embarassed to say that when I went to do this, I discovered that the system restore was turned off. It is now on. I am not sure how it was turned off. With help from a friend I made a clone of the hard drive with Acronis a few months ago and perhaps it was during this procedure.

    The popups have stopped on this computer--the Toshiba with Vista. I do not know why. It has Norton 360 running on it, but there was no obvious indication that this suddenly recognized the malware. I will continue to watch for popups, but for now they appear to be gone. I could load Norton 360 onto the other computer--the HP with XP to see if that works.

    Thank you so much for your help.
    Robbi
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good news.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. After doing the above, you should work thru the below link:
     
  12. Robbi

    Robbi Private E-2

    Greetings!

    Well, I think I went for more than a week without any popups and then they began again. Grr...

    I had hoped Norton had identified the malware and that it had been detected and removed.

    Perhaps we can find a way to remove it from the HP and then apply that to this computer.

    I will be careful to transfer files with CDs and not infect any other computers.

    Thanks again for your help.
    Robbi
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Update SUPERAntiSpyware to the current detections and then select the option under Complete Scan where you select Perform Compete Scan.
    Attach the new log.

    Also update Malwarebytes to the new version, it will probably tell you it needs to reboot so make sure you do the reboot. Then scan using the Perform full scan option. Attach the new log.
     
  14. Robbi

    Robbi Private E-2

    Greetings!

    I ran the scans and they seemed to work, but did not find anything. I attached the logs.

    Some of the advertisements on the popups seem to be new.

    Thanks again.
    Robbi
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm now sure if this is a malware problem or not. You may just be getting popups due to the sites you are accessing. Do you have any addons to IE installed? Check under Tools, Manage Addons

    How often do they occur?
    What browser do the popups appear in? ( I know you said you use IE but do the popups occur in IE type windows).
    Please check to see if the popups also occur in Safe Boot mode.
    Do you have a software firewall installed? If so, which one?
    Does your router have a hardware firewall?


    When you ran Spybot, did you run the Immunization feature and did you let it immunize everything? If not, please do this now.
     
    Last edited: Nov 1, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds