Still getting unwanted pop-ups

Discussion in 'Malware Help (A Specialist Will Reply)' started by nprescott, Oct 21, 2005.

  1. nprescott

    nprescott Private E-2

    I followed the read me first and the surfsidekick removal. I still get some ad's from static pages (usually overnight but sometimes during the day.



    Tried to attach log but your server seems to be timing out. Any Suggestions?

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: If you are timing out on uploads of your log, look in the process list of your HJT log. If you find a line with cmd.exe on it, delete the cmd.exe and let me know. Then upload it. For example:
    If you see:
    c:\windows\system32\cmd.exe edit it so it is c:\windows\system32\

    Make sure you make a note even in the log file that your edited this. But do not use the words cmd.exe just say command executable.

    Make sure you have booted to normal mode and run the steps in the below link to properly use and post a HijackThis log attachment:

    Downloading, Installing, and Running HijackThis
     
  3. nprescott

    nprescott Private E-2

    Don't quite understand your reply. Do I delete the file (cmd.exe) from the directory and reboot or stop the process. I stoped the process, but got the same results. Help!
     
  4. nprescott

    nprescott Private E-2

    OK, I reread your reply, edit the file and it's attached.

    THANKS!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in: Downloading, Installing, and Running HijackThis

    You have HJT installed and running from: C:\Documents and Settings\nprescot\Desktop\HijackThis.exe

    You also did not follow the directions in that link about using msconfig. You have it controlling startups:
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Correct the above before continuing but do not post a new log yet.

    You have a lot of problems! Let's begin with the below steps.

    Download LQfix and Save it to your desktop.
    - Doubleclick LQfix.exe and click install.
    - You must leave the default settings. If you change them, the fix will fail.
    - You need an active internet connection so LQfix can connect.
    - Allow LQfix to connect to the internet if prompted by your firewall.
    - Make sure 'Launch LQfix' is checked. After clicking finish in the install, the fix will start.
    - Follow the prompts on the screen.
    - Your system will reboot afterwards.
    - Please be patient after reboot, because there is a script running in the background and it may take awhile to complete.
    - When it is finished, continue with the below.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\9tq8td6i.exe
    C:\WINDOWS\system32\cdosys74.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.search345quest.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\Searchx.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.search345quest.com/sp2.php
    O2 - BHO: COMMUNICATOR - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - C:\WINDOWS\system32\communicator.dll
    O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll
    O3 - Toolbar: COMMUNICATOR - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - C:\WINDOWS\system32\communicator.dll
    O4 - HKLM\..\Run: [System service75] C:\WINDOWS\\\etb\\pokapoka75.exe
    O4 - HKLM\..\Run: [9tq8td6i] C:\WINDOWS\system32\9tq8td6i.exe
    O4 - HKLM\..\Run: [stb] C:\WINDOWS\system32\stb.exe
    O4 - HKLM\..\Run: [f3a252fac749] C:\WINDOWS\system32\cdosys74.exe
    O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
    O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000080.exe
    O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-110-12-0000080.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O15 - Trusted Zone: *.ibm.com
    O15 - Trusted Zone: *.macromedia.com
    O15 - Trusted Zone: *.msnbc.com
    O15 - Trusted Zone: *.macromedia.com (HKLM)
    O15 - Trusted Zone: *.msnbc.com (HKLM)
    O16 - DPF: {E9670165-86FE-4C34-8C4B-D3158DDC5D92} (Installer Class) - http://downloads.shopathomeselect.com/axinstall/SRInstall4110_sp2.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://content.kontiki.com/kdx/v2.11/kontiki/kontiki/current/kdx.cab
    O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\DNS <--- the whole folder
    C:\WINDOWS\etb <--- the whole folder
    C:\WINDOWS\system32\communicator.dll
    C:\WINDOWS\system32\9tq8td6i.exe
    C:\WINDOWS\system32\cdosys74.exe
    C:\WINDOWS\system32\windir32.exe
    C:\Program Files\Common Files\Windows\mc-110-12-0000080.exe
    C:\Program Files\Common Files\mc-110-12-0000080.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.


    Also tell me if you know what the below are:

    c:\epa.epa\EPMService.exe
    c:\epa.epa\epm.exe
    C:\WINDOWS\Wintse32.exe
     
    Last edited: Oct 22, 2005
  6. nprescott

    nprescott Private E-2

    Thanks so much for the help. Followed your suggestions, pop-ups seems to be better, more time will tell, but so far so good. The files:

    c:\epa.epa\EPMService.exe
    c:\epa.epa\epm.exe
    C:\WINDOWS\Wintse32.exe

    are related to some software inventory program our IT group makes us run.

    I have attached a new log, should I take any more actions?

    Thanks again.

    Neal
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It looks better but some other items showed up. Perhaps they were masked by msconfig previously.

    First look in Add/Remove programs for the any of the below and uninstall if found:
    SurfSideKick or SurfSideKick 2 or SurfSideKick 3
    SurfAccuracy
    180Search Assistant or 180sa


    Now run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
    O4 - HKLM\..\Run: [180sa] c:\program files\180search assistant\180sa.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\SurfSideKick 3 <--- the whole folder
    C:\Program Files\SurfAccuracy <--- the whole folder
    C:\Program Files\180search assistant <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.


    Now reboot in normal mode and post a new HJT log.

    And tell me how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds