Still receiving popups after running scans

Discussion in 'Malware Help (A Specialist Will Reply)' started by menotyou, Dec 3, 2008.

  1. menotyou

    menotyou Private E-2

    This all started a couple of weeks ago.

    The first thing that happened was my home page got hijacked. Also everytime I start up IE, another window will open with (Casino sites, Porn, Stocks, ETC...). Even when I close a IE window i was using, another popup window will appear. I still am getting these after running all the scans as stated in another thread. I cannot trust the internet connection with IE. I am not sure if any personal data is getting sent out.
     

    Attached Files:

  2. menotyou

    menotyou Private E-2

    Here is my MGLOGS.zip file
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to Major Geeks, menotyou

    I'm looking over your logs - please be patient.

    Thanks!
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, menotyou

    * What do you know about these folders?


    If you have not already done so, please disable the Guest account in User accounts.


    Please disable any antivirus and/or antispyware programs you have installed so they will not block this fix. (Remember to enable them again when this steps are completed.) Print out these instructions or save them to a text file so as All Browser Windows must be CLOSED. *The fixes are specific to your problem and should only be used for issue(s) on this machine.


    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 2:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4:
    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    DirLook::
    C:\Documents and Settings\Gushue\Local Settings\Application Data\JollyBear
    C:\Documents and Settings\All Users\Application Data\JollyBear
    
    File::
    c:\temp\420
    C:\WINDOWS\Temp\a81j5ocs.tmp
    C:\WINDOWS\Temp\hlktmp
    C:\Program Files\bhbsdrx.inf
    C:\WINDOWS\Tasks\AE46DC13907D59F7.job
    E:\htocusa.exe
    
    Folder::
    C:\Documents and Settings\All Users\Application Data\Name beep copy real
    C:\Program Files\Dupe Bold Setup
    C:\Documents and Settings\Gushue\Application Data\Dupe Bold Setup
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Step 5:
    Run Ccleaner

    Step 6:
    Now install the latest Sun Java Runtime Environment


    Step 7:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt


    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!


    Thanks!
     
  5. menotyou

    menotyou Private E-2

    Thank-you for the help,
    As far as I know with the files below, they are for a game Big City Adventure the family plays.

    C:\Documents and Settings\Gushue\Local Settings\Application Data\JollyBear
    C:\Documents and Settings\All Users\Application Data\JollyBear


    Step 1 = Could not find J2SE Runtime Environment 5.0 Update 12

    Step 2 = Disabled Messenger

    Step 3 = It did not find,
    Step 4 = I had to re-download ComboFix because of this message that poped up,
    So I clicked No and then downloaded ComboFix again and then ran the file. No message poped up like the first one.

    After computer restarted and finsihed running the ComboFix, I tried to click on a Icon and the computer froze, so i hit the restart button on the computer. No problems after that.


    Ran all next steps with no problems. Computer seems to be good now.

    Thank-you for the help with this matter. Keep up the good work.:)
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're Welcome, menotyou.

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds