Unwanted Pop Up Issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by KaronMangum, Feb 1, 2008.

  1. KaronMangum

    KaronMangum Private E-2

    Hello! I have been having issues with unwanted pop ups when using Internet Explorer. I went through the READ ME FIRST tasks and have completed the Windows XP Cleaning Procedure, but am still getting the unwanted pop ups. Attached are the reports I generated from combofix, AVG, and MGTools.

    Thank you so much!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It appears you have multiple anti-virus programs running ...please uninstall all but one.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Okay now we need to use a new tool.

    * Download and save to RenV.exe from following link to Desktop (
    must be on the Desktop)
    * Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).
    Code:
    C:\Program Files\AIM6\aim6 .exe
    C:\Program Files\BroadJump\Client Foundation\CFD .exe
    C:\Program Files\ClamWin\bin\ClamTray .exe
    C:\Program Files\Common Files\Real\Update_OB\realsched .exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp  .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
    C:\WINDOWS\SYSTEM32\ctfmon .exe
    C:\WINDOWS\SYSTEM32\hkcmd .exe
    C:\WINDOWS\SYSTEM32\igfxtray .exe
    C:\WINDOWS\SYSTEM32\dla\tfswctrl .exe
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  3. KaronMangum

    KaronMangum Private E-2

    Hello! Thank you so much for your help! I ran the tasks you outlined below and here are the logs generated. I actually just got a pop up when I went to attach my logs...please let me know if you see anything else I need to work on. Thank you again!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now you have both:
    ClamWin Free Antivirus 0.88.4
    Kaspersky Anti-Virus 6.0 SOS

    And I also see McAfee that was once installed. You need to have only one anti-virus!! More than one causes conflicts. Plus one or both are blocking the fixes that I give you.

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).

    Code:
    C:\Program Files\AIM6\aim6 .exe
    C:\Program Files\BroadJump\Client Foundation\CFD .exe
    C:\Program Files\ClamWin\bin\ClamTray .exe
    C:\Program Files\Common Files\Real\Update_OB\realsched .exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp  .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
    C:\WINDOWS\SYSTEM32\ctfmon .exe
    C:\WINDOWS\SYSTEM32\hkcmd .exe
    C:\WINDOWS\SYSTEM32\igfxtray .exe
    C:\WINDOWS\SYSTEM32\dla\tfswctrl .exe
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.

    Reboot, and install the current version of Sun Java from: Sun Java Runtime Environment.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    Then attach the new logs:

    * Log.tx from running RenV
    * c:\avenger.txt
    * C:\MGlogs.zip


    Make sure you tell me how things are working now!
     
  5. KaronMangum

    KaronMangum Private E-2

    I am looking a my add/delete programs and I don't see a uninstall for ClamWin Free Antivirus 0.88.4 or Kaspersky Anti-Virus 6.0 SOS. Where can I find these to uninstall them?

    Thank you!:eek:
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They were both in your add/remove program list ...try looking in CCleaner under tools ...and remember you should only have one anti-virus, so don't uninstall both. Have you done the rest of the fix?
     
  7. KaronMangum

    KaronMangum Private E-2

    Hello! I checked add/delete programs and CCleaner tools for these anti-virus programs and did not see them in either.

    I have completed the rest of the fix and am still having pop up issues. Attached the logs you requested.

    Thank you so much!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It appears that most of the fix did not work ....did you disable all of your security software before doing the fix?

    Let's try again:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    RenV::
    C:\WINDOWS\SYSTEM32\ctfmon .exe
    C:\Program Files\Java\jre1.6.0_04\bin\jusched .exe
    C:\Program Files\AIM6\aim6 .exe
    
    File::
    C:\WINDOWS\SYSTEM32\ssttr.exe
    C:\WINDOWS\SYSTEM32\aoqenenq.dll 
    C:\WINDOWS\SYSTEM32\bqtrwiow.dll 
    C:\WINDOWS\SYSTEM32\chwauorg.dll 
    C:\WINDOWS\SYSTEM32\eqwvgesv.dll 
    C:\WINDOWS\SYSTEM32\gebccdc.dll  
    C:\WINDOWS\SYSTEM32\hduxhsyo.dll 
    C:\WINDOWS\SYSTEM32\jwjncftr.dll
    C:\WINDOWS\SYSTEM32\kpvkdjoh.dll 
    C:\WINDOWS\SYSTEM32\myyestgr.dll
    C:\WINDOWS\SYSTEM32\curyjdbq.ini  
    C:\WINDOWS\SYSTEM32\hlnwwver.ini
    C:\WINDOWS\SYSTEM32\jutapkbc.ini  
    C:\WINDOWS\SYSTEM32\rgtseyym.ini  
    C:\WINDOWS\SYSTEM32\rttss.ini    
    C:\WINDOWS\SYSTEM32\rttss~1.ini  
    C:\WINDOWS\SYSTEM32\siydynhf.ini 
    C:\WINDOWS\SYSTEM32\vsegvwqe.ini  
    C:\WINDOWS\SYSTEM32\wcnckccx.ini 
    C:\WINDOWS\SYSTEM32\xubxirsd.ini
    C:\WINDOWS\SYSTEM32\ssttr.dll
    C:\WINDOWS\tk58.exe
    C:\erijtgqh.bat 
    C:\erijtg~1.bat
    C:\fbhelrxx.bat  
    C:\fbhelr~1.bat
    C:\vdkiscla.bat 
    C:\vdkisc~1.bat
    C:\WINDOWS\b122.exe
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\mrofinu572.exe
    C:\WINDOWS\system32\myyestgr.dll
    C:\WINDOWS\system32\ssttr.exe
    
    Folder::
    C:\\Program Files\\Drmupgds
    C:\Program Files\Drmupgds
    C:\WINDOWS\qimw
    C:\WINDOWS\S2Fyb24
    C:\WINDOWS\SYSTEM32\CZ6           
    C:\WINDOWS\SYSTEM32\RP4           
    C:\WINDOWS\SYSTEM32\V9
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Drmupgds"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "e006d8e4"=-
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31B56F8E-7F67-41CD-6C97-09A3C21298A4}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b4ae2cb2-2df6-42ce-bf88-6b9052ad6579}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E180F496-8A4B-44E2-9FE0-0364E345DB7F}]
    
    [HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\Explorer\ShellExecuteHooks]
    "{E180F496-8A4B-44E2-9FE0-0364E345DB7F}"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and the new ComboFix log.
     
  9. KaronMangum

    KaronMangum Private E-2

    Yes, I did disable all the security software before running the fixes. I completed the new tasks below and here are the logs generated...so far so good with how the computer is running on the internet.

    Thank you for all your help!:clap
     

    Attached Files:

  10. KaronMangum

    KaronMangum Private E-2

    Okay, I am getting an error message when I boot up, "During a scan of files at system startup, potential errors in the system registry were found. p-07-0100 irql: If SYSVER 0xff00024 NT_Kernel error 1256 KMODE_EXCEPTION_NOT HANDLED."

    I also cannot access My Computer or My Documents when I click on the icons on my desktop or quick launch tool bar.

    Thank you!:confused
     
  11. KaronMangum

    KaronMangum Private E-2

    One more thing, I also have 2 new icons on my desktop...they look like the windows security shields, one green called Help & Support Center, and one multicolored called Windows Update.

    Thank you!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like some things have happened in the interim .....

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button. (Do not leave the RED notice in the notepad txt!!)
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds