Virus, Trojan, and Pop Up problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by dietrick85, Sep 9, 2006.

  1. dietrick85

    dietrick85 Private E-2

    I had a lot of problems recently with a bunch a Viruses. I've run through your preliminary list of things to scan and I thought it got everything, but I'm still having ads Pop-Up in internet explorer (even though I'm using firefox).

    The preliminary process was very helpful and I thank you guys for putting together such a through help section. Things that I noticed it did get rid of were the series of "Project 1" tasks running in task mangager, a search bar that was installed on my taskbar. Also cleaned were a bunch of trojans. But I still see in my C:/ drive two malware programs, warebundlenewer.exe and installerwnusnewer.exe and I don't know if it got everything else and I'm looking for some advice on what to do next. And as I type this a Ducky B virus, and a Downloader poped up in Symantec Anti Virus Notification

    I'll post all the log files you requested, starting with hijack this

    Thanks
    jason
     

    Attached Files:

  2. dietrick85

    dietrick85 Private E-2

    And here are counterspy, runkeys and newfiles text.
     

    Attached Files:

  3. dietrick85

    dietrick85 Private E-2

    Also, I just discovered, there are Radio Ads plaing through my speakers, when no prgrams are even open. It's ridiculous. Please Help!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Weclome to Majorgeeks!

    First goto Add/Remove programs and uninstall the below:
    AVG Free Edition <--- seems broken and you are already using Symantec
    Enhanced Browser Overlay <--- malware
    J2SE Runtime Environment 5.0 Update 4 <--- old version
    J2SE Runtime Environment 5.0 Update 6 <--- old version
    Mozilla Firefox (1.0.6) <--- old version
    ScanSpyware v3.8.0.4 <--- rogue non-useful tool
    Search Bar <--- malware

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - C:\WINDOWS\system32\nsb16.dll
    O2 - BHO: Banner Rotator - {D117A61F-92C3-4450-A0C8-F425B14D4127} - C:\WINDOWS\system32\adrotate.dll
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_17.exe
    O4 - HKLM\..\Run: [defender] C:\\dfndrff_16.exe
    O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O15 - Trusted Zone: *.adgate.info
    O15 - Trusted Zone: *.adsextend.net
    O15 - Trusted Zone: *.dollarrevenue.com
    O15 - Trusted Zone: *.elitemediagroup.net
    O15 - Trusted Zone: *.imagesrvr.com
    O15 - Trusted Zone: *.matcash.com
    O15 - Trusted Zone: *.media-motor.com
    O15 - Trusted Zone: *.mediatickets.net
    O15 - Trusted Zone: *.snipernet.biz
    O15 - Trusted Zone: *.systemdoctor.com
    O15 - Trusted Zone: *.adgate.info (HKLM)
    O15 - Trusted Zone: *.adsextend.net (HKLM)
    O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
    O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
    O15 - Trusted Zone: *.imagesrvr.com (HKLM)
    O15 - Trusted Zone: *.matcash.com (HKLM)
    O15 - Trusted Zone: *.media-motor.com (HKLM)
    O15 - Trusted Zone: *.mediatickets.net (HKLM)
    O15 - Trusted Zone: *.snipernet.biz (HKLM)
    O15 - Trusted Zone: *.systemdoctor.com (HKLM)
    O15 - Trusted Zone: *.winantivirus.com (HKLM)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\asdf.txt
    C:\deskbar3.exe
    C:\dfndrff_16.exe
    C:\drsmartload1.exe
    C:\installerwnusnewer.exe
    C:\kybrdff_17.exe
    C:\kybrdff_16.exe
    C:\warebundlenewer.exe
    C:\WINDOWS\Eim03.exe
    C:\WINDOWS\MirarSetup_876075.exe
    C:\WINDOWS\srvygjhork.exe
    C:\WINDOWS\unstall.exe
    C:\WINDOWS\system32\adrot-uninst.exe
    C:\WINDOWS\system32\adrotate.dll
    C:\WINDOWS\system32\nsb16.dll
    C:\WINDOWS\system32\WinNB58.dll
    C:\WINDOWS\system32\safe.tlb
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete them if found:
    C:\Program Files\Cowabanga
    C:\Program Files\Deskbar
    C:\Program Files\ScanSpyware v3.8.0.4

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\jason\Local Settings\Temp\

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Now attach a new HJT log and tell me how the steps went.

    Now download the newest versions of both GetRunKey and ShowNew (same links as in the READ ME) and attach new logs from both of them.

    Make sure you tell me how things are working now!
     
  5. dietrick85

    dietrick85 Private E-2

    Thanks so much for your help, I followed your instructions, the only thing that happened that jumped out at me was when I rebooted after running killbox Internet Explorer poped up with "http://iesettingsupdate/" in the box, but it could not connect to server.

    Here are my updated log files, I hope we did it!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please explain why much of what I asked you to fix is still there. You must follow the directions exactly as written step by step. Try again (but start from the line that reads
    but this time disconnect from the internet while running them and also shut down ALL unnecessary applications. SOme items in the fix are already gone but some are not. Just ignore things that are already gone. MAKE SURE you find and delete all the files requested. Let me know if you have problems doing this with Pocket Killbox. Double check yourself by using Windows Explorer to locate and delete the files after the reboot from Pocket Killbox. It is quite possible that the files are deleted already and that all that is necessary is to fix the lines again using HJT.
     
    Last edited: Sep 12, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds