Windows AFA internet enchancement and other spyware that cannot be rid of.

Discussion in 'Malware Help (A Specialist Will Reply)' started by unkwon, Jul 19, 2005.

  1. unkwon

    unkwon Private E-2

    Ok I have just got this mysterious Malware jammed into my computer and it's keeping on making pop ups that move from left, right, up and down depending on the situation. Plus all the websites I got to where it has links on the words that shoud not be there.

    I've did EVERYTHING as listed onto the sticky posts, you hear that EVERYTHING and none of it had gotten rid of the random pop ups or icons on my desktop. <a href='http://consumeralertsystem.com/cas/zx-hclick.php?hid=51' target='_blank'>adware</a>, Avast Antivirus, and Spybot did detect all of the <a href='http://consumeralertsystem.com/cas/zx-hclick.php?hid=50' target='_blank'>spyware</a> and deleted it but it keeps on regenerating as for some reason if cannot find the <a href='http://consumeralertsystem.com/cas/zx-hclick.php?hid=50' target='_blank'>spyware</a> thats been doing all this. I deleted virutal bouncer, Booksend/site or whatever it's called and ETC off of the add remove and I found this: Windows AFA Inertnet enchancement and it is the only thing that can't be remove I like on the change/remove button and it won't do anything. After everytime I try to use virus scans or <a href='http://consumeralertsystem.com/cas/zx-hclick.php?hid=51' target='_blank'>adware</a> scaners and such. I get this random icon of a radom product in my desktop. I'm wondering if it's Windows AFA enchancement or if It's another unknown enemy.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have completed ALL steps in the READ ME FIRST, follow the steps below exactly:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. unkwon

    unkwon Private E-2

    Here you got my Hijackthis log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run all steps of the READ ME FIRST. Please complete all the steps. For example you did not even do step 1 of the cleaning process:


     
  5. unkwon

    unkwon Private E-2

    my apologies, I thought I did. I'll try it again.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing ALL steps continue with the below. You have remnants of a Virtumundo infection, so lets be safe and run the two items below:

    Symantec's first removal tool: Symantec Trojan.Vundo Removal Tool

    Symantec Vundo.B removal tool: Symantec Trojan.Vundo.B Free Removal Tool

    Then look in Add/Remove programs for any of the below and uninstall if found:
    Cas or CAS Client
    Media Access

    Then complele the steps below to make sure we also get the above items I included them again as a backup measure:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\odfda.exe
    C:\Program Files\Cas\Client\casclient.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr52.dll
    O2 - BHO: MSEvents Object - {44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44} - C:\WINDOWS\msagent\catutil.dll (file missing)
    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
    O4 - HKCU\..\Run: [Mwr4RSi5P] odfda.exe
    O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O18 - Protocol: vskype - (no CLSID) - (no file)
    O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll
    O20 - Winlogon Notify: catutil - C:\WINDOWS\msagent\catutil.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\odfda.exe
    C:\WINDOWS\cfgmgr52.dll
    C:\WINDOWS\msagent\catutil.dll
    C:\Program Files\Media Access <--- the whole folder
    C:\Program Files\Cas <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. unkwon

    unkwon Private E-2

    Ok I did it all now hopefully, I even did everything in exact detail, internet scan, spyware scan, everything in safe mode as well as doing the things with HJT again. Heres my HJT file and see if this helps, I'm going to restart and check if I have any problems. ;) If theres anything post away. I'm going to check if the popups now exist still.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HJT logs must be from normal boot mode (as requested in my message) to be useful. Please repost.
     
  9. unkwon

    unkwon Private E-2

    Thanks, It's gone now! I don't see any more popups, nor do I see words such as Diet, Net, etc. linked to consumeralearts anymore. Thanks a bunch! ;) Heres a the HJT anyway.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. unkwon

    unkwon Private E-2

    will do! :cool:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds