Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Can anyone help me get rid of this?

[Fixed] Hijackthis! Logs - [Fixed] Can anyone help me get rid of this? posted in the Security & Safety forums; Something has obviously been planted on my computer (spyware i believe) without my permission, most likely from a website, although i don't know how it got there because my firewall ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-29-2005
Bronze Member
 
Join Date: Nov 2005
Location: England
Posts: 43
Dayve - See this Members User comments on their Profile page
Send a message via AIM to Dayve Send a message via MSN to Dayve Send a message via Yahoo to Dayve
Default [Fixed] Can anyone help me get rid of this?

Something has obviously been planted on my computer (spyware i believe) without my permission, most likely from a website, although i don't know how it got there because my firewall is always set to high and i have antivirus programs, but it's still got on here regardless. I'm getting tons of "Your computer is infected with spyware! Click here to download our revolutionary new spyware removal program!" popups, various different casino and XXX popups...

I've run several different things to try and get rid of them, AVG, Adaware, CCleaner, stinger... All found **** and deleted it but it didn't get rid of the problem...

I can't take it anymore... I can't use my computer because everytime i'm running a program i get one of these popups which shuts down the program... It doesn't just go to my desktop, it actually closes the program without giving me an option to save what i was doing, and a popup will fill up my screen... It's ridiculous... If i could get my hands on the person that made these things and thought i could get away with it, i'd open their veins with my teeth!

Hijack log attatched.
Attached Files
File Type: txt HJTlog.txt (7.8 KB, 3 views)


  #2  
Old 12-29-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Dayve,

Let me take a quick look, in the mean time, relax, we'll help you get rid of this.

LGW


  #3  
Old 12-29-2005
Bronze Member
 
Join Date: Nov 2005
Location: England
Posts: 43
Dayve - See this Members User comments on their Profile page
Send a message via AIM to Dayve Send a message via MSN to Dayve Send a message via Yahoo to Dayve
Talking

I trust you will, you people here do a great job... I remember it was you who helped me a month or so back with a spyware problem i had. :evil:


  #4  
Old 12-29-2005
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Dayve,

You are showing one Trojan, and one adware program, also, I didn't recognize your starting page choice. If it is legit, let it be, otherwise fix it. It is possible that you are still having traces of previous malware affecting your PC.

Please download and install Spyware Blaster, and RegSupremePro from my signature. Do not run them just yet.

Before running HJT however, download and run Counter Spy from my signature. Boot into Safe Mode, making sure that you have System Restore disabled, and all files and folders showing. Run a full system scan with it, and let it fix what ever it finds.

Then, still in Safe Mode, run HijackThis, and fix the following;
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
Is this really who you want as your start page? mapletip.com
If not, fix R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mapletip.com/
as well

Find and delete the file in Bold;
C:\WINDOWS\System32\mssearchnet.exe

Run CCleaner with ALL options selected, answer OK to all warnings. Then reboot into regular mode.

Now run RegSupremePro, it will want to create a backup of your cache, let it. When it is finished, click on the Registry Cleaner tab, select Aggressive. Let it run. When complete, click on Select, and choose All. Click on Fix, and let it fix everything that it finds.

Now run Spyware Blaster, make sure that it is completely updated.

Run ewido, and HijackThis and post the new logs back here.

Look forward to your reply,

TTFN

LGW


  #5  
Old 12-29-2005
Bronze Member
 
Join Date: Nov 2005
Location: England
Posts: 43
Dayve - See this Members User comments on their Profile page
Send a message via AIM to Dayve Send a message via MSN to Dayve Send a message via Yahoo to Dayve
Default

Mapletip.com is the homepage i use for internet explorer yes, it's a trusted website i've used for a long time for information about a game i play, but i don't use internet explorer anymore because of all the popups i got with it despite having a popup blocker... I use MSN explorer now instead which is much better... I'm about to go and do all the stuff you told me to but i can't run Ewido because my trial ran out ages ago... Also rebooting into safe mode with f8 doesn't work for me, what is that thing i have to type into run to boot up in safe mode?


  #6  
Old 12-29-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Please don't start double posting if you dont get a response immediately..

http://www.pchelpforum.com/hijackthi...-problems.html


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 12-29-2005 at 02:46 AM.
  #7  
Old 12-29-2005
Bronze Member
 
Join Date: Nov 2005
Location: England
Posts: 43
Dayve - See this Members User comments on their Profile page
Send a message via AIM to Dayve Send a message via MSN to Dayve Send a message via Yahoo to Dayve
Default

Sorry Joe.

I'm gonna go to bed, i shall do all the stuff you told me and post back in this thread tomorrow when i wake up... I need to know the different way of starting my computer in safe mode though... I remember last time i came here restarting and tapping f8 didn't work so someone suggested i try something else, which was to type something into run and then restart the computer... (Forgot what it was i had to type though).

Goodnight everybody. :evil:



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 05:41 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top