Free PC Performance Scan

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Annoying popups, unknown source.

[Fixed] Hijackthis! Logs - [Fixed] Annoying popups, unknown source. posted in the Security & Safety forums; Hi PCHF, I am having problems with popups, i thought it was caused by a program called look2me, which i succesfully removed [or so i believe]. However since look2me's removal ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-26-2006
Bronze Member
 
Join Date: Feb 2006
Posts: 11
helpme - See this Members User comments on their Profile page
Default [Fixed] Annoying popups, unknown source.

Hi PCHF, I am having problems with popups, i thought it was caused by a program called look2me, which i succesfully removed [or so i believe]. However since look2me's removal the popups have remained. I wonder if u can advise me on what needs removing from my HJT log.

Many Thanks
Attached Files
File Type: log hijackthis.log (7.9 KB, 5 views)


  #2  
Old 02-26-2006
Hengis's Avatar
PCHF Head Honcho
My PC
 
Join Date: Jan 2004
Location: Southern England
Posts: 11,459
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default

Welcome to the forum, I am sure someone will be along soon to cast their eye over your log. I have had a quick look and yup, you're pretty infected

Hang tight.


__________________

Pre-Work
/ System File Checker / Help promote PCHF! / What's inside your PC? / Did we help you? If we did, please consider A Donation
  #3  
Old 02-26-2006
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,767
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

:smiley: Hi Helpme,

My welcome to you as well. We have an excellent team of techs here, and I am sure that we can remove those rlms (rotton little monsters) from your PC.

First, please carefully follow the instructions for PreWork in my signature. Make sure to save the ewido log to post back here, also make sure that your HijackThis is unzipped into its own folder and is not being run from a temp location or your desktop. Once you have posted both of the logs back here we can get started on the clean up.

Look forward to your reply,

TTFN

LGW


  #4  
Old 02-26-2006
Bronze Member
 
Join Date: Feb 2006
Posts: 11
helpme - See this Members User comments on their Profile page
Default

Hi just to update you, the Ewido scan looks like it will take a while to complete and its getting late here so ill have to update you with the logs tomorrow. Hope this doesnt inconvinience you too much!


  #5  
Old 02-26-2006
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,767
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

:cheesy: Not at all! If you are cool, we are cool. LOL

That ewido scan can take a while, especially the first time. The thing is, once it starts to find infections, it needs someone to tell it to fix them. I would have you remove all of the infections except for the chance of false positives.

If you have to leave it, have it ignore all that it finds, and we will tell you what to fix when we can look over the report.

It will either be myself or Joe5 our Security Team Leader ,

Look forward to your reply,

TTFN

LGW


  #6  
Old 03-06-2006
Bronze Member
 
Join Date: Feb 2006
Posts: 11
helpme - See this Members User comments on their Profile page
Default

Hi sorry for such a delay.

Here are my 2 reports from ewido and HJT.

Look forward to your reply.
Attached Files
File Type: txt hijackthis2.txt (8.1 KB, 3 views)
File Type: txt Scan report_20060306.txt.txt (12.2 KB, 2 views)


  #7  
Old 03-07-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Lets clean that up.

First please download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original Hosts file.

Then download and install the trial version of Webroot SpySweeper (8.3mb)
http://www.webroot.com/shoppingcart/...011&vcode=DT02

When SpySweeper starts, please accept any prompts to update definitions.
Configure it as follows:

From the left pane, click Options
Select the Sweep Options tab & ensure the following are ticked:

*Sweep Memory
*Sweep Registry
*Sweep Cookies
*Sweep All Users accounts
*Do Not Sweep System Restore Folder
*Enable Direct Disk Sweeping
*Sweep contents of compressed files
*Sweep For Rootkits

-After that's done, select Sweep from the left pane & click on the Start button

Allow Spysweeper to reboot your machine to remove the infected files.
After rebooting, launch SpySweeper & select Results from the left pane
Click the 'Session Log' tab & choose Save to File to create a log.

Now go to add/remove programs and uninstall NewdotNet. If you don't have that option or if you have difficulties then please follow the instructions on this site

Then fix these with hjt:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
When youre done please post the Spysweeper log , plus an new hjt log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 02:55 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top