Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Baffled by Popups

[Fixed] Hijackthis! Logs - [Fixed] Baffled by Popups posted in the Security & Safety forums; Using Windows XP with all updates in place and AVG as anti-virus and no funny Toolbars in IE6 Have scanned PC in Normal Mode AND in Safe Mode with Ad-Aware, ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 03-26-2006
elpmek's Avatar
Tech Support Team
 
Join Date: Feb 2006
Location: Gloucestershire
Posts: 886
PC Experience: Experienced
elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page
Question [Fixed] Baffled by Popups

Using Windows XP with all updates in place and AVG as anti-virus and no funny Toolbars in IE6


Have scanned PC in Normal Mode AND in Safe Mode with Ad-Aware, Spybot & Ewido and these now find no problems.


Also have used Hijack which using www.hijackthis.de advises no problems.


But still get popups!!!

Also the ISP - Metronet - claims to have a firewall in place & XP firewall turned on.


I could use a system restore but I'd rather solve the existing problem in case it happens again


Any clues????

regards

elpmek


  #2  
Old 03-26-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi there Elpmek , welcome to PCHF.


Sounds like you have an Apropos rootkit on there , let's get rid of it.



Please download AproposFix.exe - but do NOT run it yet.
http://swandog46.geekstogo.com/aproposfix.exe

Boot youre pc in safemode (hit f8 when booting up)

Once in Safe Mode, double-click aproposfix.exe and unzip it to the desktop.
Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.

When the tool is finished, please reboot back into normal mode.

When done please post a HijackThis log (hjt.de is good , but does make mistakes) , and the log.txt file in the aproposfix folder.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 03-26-2006
elpmek's Avatar
Tech Support Team
 
Join Date: Feb 2006
Location: Gloucestershire
Posts: 886
PC Experience: Experienced
elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page
Thumbs up

logs attached

thanks
elpmek
Attached Files
File Type: txt log.txt (371 Bytes, 1 views)
File Type: txt hijackthis-elpmek.txt (6.5 KB, 1 views)


  #4  
Old 03-26-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Nope , it wasn't apropos. And i dont really see anything in youre hjt log , only messenger plus3 , wich often also comes with a Lop.com infection but i see no evidence of Lop.com in youre log.

Did you already have messenger plus installed before the popups begon?

And can you do a Panda active scan here and post the log from that?

http://www.pandasoftware.com/products/activescan


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 03-27-2006
elpmek's Avatar
Tech Support Team
 
Join Date: Feb 2006
Location: Gloucestershire
Posts: 886
PC Experience: Experienced
elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page
Lightbulb

Messenger was loaded before this popup outbreak

Panda log attached

elpmek
Attached Files
File Type: txt Activescan.txt (5.0 KB, 3 views)


  #6  
Old 03-27-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

You do have a Lop.com infection on there im afraid.


1. Go to Add/Remove programs. Double click on "Messenger Plus!" (or click on Remove) (see quote below)
2. The "Messenger Plus! - Setup" is now displayed. Click on the Uninstall button. Note: options displayed on the first screen are not related to the sponsor program.
3. The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen, you have to type the code that is displayed. Once you enter the code, press Uninstall.
4. If you entered the code properly, the program will ask you to confirm that you want to uninstall. You must answer "Yes" to this question, else, you won't have another chance of uninstalling.
5. To complete the uninstallation, follow the instructions that are displayed (the first one is to close all your Internet Explorer windows, that's very important). When everything is complete, restart your computer and, hopefully one nasty infection is gone.


When removing Lop.com from the Add/Remove screen it may not show up as Messenger Plus instead also look for these and remove them:

Window Search
Window Searching
Lop.com
LOP SEARCH
Browser Enhancer
Ultimate Browser Enhancer
L.O P. Un insta11
L O.P. Un instal1
Live 0n line Portal
Live.0nli ne Porta1
Window Active

Finally there is a step in the removal process of Messneger Plus where the sponsor asks if you want to uninstall that aswell, You have to click YES to this part of the removal process

If you dont do this corretly then you will have no other choice but to reinstall Messenger Plus and then go through the whole removal process again from the start.
Then do another panda scan please and post the new log from it.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 03-28-2006
elpmek's Avatar
Tech Support Team
 
Join Date: Feb 2006
Location: Gloucestershire
Posts: 886
PC Experience: Experienced
elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page
Angry

Followed instructions - didn't quite go as planned as got messages about corrupt files etc.
Anyway it said MessengerPlus was removed.
Did Panda scan (attached) & LOP still present so will reinstall Messenger Plus & remove again.

Will advise after that...


elpmek
Attached Files
File Type: txt Activescan.txt (4.3 KB, 1 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On