Recommended Driver Scanner

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Popup Infestation

[Fixed] Hijackthis! Logs - [Resolved] Popup Infestation posted in the Security & Safety forums; Hi Everyone, Shakyra here. Good to meet all of you. Well, here's what's going on. I've a Compaq Presario V2000 running Windows XP Home and I've become infested with popups. ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 05-20-2006
Bronze Member
 
Join Date: May 2006
Location: Baltimore, MD
Posts: 6
shakyra - See this Members User comments on their Profile page
Send a message via Yahoo to shakyra
Default [Resolved] Popup Infestation

Hi Everyone,

Shakyra here. Good to meet all of you.
Well, here's what's going on. I've a Compaq Presario V2000 running Windows XP Home and I've become infested with popups. They're coming from everywhere. I'm at my wits end. Please Help.

Another thing that's going on is that like now trying to add the attachments now, the window comes up but doesn't opens. That happens to I think all the windows that opens from another page. I will send this but will have to go to another pc to attach my 2 logs. They will be to you shortly.

Thanks,

Shakyra.

I've done the preq. and am attaching my EWida log and hijack this log. Will be attached in next thread. See above.


  #2  
Old 05-20-2006
Bronze Member
 
Join Date: May 2006
Location: Baltimore, MD
Posts: 6
shakyra - See this Members User comments on their Profile page
Send a message via Yahoo to shakyra
Default Popup Infestion Adding Ewida and Hijack This log

Same messege as before just at another pc and attaching my Ewida and Hijack This logs.

Hi Everyone,

Shakyra here. Good to meet all of you.
Well, here's what's going on. I've a Compaq Presario V2000 running Windows XP Home and I've become infested with popups. They're coming from everywhere. I'm at my wits end. Please Help.

Another thing that's going on is that like now trying to add the attachments now, the window comes up but doesn't opens. That happens to I think all the windows that opens from another page. I will send this but will have to go to another pc to attach my 2 logs. They will be to you shortly.

Thanks,

Shakyra.

I've done the preq. and am attaching my EWida log and hijack this log. Will be attached in next thread. See above.
Attached Files
File Type: doc ewidoreport.doc (31.5 KB, 2 views)
File Type: log hijackthis.log (11.5 KB, 3 views)


  #3  
Old 05-21-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Shakyra.

First download delcmdservice.zip , unzip it to youre desktop , open the folder and doubleclick on delreg.bat.

http://users.telenet.be/marcvn/tools/delcmdservice.zip

Then uninstall anything related to MyWebSearch in add/remove programs.


After that boot in safemode (hit f8 when booting up) and then fix these with Hijackthis:
(if still present)


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...Q305&bd=presar io&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\ MyWebSearch \SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {0A6B148E-8337-92CA-4CA4-F4CAE923E3CE} - C:\WINDOWS\system32\ vskx.dll (file missing)
O2 - BHO: web compressor - {23FB5ADD-DA37-4a40-9FC0-B0E2384CDE92} - C:\WINDOWS\system32\nso23.dll (file missing)
O2 - BHO: RieMon Class - {70F6A776-579A-4C95-BA88-134253907752} - C:\WINDOWS\system32\ irsmtyrw.dll
O2 - BHO: Banner Rotator - {D117A61F-92C3-4450-A0C8-F425B14D4127} - C:\WINDOWS\system32\ adrotate.dll
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\ thiselt.exe
O4 - HKLM\..\Run: [epitgt] C:\WINDOWS\system32\ fxedgv.exe reg_run
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\ CCZoop05.exe
O4 - HKLM\..\Run: [adstart] iexplore.exe http://__adstart
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [bmpvh] C:\WINDOWS\system32\ fxedgv.exe reg_run
O4 - HKCU\..\Run: [Tbsa] "C:\PROGRA~1\ DOBE~1 \netdde.exe" -vt tzt
O4 - HKCU\..\Run: [Jvljuw] C:\Documents and Settings\Owner\My Documents\ s?mbols \j?vaw.exe
O4 - HKCU\..\Run: [irssyncd] C:\WINDOWS\system32\ irssyncd.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZCxdm231YYUS
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache...FWBInitialSetu p1.0.0.15.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - D:\CDS300\__CDS2.dll (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ T3duZXI \command.exe (file missing)
Then manually delete the files in bold , reboot , and post a new hjt log please.


Also i see you have both Avast4 and norton AV installed. To prevent coflict and performence problems i would disable/uninstall one of those.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 05-22-2006
Bronze Member
 
Join Date: May 2006
Location: Baltimore, MD
Posts: 6
shakyra - See this Members User comments on their Profile page
Send a message via Yahoo to shakyra
Default Popups

Hi Joe


And thanks.

I've done as you suggested and have attached the hijack this log. The popups seem to be gone. The pc also appears to be very slow now. Also will be taking off the Avast soon.

Let me know what you want me to do next.

Sincerely,

Shakyra
Attached Files
File Type: log hijackthis.log (9.0 KB, 2 views)


  #5  
Old 05-22-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

I forgot to ask in my last post if you know that Laplink Gold remote control software is installed on youre pc , and do you use it?


install and run RegSupremePro.
It will want to make a backup of your registry , let it. Once it has finished, click on the Registry Cleaner tab, select Aggressive. When it has completed, click on Select, choose All. Click on Fix, and let it fix everything that it finds.

Then run ATF cleaner again , also defrag youre HD , and then see after uninstalling Avast aswell how the speed is with youre pc then.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 05-23-2006
Bronze Member
 
Join Date: May 2006
Location: Baltimore, MD
Posts: 6
shakyra - See this Members User comments on their Profile page
Send a message via Yahoo to shakyra
Default

Thanks Joe,

And yes, my dad uses Laplink to transfer file from pc to pc. He has windows 98 and no burner and very limited hard drive space on his pc and he uses it to transfer and offload files.

I'll uninstall Avast, and run the RegSupremePro and run the ATF Cleaner. Do I do this in Safe Mode?

Thanks again,


  #7  
Old 05-23-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

I would run ATF cleaner in safemode since it is possible that files are in use in normal mode and can be easier/only deleted in safemode , but for the regcleaner it doesn't really matter eitherway i think.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 03:03 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top