Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Virus Can anybody help?

[Fixed] Hijackthis! Logs - [Resolved] Virus Can anybody help? posted in the Security & Safety forums; Hi, I keep getting a pop-up on my screen telling me that i have to pay a bill for something i have not knowingly subscribed to. The subscription is apparently ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-01-2007
Bronze Member
 
Join Date: Jan 2007
Location: Nottingham
Posts: 6
Lmac - See this Members User comments on their Profile page
Default [Resolved] Virus Can anybody help?

Hi,
I keep getting a pop-up on my screen telling me that i have to pay a bill for something i have not knowingly subscribed to. The subscription is apparently to something called sexxpassport.

I know someone else has had this problem and this forum helped him out i tried to read the thread he posted, but it realy confused me as im not too good with computers, so if there is anyone who can help me could you please dumb things down for me so that i will be able to understand.

thanx,
LMac


  #2  
Old 02-01-2007
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,329
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

Welcome to PCHF lmac!

Can you follow the PCHF Prework link in my signature and then post back here a Hijackthis log and an AVG report, then a member of our security team will help you get rid of it.

Thanks,

Chris


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #3  
Old 02-01-2007
Bronze Member
 
Join Date: Jan 2007
Location: Nottingham
Posts: 6
Lmac - See this Members User comments on their Profile page
Default

thanxs chris,
i have done what was asked.
My problem in more detail is, i keep getting a pop-up on my screen from a company called MBS billing agency, it says that i have to pay £19.00 for a monthly subscription to something called sexxpassport, which i never subscribed to, and i have no history of visting this site.
Someone else has had this same problem and this forum has helped him and i hope the same can be done for me.

thanx lmac
Attached Files
File Type: log hijackthis.log (4.0 KB, 2 views)


  #4  
Old 02-01-2007
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,329
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

Yep it sounds like malware, hopefully our security team can help you otherwise it will be reffered back here.

[Moved to HJT Logs Forum]


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #5  
Old 02-03-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,594
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Please do not pay anything, as this is a scam. We have seen a few cases here at PCHF as well. Follow the instructions below carefully.


First, please open Add/Remove programs and uninstall New.Net or NewDotNet from there if listed. If it is not listed, follow these instructions:

· From a computer that has Internet access, click on the following link:
http://www.new.net/support/uninstall6_90.exe.
· Download and save uninstall6_90.exe to the Desktop.
· Go to the Desktop and double-click on uninstall6_90.exe
· Click on the OK button.
· After removal, you may be prompted to reboot. Please reboot even if not prompted.



Next download this and run it:
WinSock XP Fix download and review - fix XP internet connectivity from SnapFiles

Click the fix button. It should ask to reboot. Do so. Boot into Safe Mode:
PC Hell: How to Start Windows in Safe Mode


In safe mode, run HijackThis and place a checkmark by the following entries if still present:
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_22.dll (file missing)
O4 - HKLM\..\Run: [mbssm32] C:\WINDOWS\system32\mbssm32.exe

Close all other windows except HijackThis and press "Fix Checked". Then close HijackThis and restart the computer. You should get back to normal mode automatically.


Download Avenger from here:
Swandog46’s Public Tools Page

Open the program. Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens, paste this:
Files to delete:
C:\WINDOWS\system32\mbssm32.exe
and click 'Done'

Click the Traffic Light icon to start the program, and OK the prompts to reboot your PC.


Post the Avenger output.txt (which you can find at C:\Avenger\.txt), along with a new HijackThis log.


  #6  
Old 02-03-2007
Bronze Member
 
Join Date: Jan 2007
Location: Nottingham
Posts: 6
Lmac - See this Members User comments on their Profile page
Default

hi Thanx,
I tryed to follow the intsructions that you gave me, but i encounted a few problems. i couldnt place a checkmark in Hijackthis on O4 - HKLM\..\Run: [mbssm32] C:\WINDOWS\system32\mbssm32.exe as it wasnt listed. Also avenger couldnt find the file C:\WINDOWS\system32\mbssm32.exe.
Thanx Lmac


  #7  
Old 02-04-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,594
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Alright then, please post a new HijackThis log. Is the pop-up still appearing?



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 12:07 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
MPAA
Funny session with MPAA at the 2006 SXSW show.

Loan
We are the experts. Our name says it all. Get advice from Moneyexpert.

Mobile Phones
Mobile Phones from Three store, the phone people.