|
DAL Computer Help
» Internet Security Help
» Spyware, Adware, Viruses and HijackThis Logs
»
Help with some popups
Help with some popups
Spyware, Adware, Viruses and HijackThis Logs

01-06-2006, 02:41 PM
|
|
Newbie
D-A-L Newbie
|
|
Join Date: Jun 2006
Posts: 8
|
|
|
Help with some popups
Well I (Accidently) opened a program that installed a hell of a lot of viruses and spyware and stuff on my comp (Even though I scanned the file with AVG before opening and came up with nothing).
Anyway, I've been getting popups to different sites like constantly (In Opera (Latest version)). It also changed the IE start page and installed a load of things but I was able to fix that. I've run 5 different spyware scanners including Spybot S&D, McAfee Antispyware and Adaware SE Pro and it still hasn't come up with anything. On top of that I've gone through the HiJackThis report and I can't see anything that it could be.
Here's the report:
Quote:
Logfile of HijackThis v1.99.1
Scan saved at 2:40:19 PM, on 6/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\MESSEN~1\Msmsgs.exe
C:\Program Files\Spyware Nuker\swnxt.exe
C:\Documents and Settings\Nick\My Documents\antispaywareosos.exe
C:\DOCUME~1\Nick\LOCALS~1\Temp\ir_ext_temp_1\autor un.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\progra~1\mcafee\MCAFEE~1\masalert.exe
c:\progra~1\mcafee\MCAFEE~1\mascon.exe
c:\program files\mcafee.com\shared\mghtml.exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\Nick\My Documents\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [MCAFInstaller_masins.ui] C:\WINDOWS\TEMP\mcu137.tmp\MCAPPINS.exe /v=3 /start=masins.ui::default.htm
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\Msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: DIFxApp - C:\WINDOWS\system32\kmymgr.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
|
|

01-06-2006, 10:53 PM
|
 |
Senior Member
|
|
Join Date: Sep 2005
Posts: 5,524
|
|
|
Re: Help with some popups
Welcome to DAL,
Please go into add/remove program and remove Spyware Nuker which is a rogue program.
Reboot if found and removed.
Create a folder such as C:\HJT or C:\Program Files\HJT and move HJT.exe into the newly created folder so we can have avaiable backups in case you fix the wrong thing or I make a mistake. Very important.
Please download Look2Me-Remover.exe by Atribune to your desktop. - Close all windows before continuing.
- Double-click Look2Me-Remover.exe to run it.
- Put a check next to Run this program as a task.
- You will receive a message saying Look2Me-Remover will close and re-open in approximately 10 seconds. Click OK
- When Look2Me-Remover re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
- Once it's done scanning, click the Remove L2M button.
- You will receive a Done Scanning message, click OK.
- When completed, you will receive this message: Done removing infected files! Look2Me-Remover will now shutdown your computer, click OK.
- Your computer will then shutdown.
- Turn your computer back on.
- Please post the contents of C:\Look2Me-Remover.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.
If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new...b/MSWINSCK.OCX
After the above, you appear to be running 2 anti-virus programs and that is a bad idea, please uninstall one of them now. Thanks.
__________________
Stalking and killing Spyware
Have we helped you? Please consider a donation to help keep D-A-L free. Click on donate below
MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis Log __V2.0.2 _|
ASAP: promoting a high standard and quality of security support no matter where you seek help.
|

02-06-2006, 12:26 AM
|
|
Newbie
D-A-L Newbie
|
|
Join Date: Jun 2006
Posts: 8
|
|
|
Re: Help with some popups
Log file from Look2Me-Remove:
Quote:
Look2Me-Destroyer V1.0.12
Scanning for infected files.....
Scan started at 6/2/2006 12:15:16 AM
Infected! C:\WINDOWS\system32\mm3216.dll
Infected! C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003182.dll
Infected! C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003192.dll
Infected! C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003195.dll
Infected! C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003226.dll
Infected! C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP34\A0003277.dll
Infected! C:\WINDOWS\system32\mm3216.dll
Infected! C:\WINDOWS\system32\wwnstrm.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\mm3216.dll
C:\WINDOWS\system32\mm3216.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003182.dll
C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003182.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003192.dll
C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003192.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003195.dll
C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003195.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003226.dll
C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP33\A0003226.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP34\A0003277.dll
C:\System Volume Information\_restore{9DBEC0ED-5C8A-4311-8E0B-471C71D5D8AB}\RP34\A0003277.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mm3216.dll
C:\WINDOWS\system32\mm3216.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\wwnstrm.dll
C:\WINDOWS\system32\wwnstrm.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{E1D89784-0681-4639-B5D5-0372FF530FC4}"
HKCR\Clsid\{E1D89784-0681-4639-B5D5-0372FF530FC4}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
|
HiJackThis:
Quote:
Logfile of HijackThis v1.99.1
Scan saved at 12:25:15 AM, on 6/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
|
Been on Opera for about 10 minutes and nothing so far, looking good.
Thanks for the help mate really appreciate it.
|

02-06-2006, 12:33 AM
|
 |
Senior Member
|
|
Join Date: Sep 2005
Posts: 5,524
|
|
|
Re: Help with some popups
Great job,
Let's do an online scan with BitDefender to be sure nothing is hiding in the bushes:
Go here http://www.bitdefender.com/scan8/ie.html and run an online scan with BitDefender (you will need to use Internet Explorer for this scan). When the ActiveX Control has loaded, click on "Click here to scan" and grab a coffee.
When BitDefender completes the scan, select the "Detected Problems" tab. Click on "Click here to export scan". Save the file as an HTML to your Desktop. Then click on the saved file and allow it to open with your browser. Go to Edit - Select All then copy/paste that log back here. Post back and let us know what it found (post the log).
And post a new HJT log also..
__________________
Stalking and killing Spyware
Have we helped you? Please consider a donation to help keep D-A-L free. Click on donate below
MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis Log __V2.0.2 _|
ASAP: promoting a high standard and quality of security support no matter where you seek help.
|

02-06-2006, 02:07 AM
|
|
Newbie
D-A-L Newbie
|
|
Join Date: Jun 2006
Posts: 8
|
|
|
Re: Help with some popups
Looked a bit dodgy when i previewed so I've uploaded it to my host:
http://astution.net/report.html
And here's my new HJT log:
Quote:
Logfile of HijackThis v1.99.1
Scan saved at 2:07:12 AM, on 6/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
|
Once again I offer you my thanks.
|

02-06-2006, 09:06 PM
|
 |
Senior Member
|
|
Join Date: Sep 2005
Posts: 5,524
|
|
|
Re: Help with some popups
How's your computer running now?
__________________
Stalking and killing Spyware
Have we helped you? Please consider a donation to help keep D-A-L free. Click on donate below
MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis Log __V2.0.2 _|
ASAP: promoting a high standard and quality of security support no matter where you seek help.
|

02-06-2006, 09:11 PM
|
|
Newbie
D-A-L Newbie
|
|
Join Date: Jun 2006
Posts: 8
|
|
|
Re: Help with some popups
Working fine again now, no sign of spyware or anything and it's been a while. Was the first time I had spyware in possibly a year, I usually avoid it by being sensible but this one time I was foolish, heh.
|

02-06-2006, 10:23 PM
|
 |
Senior Member
|
|
Join Date: Sep 2005
Posts: 5,524
|
|
|
Re: Help with some popups
Excellent, thanks for stopping by,
If you are no longer having any more trouble here is some preventative measures for you.
Here are some preventive measures you can take to keep your computer from getting infected again. also keep all these and Ad-awareSE and SpybotS&D updated.
Read This First - IMPORTANT Instructions
Flush your restore points in ME and XP, by turning System Restore off and then back on.
This will create a fresh restore point.
Explained Here:
Windows XP: service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam
Explained Here
Microsoft ME:
http://service1.symantec.com/SUPPORT...rc=sec_doc_nam
RegProtect
This small registry protection tool will save you hours of heartache by notifying you when some program good or bad is trying to access your registry.
You have the option of allowing(good) items or blocking(bad)items.
http://www.diamondcs.com.au/index.php?page=regprot
To reduce the re-infection potential for malware and protect yourself against spyware, here are a few helpful suggestions:
1. Keep Windows and Internet Explorer current with the latest critical security updates from Microsoft. This will patch many of the security holes through which attackers can gain access to your computer. You CANNOT complete this update using an alternate browser.
http://v5.windowsupdate.microsoft.co....aspx?ln=en-us
http://www.microsoft.com/windows/ie/default.asp
2. Run your antivirus software regularly, and to keep its definitions up-to-date. If you are thinking about switching, there are a some good free Antivirus programs that are decent, including AVG and Avast!.
AVG: http://free.grisoft.com/doc/1
Avast: http://www.avast.com/eng/avast_4_home.html
3. In addtion to using Ad-aware consider using another free malware scanning/removal program:
Windows Defender
http://www.microsoft.com/athome/secu...e/default.mspx
4. Consider using a free firewall if you are not already using one. Some good free ones are:
Kerio
http://www.sunbelt-software.com/Kerio.cfm
OutPost Personal Firewall:
Outpost
5. Consider using an alternate free browser for general web surfing but you must use IE for windows update.
Mozilla Firefox: www.mozilla.org/products/firefox/
6. Consider increasing your browser security by using these programs:
SpywareGuard will protect your homepage from being hijacked: http://www.javacoolsoftware.com/spywareguard.html
SpywareBlaster will increase browser protection by blocking Thousands of known malware sites by adding them to IE's restricted sites zone. Download it here:
http://www.javacoolsoftware.com/spywareblaster.html
If you use SpywareBlaster, you can also use a customblocklist to add even more entries into IE restricted sites zone. Go to this site for the current list and how to use instructions: http://customblockinglist.cjb.net/
IE-SPYAD is similar in that it adds thousands more known malware sites to IE's restricted zone. Download it here:
https://netfiles.uiuc.edu/ehowes/www/resource.htm
Block access to Untrustworthy Sites
You can prevent your computer from visiting a myriad of untrustworthy sites and ad-servers by installing a customised hosts file. One of the best available is the: MVPS Hosts File. Simply follow the instructions to install the file in the correct location. This will not only make surfing safer but will improve website load times and block popups from many of the large ad-servers.
Mcafee SiteAdvisor
Surf the Net safer with SiteAdvisor, SiteAdvisor notifies you of safe sites or dangerous sites before you ever go there with a simple green check or a red x or a yellow caution when you do a Google search. Just put your cursor on the green check or red X or caution and recieve information about the site.
SiteAdvisor works with Internet Explorer and FireFox.
SiteAdvisor
See what it looks like Here
*Remember just like your primary anti-virus software, it is important to keep all of these programs up-to-date and use them on a regular basis. It's Free
__________________
Stalking and killing Spyware
Have we helped you? Please consider a donation to help keep D-A-L free. Click on donate below
MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis Log __V2.0.2 _|
ASAP: promoting a high standard and quality of security support no matter where you seek help.
|
 |
Similar Threads
|
| Thread |
Thread Starter |
Forum |
Replies |
Last Post |
|
Cid Popups
|
energig |
Spyware, Adware, Viruses and HijackThis Logs |
3 |
28-03-2007 08:54 PM |
|
CiD popups Help!!!
|
kenkilla3 |
Spyware, Adware, Viruses and HijackThis Logs |
1 |
09-03-2007 01:55 AM |
|
CiD: Popups HELP
|
xmom2sixx |
Spyware, Adware, Viruses and HijackThis Logs |
5 |
09-03-2007 01:16 AM |
|
Popups
|
nabed4t |
General Internet Issues and Questions |
0 |
31-01-2007 06:48 AM |
|
getting rid of popups
|
caroline.nixon |
Windows XP Help |
0 |
27-10-2006 09:37 AM |
All times are GMT +1. The time now is 06:45 AM.
|
|