POP UPS and BROWSER HIJACKER

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by minler, Jun 9, 2005.

  1. minler

    minler Private E-2

    I have complete all of the steps outlined in the your "how to: Spyware, Trojan, & Virus removial" including the optional steps and and alternative scans, but I still have the popups, browser redirection and several undesired additions to my favorites in IE. I have ran Security Task Manger and keep finding two suspicious files that I keep removing but they keep coming back, rdsndin.exe & cisvvc.exe. When I attemp to see them in windows explorer they are not visible even with show hidden file types selected. I appreciate any help. Thanks.
    Minler
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. minler

    minler Private E-2

    This is the the attached log file from HJT. Thanks for any insight.
    Minler
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log shows no apparent problems.

    Did you place the below restriction on your system?

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Perhaps if you disable or uninstall Security Task Manager so the problem can make itself visible, then we can figure out how the best fix the problem.

    What are the popups about? Do they give a URL?


    Try the following. Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Now tell me how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds