ads1.revenue and yazifind popups

Discussion in 'Malware Help (A Specialist Will Reply)' started by AlanLipscomb, Feb 1, 2005.

  1. AlanLipscomb

    AlanLipscomb Private E-2

    I have these two popups coming up at different times. I have Mcafee Security Center Running and Mcafee Anti-Spyware installed and detected nothing.

    Hijackthis Log:

    Logfile of HijackThis v1.99.0
    Scan saved at 9:52:22 PM, on 2/1/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Unrequested, inline log deleted

    Any help would be appreciated.
     
    Last edited by a moderator: Feb 2, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is not the first step and we have guidelines that must be followed about how to use HJT and how to post logs. Please read and follow our sticky threads.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    What is your expected home page?
    Is it C:\WINDOWS\about.htm

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    After getting HJT installed in the proper folder do the following:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\WINDOWS\system32\gtowqo.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [gtowqo] C:\WINDOWS\system32\gtowqo.exe
    O15 - Trusted Zone: http://www.neededware.com
    O16 - DPF: NDWCab - http://www.neededware.com/NDWCab.CAB

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\gtowqo.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Reset your home/start page to what you want.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  3. AlanLipscomb

    AlanLipscomb Private E-2

    Would love to do the required list but the links available for the dozen programs needed for download are not working.
     
  4. PhilliePhan

    PhilliePhan Guest

    Please check your Hosts file and tell us what it says.

    C:\Windows\System32\Drivers\Etc\Hosts - Open with Notepad.

    You may be being blocked by malware.

    PP :)
     
  5. AlanLipscomb

    AlanLipscomb Private E-2

    Just has local host on there.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't think that's the problem PP. Some locations cannot access the main page or file systems. I have had problems myself most of the day. Others have no problems. I know from NJ and CA. We had no access but NY State has no problem.
     
  7. AlanLipscomb

    AlanLipscomb Private E-2

    So basically Im screwed? Or go search and download elsewhere?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. PhilliePhan

    PhilliePhan Guest

    You know me . . . Always suspecting the worst! ;)
     
  11. AlanLipscomb

    AlanLipscomb Private E-2

    I have already started searching and dowloading.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Seems to be theplanet.com. A trace route times out there. We are working on it.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I gave you some links below. Try them!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. AlanLipscomb

    AlanLipscomb Private E-2

    Let me rephrase my last post. I have those downloaded already. There is no download for the Spybot exploit that I can find though.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think we were one of the very few that had it available. If I find a link I'll post it. We are working on fixing the problem with the main board and file archives.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Here is a link to Spybot DSO Exploit fix

    http://news.swzone.it/link.php?action=d&id=12932
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds