Another Free6.se problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SuPeR`Yue, Dec 29, 2004.

  1. SuPeR`Yue

    SuPeR`Yue Private E-2

    Re: Free6.se problem

    Hi,

    I've the same Free6.se problem too.

    In addition, the below pop-ups with the links would also pop-up.

    1) -http://540.scmg.net/randomsites/banner.aspx
    directing to the page
    http://www.google.se/search?hl=&q='george+bush+idiot'

    2) -http://194.237.110.186/randomsites/banner2.aspx?day=28&hour=17

    Is it possible to help me see what's the problem with my log file. Thanks alot.

    Edit by chaslang: Inline log and unrequested attachment deleted.
    Please follow forum guidelines.
     
    Last edited by a moderator: Dec 29, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Free6.se problem

    Start your own thread and followed the steps of the READ ME FIRST. PLEASE DO NOT POST inline HJT logs and do not post them unless we ask for them.

    EDIT: I'm moving you to your own thread. The original thread you posted in was:
    http://forums.majorgeeks.com/showthread.php?t=49305

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
    Last edited: Dec 29, 2004
  3. SuPeR`Yue

    SuPeR`Yue Private E-2

    Hi,

    I've ran Spybot S&D but all they found was Alexa and nothing else. I fixed it already but the pop-ups still appears. i Have also ran HijakThis already. I also done a full system scan with my norton anti-virus program. What shld i do next? Thanks alot.
     
  4. SuPeR`Yue

    SuPeR`Yue Private E-2

    Hi again,

    Here's my HijakThis file. Hope you guys can work something out for me ;) Thanks alot.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run ALL of the steps from the READ ME including the online scans. Your log shows they were not run. What else did you skip? Running ALL the steps is not optional. Please complete them. If you are having a problem running certain steps, you need to tell us.

    And remember what we said, "before using HJT all browsers must be shut down". You had these running:
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    You can have HJT fix the following:

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2 (file missing)

    But you must complete ALL of the READ ME FIRST steps.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds