Can' get rid of pop up web pages

Discussion in 'Malware Help (A Specialist Will Reply)' started by jimmy5000, Apr 14, 2005.

  1. jimmy5000

    jimmy5000 Private E-2

    Have run spybot search and destroy, spyware doctor and ad-aware but still keep getting pop-ups of web pages like 'adddynamix' and other similar.

    How do I get rid of these pop ups?

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. jimmy5000

    jimmy5000 Private E-2

    Re: Can't get rid of pop up web pages

    Hi Chaslang,

    Thanks for the help, I did everything suggested in the link and I thought it had fixed the problem completely - however, I am still receiving one or two of the old pop-ups: Adultdater (I think that's the name!)is one that I still get..
    I have run HJT and attached the file.

    Thanks very much for your help:)
    J
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't get rid of pop up web pages

    Are the below two lines for your ISP?
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dunton.visteon.com,visteon.com,vcs.visteon.com
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dunton.visteon.com,visteon.com,vcs.visteon.com


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\??oolsv.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {41D13364-D9FD-C31C-D2EA-850A7B09F194} - C:\WINDOWS\System32\okb.dll
    O2 - BHO: (no name) - {48D13317-D9FD-C515-D2EE-F00A7209F197} - C:\WINDOWS\System32\okb.dll
    O4 - HKCU\..\Run: [Atnd] C:\Documents and Settings\jnorton4\Application Data\aeeh.exe
    O4 - HKCU\..\Run: [Cxol] C:\WINDOWS\System32\??oolsv.exe
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O15 - Trusted IP range: 206.161.125.149
    O16 - DPF: {11111111-1111-1111-1111-222222222222} - ms-its:mhtml:file://d:\foo.mht!http://t058.com/inst//x.chm::/open.exe
    O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
    O16 - DPF: {43331111-1111-1111-1111-611111195622} - file://c:\ex.cab
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\okb.dll
    C:\Documents and Settings\jnorton4\Application Data\aeeh.exe
    C:\WINDOWS\System32\vbsys2.dll
    c:\ex.cab
    c:\eied_s7.cab

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. jimmy5000

    jimmy5000 Private E-2

    Hi Chaslang,

    Thanks for all those instructions - I think it all went as planned.

    1) Yes those two lines relate to a VPN I use at work for a company called Visteon.

    2) When I clicked fix as you said, an error window headed 'HijackThis' popped up saying:

    Unexpected Error #75
    @Procedure
    modbackup-makebackup(sidem=016 - dpf:{33331111-1111-1111-1111-6111111193458} - file://c:\ex.cab

    Please email merijn@spywareinfo.com with a HJT log and details.


    3) After I pressed ok, no further problems
    4) You specified 5 files to delete, but only vbsys2.dll existed.

    Is the error a spoof or something that might cause a problem?

    Thanks again for your invaluable help. I have posted a new HJT log with this note.

    J
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have not seen that error message with the latest versions of HJT Older versions did have some problems like that. I would not worry about it. Your log is clean now. To help it stay that way you should complete all steps in the below:

    How to Protect yourself from malware!
     
  7. jimmy5000

    jimmy5000 Private E-2

    Chaslang,
    I am very grateful for your help and advice.
    Many thanks.

    J
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds