Can't kill the pop ups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by auron99ie, Apr 15, 2005.

  1. auron99ie

    auron99ie Private E-2

    Re: Can't kill the pop ups by myself, need help please!

    Hi,
    I've been following this thread since it started and i think i have the same problem, it also started around the same time. I've tryed a load to get rid of it but there's always some left. I've gone to the point of post #7, just before downloading hoster? bjgarrick, i'm just wondering should i continue and do the same things you described for Plane Nuts, or would mine be a different case. I've also attached my hijack this file. Note- the popups don't seem as bad now, but they're still there?Also they started around the same time as i got EliteBar, but I've managed to get rid of that. Finally the became a lot more frequent when i was doing the online scans, I'd leave my computer for 5 minutes and theyre'd be 15+ popups...
    Thanks very much for your help
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't kill the pop ups by myself, need help please!

    You need to post in your own thread. We prefer not to work multiple user problems in the same thread because it always leads to confusion. And typically the problems on each PC are not exactly the same (as is the case here) and they may not even be the same OS. I'm moving you into your own thread. For reference purposes, you originally posted in: http://forums.majorgeeks.com/showthread.php?t=60362

    In the future do not post requests for help in another users thread. Also, please do not post HJT logs unless requested.
     
    Last edited: Apr 15, 2005
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't kill the pop ups by myself, need help please!

    Do you know why you have the below ProxyServer setting?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [motoin] C:\WINDOWS\mm15201518.Stub.exe
    O4 - HKLM\..\Run: [sixtysix] C:\WINDOWS\sixtypopsix.exe
    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitefex32.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\mm15201518.Stub.exe
    C:\WINDOWS\sixtypopsix.exe
    C:\windows\system32\elitefex32.exe <--- also look for and delete other files beginning with elite and ending with exe. There could be as many as ten more.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  4. auron99ie

    auron99ie Private E-2

    Firstly, I'm sorry abot posting in the wrong forum, I didn't know, I'll take care not to do it in the future.
    No, off the top of my head I don't why I have the proxy setting, is there something wrong with it?

    I fixed the problems in HJT, but when i rebooted i couldn't find mm15201518.Stub.exe or sixtypopsix.exe. I did find elitefex32.exe(and several more elite files!) and deleted them but HJT still says elitefex32.exe is there?
    But as for the popups, I haven't seen any since I rebooted about 10minutes ago :) , but I've thought that before and they've come back... :mad:
    Thanks for the help so far, I've attached the new log also
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not post in the wrong forum! You posted in a thread that belongs to someone else.

    You may have missed some of the elitexxxx.exe files. You must make sure you have the following options setup.

    Right Click Start.
    Select Explorer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitefex32.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\system32\elitefex32.exe <--- also look for and delete other files beginning with elite and ending with exe. There could be as many as ten more.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. auron99ie

    auron99ie Private E-2

    Ok elite... isn't being detected by HJT, after the last fix, but I couldn't find any more elite...exe files.
    Well all seems well now!Haven't got a popup since yesterday, woohoo! :D
    Thanks very much for your help! Hope the HJT file looks ok now!
    Thanks again!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds