Could really use some help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BCT, Oct 6, 2004.

  1. BCT

    BCT Private E-2

    First off let me say that I read this site a lot and have learned some valuable info due to that fact. My problem is I went to a site that I always go to a few days (ezboard) ago and got hit with all sorts of nasty stuff. Mostly droploaders (if that's what they're called )and generally sluggish surfing and low system resources.
    I read the sticky threads above and followed the instructions as best I could. I downloaded all the programs, updated, and ran them and fixed what they found. My lingering problem is with popups in IE. I'll be looking at a site and all of a sudden a window will load that says "advertising window powered by paypopup.com" and then after a bit a full page of advertising will open. IE is slow to open and sometimes I'll get a "not responding" message and have to end task before it will work again.

    As computer illiterate as I am I probably shouldn't have but I downloaded hijackthis and did let it fix some of the things that I knew shouldn't be there. I ran the last log through a HJT anylizer and it came up clean but I still have the popups and a very sluggish machine. Any help would be most greatfully appreciated.
     
  2. Kodo

    Kodo SNATCHSQUATCH

    lets have your log
     
  3. BCT

    BCT Private E-2

    Sorry but I had to C&P the log here. The manage att. button wouldn't open for me.
     

    Attached Files:

    Last edited by a moderator: Oct 7, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run the online scans. Why? Is there anything else you skipped from the Read ME?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Spykiller its on a list of rogue/fake spyware removers.

    Make sure viewing of hidden files is enabled.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    O2 - BHO: Zedd4Proj.clsUnoOne - {08227B4B-54FE-4C4D-809F-BCA46292FC5B} - C:\WINDOWS\SYSTEM\AANTX.DLL
    O4 - HKLM\..\Run: [edow.exe] C:\WINDOWS\edow.exe

    Did you put this restriction in place using some tool like SpyBot S&D? If not, fix the line below too.
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Then boot in safe mode and delete:
    C:\WINDOWS\SYSTEM\AANTX.DLL
    C:\WINDOWS\edow.exe

    Now boot in normal mode and come back and tell us how things are working. If still having a problem, tell us what it is and post a new HJT log.
     
  6. BCT

    BCT Private E-2

    chaslang
    I really did run all the programs that are in your list to the best of my ability. There was one that wouldn't load on 98SE but the others did ok. I ran several hijackthis scans after running those and I'm sure I ended up deleting some of the stuff that I ran from the list.

    I attached another scan and it appears to be clean. My system is running normal so far(been about an hour since I fixed the entries) so looks like it may be gone.

    One thing I did notice was the spykiller.exe entry. I couldn't find it anywhere on my system. I searched and manually looked where it was supposed to be but nothing was there. 2 of the other entries were not there either but it seems hjt took care of it.

    If I have anymore trouble I'll let you know and thanks so much for your help. :)
     

    Attached Files:

  7. Kodo

    Kodo SNATCHSQUATCH

    it does look clean.
    let us know if you have any more problems ;)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! The online scans leave information in the O16 section of your HJT log and I did not see them. That is why I thought you did not run them. In the future, when having a problem, it would be better to not fix anything until you have posted a log for us to look at.
    I did see the Bitdefender info in the O16 section though.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds