Free6 Popup

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TT27, Oct 30, 2004.

  1. TT27

    TT27 Private E-2

    Hi guys,

    I have a persistent free6 popup problem that is annoying. I've run all of the spyware programs suggested in "Read me before asking for support". I've run HijackThis and I was wondering if someone could look at the log and see if there is any issues? Thank you in advance!

    TT
     

    Attached Files:

  2. PhilliePhan

    PhilliePhan Guest

    TT27,

    You are running HJT improperly. Please place it in its own safe folder - C:\Program Files\HijackThis

    I see a few issues in your log that can be addressed after you have done the above.

    By the way, did you edit the running process list in any way before attaching your log?

    PP
     
  3. TT27

    TT27 Private E-2

    PP,

    Thanks for the response. I have confirmed HJT is filed per your instructions. I did not edit the log that I attached.

    TT
     
  4. PhilliePhan

    PhilliePhan Guest

    Hi TT27,

    It's probably a good idea to attach a fresh log, in case some things have changed. Please do so now. I should have asked in my last post - sorry! :)

    PP
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PP,

    The READ ME FIRST does not look like it was followed. No signs of the online scanners exist.
    So either:
    - the log is edited or
    - it is being filtered using the Ignorelist feature of HJT
    - or the READ ME FIRST was not followed
     
  6. PhilliePhan

    PhilliePhan Guest

    Hey Chas,

    I've already worked through the old log - Just waiting for a new log to make sure they match up ok. Hey TT27 - In case you missed my last post, please attach a fresh log.

    By the way, I am also looking at raygt13's log - Could you do me a favor and merge his three threads together?

    Thanks,
    PP
     
  7. TT27

    TT27 Private E-2

    PP & Chaslang,

    I'm forwarding a fresh log per your request. I did follow the steps suggested in "Read Me First" about a week ago. I only learned of the HJT program through these instructions. Perhaps I did not install the online scanners correctly but the icons still show on my screen. Sorry for any confusion. Thank you again for your help.

    TT
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The online scanners do not install but they do download files that should appear in the O16 section of your HijackThis log. So since they do not appear, it means they could not have been run.
     
  9. PhilliePhan

    PhilliePhan Guest

    Hi TT27,

    You are still running HJT improperly. You have it here: C:\DOCUME~1\STEVE\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

    You MUST EXTRACT IT to its own SAFE FOLDER - C:\Program Files\HijackThis before proceeding with the following instructions. Let us know if you have trouble doing this.


    Please turn System Restore OFF and enable the Viewing of Hidden Files.

    Please shut down this running process via Task Manager (if found)
    ?hkntfs.exe

    Now, run HijackThis and Check the Boxes for the Following:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://media71.fastclick.net/w/safepop.cgi?mid=34789&sid=8627&id=101413&len=245&c=4&nfcp=1&fp=2

    O2 - BHO: (no name) - {4BA2435C-EA60-26E5-8027-635579F12E12} - C:\WINDOWS\System32\ihzqpd.dll (file missing)

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKCU\..\Run: [Geos] C:\WINDOWS\System32\?hkntfs.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\system32\vbsys2 (file missing)


    Make sure ALL Browser Windows are Closed before you Click FIX.

    Now, boot into SAFE MODE and delete the following:
    C:\WINDOWS\System32\?hkntfs.exe

    Reboot to Normal Windows and attach a fresh log and tell us how things are working.

    I'll try to check back when I get a chance.

    Best
    PP
     
  10. TT27

    TT27 Private E-2

    Hi PP,
    I followed your steps (sorry about the HJT location) and I attached a fresh log. I had previously turned System Restore OFF and enabled the Viewing of Hidden Files. However, I could not locate ?hkntfs.exe via Task Manager and shut it down. After running HJT, I looked for C:\WINDOWS\System32\
    ?hkntfs.exe but could not locate it while in SAFE MODE. Please let me know if I need to take additional steps. Thank you again in advance for all of your help.

    TT
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. TT27

    TT27 Private E-2

    PP & Chaslang

    Thank you again for all of your help. You are life savers!

    Best Regards,
    TT
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess PP hit the sack early tonight so I'll so you're welcome from him (he did most of the work) and me.
     
  14. PhilliePhan

    PhilliePhan Guest

    Just midnight snackin'! He's right TT - We're happy to help :)

    PP
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oooooh! I was going to add "or stuffing his face". I knew I should have! :D
     
  16. PhilliePhan

    PhilliePhan Guest

    Oh come on now!! I let you off the hook the other day when you dropped that OH SO LAME 10 Fast 10 Furious (was that really the best you could do :p ) and this is how you play me!!?? ;)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you expect? You the one the that said you went to get a snack. :D What was it Holloween candy! Trick or Treat!
     
  18. PhilliePhan

    PhilliePhan Guest

    No. . . Baskin Robbins Ice Cream. You MUST be well acquainted with their 11111 flavors ;)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't they have more flavors then that now? Personally I think the best two flavors were the ones by Haagen Daz and they stopped making them: chocolate chocolate mint and heavy belgium fudge.
     
  20. crasher

    crasher Private E-2

    I spent all day on this one and eventually found an article which worked for me on: http://forums.thetechguys.com/archive/index.php/t-10827.html

    The bit which really did it was looking for and deleting the files under windows/system32 The offending item in my case was C:\WINDOWS\System32\vbsys2

    Did this in safe , cleared the temps, cookies, recycle and rebooted SUCCESS!

    Hope it helps

    Crasher
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    TT27's problem was solved 24 days ago and vbsys2 was mentioned back on 10/30 too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds