getting many pop ups

Discussion in 'Malware Help (A Specialist Will Reply)' started by wesburnsco86, Apr 25, 2005.

  1. wesburnsco86

    wesburnsco86 Private E-2

    Ive been here times before but not sure how to read HJT.Ive removed a few things with(read this before posting).Still getting pop ups bad!!
     
  2. wesburnsco86

    wesburnsco86 Private E-2

    by the way one problem im sure i have is called msole32.exe
    causes a triangular sign in my taskbar
     
    Last edited: Apr 25, 2005
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See http://www.virus-buster.com/en/viruslab/descriptions/sambud.n

    Did you complete all steps in the READ ME FIRST. If so, do the below.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. wesburnsco86

    wesburnsco86 Private E-2

    not sure where to look and delete msole32.exe
    log file attached tho.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps in my message exactly. You do not have the current version of HijackThis.
    Did you search your PC for the msole32.exe file?
    According to your HJT log, it is here: C:\WINDOWS\System32\msole32.exe


    You could also use the below to find files like this.
    If you use Search, you need to do the following:
    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter msole32.exe
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.

    You have other problems too. Get the new HJT program and post a new log.
     
    Last edited: Apr 25, 2005
  6. wesburnsco86

    wesburnsco86 Private E-2

    sorry here it is,with the new version
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you found and deleted the msole32.exe file?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember to exit all browsers (C:\PROGRA~1\MOZILL~1\FIREFOX.EXE) before running HJT.

    Go to Add/Remove programs and uninstall if found
    Security iGuard

    Let me know if you find it there.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
    O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitekpz32.exe

    Nothing (not even majorgeeks) belongs in the Trusted Zone.
    O15 - Trusted Zone: http://www.majorgeeks.com
    O16 - DPF: {2D3F1F38-4BD7-0A75-F6BC-04235BEE35CA} - http://216.118.71.185/1/rdgUS1828.exe
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Security iGuard <--- the whole folder
    C:\windows\system32\elitekpz32.exe <--- also delete all other file names beginning with elite and ending with .exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. wesburnsco86

    wesburnsco86 Private E-2

    yes msole32 was deleted among others.Could not find security I-Guard.
    let me know if you see anything else wrong.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You did not get the below fixed:


    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitekpz32.exe

    Repeat the steps. Make sure hidden & system file viewing is enabled. Also make sure you look for ALL files named elitexxxxx.exe (where xxxxx can be anything). Delete all of them.
     
  11. wesburnsco86

    wesburnsco86 Private E-2

    how bout now.....
    thanx for the help by the way
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's better!

    Is everything working okay now?
     
  13. wesburnsco86

    wesburnsco86 Private E-2

    things are fine thanx again.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy I could help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds