Hijackthis.log: Banner ads try to redirect

Discussion in 'Malware Help (A Specialist Will Reply)' started by charimichan, Dec 3, 2005.

  1. charimichan

    charimichan Private E-2

    Hello,

    My problem is this: banner ads try to redirect me to sites, but my pop-up blocker doesn't allow it, thus causing some sort of infinite loop and the inevitible freezing of my browser. The site that does it 100% of the time seems to be http://www.edmunds.com. So whatever they have for banner ads is killing me!

    I did all of the scans this site asked me to do. And I'm still having the problem, so I ran hijackthis. Here is my log. If someone could help out, I'd be eternally grateful!

    • Edit by bjgarrick: Unrequested, Inline HJT log removed!
     
    Last edited by a moderator: Dec 3, 2005
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download Spy Sweeper
    • Click the link above to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post along with a fresh HJT log.
     
  3. charimichan

    charimichan Private E-2

    OK, I followed your instructions. Here are my two logs.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download AproposFix by Swandog46

    Save it to your desktop or to another folder of its own, but do NOT run it yet!

    Now reboot your computer in Safe Mode! (You must be in safe mode or this fix will not work.)

    Once in Safe Mode, double-click aproposfix.exe which will give you a chice of where to unzip/install the program to). This is called the Destination folder in the window that popsup. So either install it to the Desktop or the folder where you downloaded the aproposfix.exe file to. It will create a new folder named aproposfix. Open the aproposfix folder and double click on RunThis.bat to run the fix. Follow the prompts.

    When the tool is finished, reboot back into normal mode, and post a new HijackThis log, along with the entire contents of the log.txt file that has been created in the aproposfix folder.
     
  5. charimichan

    charimichan Private E-2

    Here are the requested logs. I tried using Edmunds.com and it works fine now! I am very excited that the problem may be solved, thanks to your help. Is there anything else I need to do?
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download this trial version of Ewido Security Suite

    • First, please download and run CCleaner to clean temp files, cookies, etc; to make the log shorter.
    • Install ewido security suite
    • When installing the program, under "Additonal Options" uncheck..
      • Install background guard
      • Install scan via context menu
    • Launch ewido, there should now be an icon on your desktop, double-click it.
    • You will need to update ewido to the latest definition files:
      • On the left hand side of the main screen click update.
      • Then click on Start Update.
    • The update will start and a progress bar will show the updates being installed.
      (the status bar at the bottom will display "Update successful")
    If you are having problems with the updater, you can use this link to manually update ewido. Ewido Manual Updates

    • Once the updates are installed, exit Ewido.
    • Now print the below instructions or save them locally because I want you to have all browsers closed and also have no connection to the internet (unplug your cable) while doing the below:
    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    • While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.
    • Once the scan has completed, there will be a button located on the bottom of the screen named Save report[/size][/color]
    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    • Reboot into normal mode and reconnect to the internet.
    Once your machine reboots please attach the report from Ewido along with a fresh HJT log from normal mode.
     
  7. charimichan

    charimichan Private E-2

    OK. Here is the log and report.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Ewido

    Spy Sweeper

    Viewpoint

    Webdialer


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKCU\..\Run: [60-1-1-120] c:\program files\Webdialer\60-1-1-120.exe -m
    O4 - HKCU\..\Run: [5-1-61-90] c:\program files\Webdialer\5-1-61-90.exe -m O4 - HKCU\..\Run: [5-1-25-386] c:\program files\Webdialer\5-1-25-386.exe -m
    O4 - HKCU\..\Run: [li-speed00138] c:\program files\Webdialer\li-speed00138.exe -m
    O4 - HKCU\..\Run: [5-1-25-358] c:\program files\Webdialer\5-1-25-358.exe -m
    O4 - HKCU\..\Run: [5-2-145-59] c:\program files\Webdialer\5-2-145-59.exe -m
    O4 - HKCU\..\Run: [od-teen52] c:\program files\OnlineDialer\od-teen52.exe -m
    O4 - HKCU\..\Run: [5-4-49-60] c:\program files\Webdialer\5-4-49-60.exe -m
    O4 - HKCU\..\Run: [od-teen88] c:\program files\Webdialer\od-teen88.exe -m
    O4 - HKCU\..\Run: [li-nolle00000] c:\program files\Webdialer\li-nolle00000.exe -m

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} - http://207.188.7.150/1922ec115d7c04f1f003/netzip/RdxIE.cab
    O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (IEInstallObj Class) - http://cdnserv001.colocenters.com/common/tukati.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    C:\Program Files\Viewpoint ←–– Delete this whole folder if it exist!

    C:\Program Files\Webdialer ←–– Delete this whole folder if it exist!

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  9. charimichan

    charimichan Private E-2

    OK. Here is the new log.
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean, are you having any further problem?
     
  11. charimichan

    charimichan Private E-2

    Awesome. Everything seems back to normal.
    Thank you very much. Anything else I should do?
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  13. charimichan

    charimichan Private E-2

    Will do. Thanks again.
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Surf Safely!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds