IE Browser Hijack and Popups

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cahliuel, Oct 15, 2005.

  1. Cahliuel

    Cahliuel Private E-2

    I normally use Firefox, and IE suddenly produced some popups. I checked my processes, and these are the exe viruses that I found - shnlog.exe, intmon.exe, and popuper.exe. I have already went through the cleaning of all the "READ AND RUN ME FIRST" links and also went through the "Hijack This" process and attempted to fix all my known viruses. I selected the O2-F.......FA and ctfmon.exe in the hi-jack this program and tried to fix them but they came back. Also I get really long boot up times now.

    It sends me to the www.patchyoursystem.com site where i found out about the PSGUARD and Spytrooper viruses (no I did not d/l or click on them) when I start IE also.

    Much Appreciated,
    Cahliuel
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please make sure System Restore is OFF.

    Please do the following:

    How to view hidden, system files & folders!


    Searching for Hidden Files on WinXP


    Using Add or Remove Programs in the Control Panel; uninstall the following:
    Download
    - Pocket Killbox

    In HJT Choose Open the Misc Tools Section choose Process Manager, Highlight:
    Choose Kill Process

    Now scan and have HJT Fix the following:
    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Run HijackThis and post a fresh log as an ATTACHMENT.
     
  3. Cahliuel

    Cahliuel Private E-2

    Thanks a bunch! I think that fixed it, well mostly
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please post a fresh HijackThis log. So, that I can verify the fix took.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds