Need help!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by alazo, Nov 17, 2005.

  1. alazo

    alazo Private E-2

    Hello,
    I have followed every single step from the ReadMe First process but I still keep getting publicity popups like crazy. Don't know what else to do....
    I run trendmicro and trojanscan and both said my computer is clean. I then run Ccleaner, Ad-Aware and Spybot and they also say I am clean. I run Hijack This and I don't see where the problem can be. Can anyone PLEASE HELP!!??.
    I am attaching the results from running Hijackthis...


    Thanks in advance for your help....
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can have HJT fix the below line:

    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.38/ttinst.cab

    I would also fix the below unless you know that it is okay:
    O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://hcggmail.hubgroup.com/iNotes6.cab

    When do these popups occur?
    Is it only when connected to certain sites?
    Does it happen when no browsers are opened?
    What do they say and what URL if any is indicated?
     
  3. alazo

    alazo Private E-2

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How do you connect to the internet (dial-up, cable, dsl)?
    Do they occur if your cable to the internet is physically unplugged?

    From a command prompt Window run the below command:

    ipconfig /flushdns

    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    If this does not help, then continue on to run the steps in the below link:



    Running Spy Sweeper...
     
  5. alazo

    alazo Private E-2

    Seems that the ipconfig version I have does not support flushdns. This is what I get when I type "ipconfig /flushdns" at the command prompt

    C:\WINDOWS\Desktop>ipconfig /flushdns
    Windows 98 IP Configuration
    Command line options:
    /All - Display detailed information.
    /Batch [file] - Write to file or ./WINIPCFG.OUT
    /renew_all - Renew all adapters.
    /release_all - Release all adapters.
    /renew N - Renew adapter N.
    /release N - Release adapter N.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's correct! I forgot that Win9x does not support that. Please answer other questions and follow the other steps.
     
  7. alazo

    alazo Private E-2

    OK..here is what happened.

    Running hoster did not help. It kept listing over 60 different urls for 127.0.0.1 even after I deleted them. Then, I installed spysweeper. I ran it and when trying to delete the problems it had found, spysweeper crashed. Seems that it had problems with application "ccapp" running in the background. So I decided to delete Norton antivirus from my system and rebooted.
    After the reboot, hoster updated correctly the host file and spysweeper swept my problems away. The popups are finally gone.
    Thanks a million for your help....!!!!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds