pop up at sign on

Discussion in 'Malware Help (A Specialist Will Reply)' started by jtpiano, Jan 9, 2005.

  1. jtpiano

    jtpiano Private E-2

    I trust I am going to the correct forum. Please forgive me if not. I have been getting a pop up window when I first sign on to my pc. It says- You or another program have requested information from www.ysweb.com (sometimes a different web site is listed). Which connection would you like to use? It then lists my two dial up connections. I have used Spybot S&D 1.3 and AdAware 1.05 to check for problems and I still keep getting this mesaage at startup. Both programs are updated. I also have Norton AV which is updated. None of the above programs seem to catch anything. So I ran hijack this. I did notice a processs that I am suspicious of called wtuvmy.exe I rather suspect this needs to go. I could find no info for it on the web. Your help is greatly appreciated!
     
  2. bem

    bem Private E-2

    Only reference I could find at all was in Chinese. Not a good sign...

    I wouldn't mess with it till you get some qualified help. No telling what it will do if it feels threatened...
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it sounds like you have a few problems one of which may be VX2 and or Qooligic related. The first things we need to do is get you into a know state. Please follow the directions below and we will continue with additional manual cleanups after that as necessary.
    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  4. jtpiano

    jtpiano Private E-2

    OK, I went back a ran through all the steps again exactly as listed in the directions. I missed doing an online virus scan the first time. Trend Micro came up with two viruses listed and removed them for me. Norton AV came up clean for me (which is what I already have on my PC). I went through all the spyware cleanup and came up clean. I am still getting the popup about "You or some other program have requested information from "website". Which connection would you like to use?" The process I suspected was illegitimate was a virus according to Trend Micros online scan. Now I am baffled. Why the popup?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME FIRST does not ask you to run Norton AV is asks you to run an online scan at Symantec. They are quite often not the same. The online references are often updated more frequently than the full AV package definitions.

    Complete the rest of my directions!
     
  6. jtpiano

    jtpiano Private E-2

    I beg your pardon. What I meant to say was, I did do the online scan at Symantec I just used the wrong term (Norton AV). I just didn't understand the difference between the online and what was already on my PC. Thanks for the clarification. I find it odd that the same company can provide two similar type products yet one is much better than the other? The rest of the directions were completed as you asked before I posted the second time. I guess I should be more explicit in my replies.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The rest of my directions were not completed. I'll repeat them:

     
  8. jtpiano

    jtpiano Private E-2

    Here is my log as requested.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would guess that the following line is your problem:

    F1 - win.ini: load=c:\01comm32\bin\01comm32.exe

    Do you know what 01comm32 is? If not, do the below steps:


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F1 - win.ini: load=c:\01comm32\bin\01comm32.exe

    After clicking Fix, exit HJT. Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    If this has fixed your problem, I would then think about deleting the c:\01comm32 folder.
     
  10. jtpiano

    jtpiano Private E-2

    I would guess that the following line is your problem:

    F1 - win.ini: load=c:\01comm32\bin\01comm32.exe

    Do you know what 01comm32 is? If not, do the below steps:

    Yes, it is my fax software.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure this is legit? Is it a cracked or pirated version?

    What application gives you the pop up warning? Is it a firewall? Doesn't it tell you which application is trying to run?
     
  12. jtpiano

    jtpiano Private E-2

    This is OEM software that came with my modem. I can't tell what application gives me the pop up; it is just there at sign on. I'll post a jpeg.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This could just be C:\Program Files\Messenger\msmsgs.exe
    Do you use messenger?
    If not you could use this, Uninstall Messenger and see if you still get that popup.
     
  14. jtpiano

    jtpiano Private E-2

    I think I found my problem. There is a PowerReg Scheduler next to a 04 section entry. Other sites tell me this is a type of adware that gets unknown information from the web. I didn't recognize this and on a whim tried to find some information about it. BTW I do use MSN Messenger. As I indicated in my first post, the popup look for different sites. I'll cross my fingers and see what happens. I can always undo later if needed.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PowerReg Scheduler is a registration scheduler. Periodically attempts to connect to the Internet. Gathers unknown information. It is not necessarily a problem but it is not required either and yes it could be your problem too.

    Messenger is not the same as MSN Messenger.
     
  16. jtpiano

    jtpiano Private E-2

    Well I guess I don't use messenger then. What is it? I did disable power reg using HijackThis. Everything seems to be ok now. I am not seeing the window when I sign on anymore.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Messenger is Windows Messenger!
    MSN Messenger would appear as MSN Messenger.

    They are differenet. Perhaps you are just using Windows Messenger.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds