pop-ups just keep coming...help!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by playmates, Oct 30, 2004.

  1. playmates

    playmates Private E-2

    i have pop-ups that always show up if i open my hotmail or i.e. and they are always from the same 2 damn sources.
    i have adaware 6.0 and spybot and cwsshredder and have used them all to no avail. they all come up with no threats found. i have every single pop-up blocker enabled and they still get past that.
    i thought i had found them when i went into misconfig - startup and discovered 2 unidentifiable programs there. i disabled them, restarted and evrything seemed great for an hour or so, my system ran tons faster and no popups but then they started showing up again.
    they are really starting to annoy the hell out of me, what can i do next? anyone have any ideas?
    thanx
     
  2. Kodo

    Kodo SNATCHSQUATCH

  3. playmates

    playmates Private E-2

    thanks for replying to my scream for help, i did everything in the tutorial before i posted and no success the popups are still here. (i meant to say that before~sorry)
    have now run Hijack this and have attached the log.

    thanx
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you were using Ad-Aware 6.0, you did not follow our tutorial. In addition, you did not run the Symantec online scan. Online scans quite often find things that full blown virus applications due not. Is there anything else you did not run or negelected to check for the proper versions of?

    Your problem makes me wonder of what use PopUpStopperProfessional is to you.

    Questions:
    1) Did you put thie in your Trusted Zone: http://www.elizabeth.fkon.com
    2) What do you expect to have for you start and search pages? Is it supposed to be that yahoo (red.clientapps.yahoo.com) stuff?
    3) Why are you running msconfig at startup? What is it that you are selectively not loading? We may need to see it. It is not a good idea to use msconfig to permanently avoid loading items. A startup manager program would be better.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below process and End it:
    DeskMateAutoUpdate.exe

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\localNRD.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\system32\msbe.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F3 - REG:win.ini: load=??? ?
    F3 - REG:win.ini: run=??? ?
    O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dll
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    As far as I know DeskMateAutoUpdate is part of BargainBuddy problems (see http://www.pestpatrol.com/PestInfo/b/bargainbuddy.asp)
    Unless you know this is for something different fix the next line too, otherwise skip and continue.
    O4 - HKLM\..\Run: [DeskMateAutoUpdate] C:\PROGRA~1\DESKMA~1\DeskMateAutoUpdate.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\localNRD.dll
    C:\WINDOWS\system32\msbe.dll
    C:\PROGRA~1\DESKMA~1 <--- if it was BargainBuddy delete the whole directory
    C:\Program Files\AWS <--- the whole directory if found

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. playmates

    playmates Private E-2

    i dont know why but i was unable to download the other version of adaware i kept receiving a' download failed ' message so had to rely on the adaware version i have already. as for the symantec online scan i have tried to run this numerous times and it fails to complete and asks for me to restart scan.

    elizabeth.fkon.com is my website but i dont know how it ended up in trusted sites.
    the red.clientapps.yahoo.com stuff i am not sure what that is, when i go on to i.e yahoo is supposed to be my home page.
    i was advised on another site to run msconfig and close down programs and applications that were not necessary for startup to narrow down the possibility of the ads being linked to a startup program. there were 2 there that i didnt know which i disabled (the names were all box icons) this caused no effect on my comp except to speed it up and the popups stopped for about an hour.
    Deskmateautoupdate.exe was not in the task manager so could not end it.
    i am just about to try and download the adaware and try again on the symantec scan.
    if this still fails do i still go ahead with the hijack this?

    i really appreciate everyones help in this , thanks.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to fix those items with HJT now. Don't wait. Stop using msconfig too. What were the names of the items you told it not to load.

    The procedure I gave to you needed to be run from beginning to end without doing anything else in between once you looked for DeskMateAutoUpdate.exe to be running, you should have continued on with the rest whether it was running or not. You should not be looking to download the Ad-Aware SE or do a Symantec scan in the middle of the process. Please follow the steps I give you exactly in the order written, only doing what I request.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds