1. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    for some reason i keep getting popups. i have used adaware, cwshredder, aranea scanner, winpatrol, and hijack this. here is the log

    Logfile of HijackThis v1.97.7
    Scan saved at 8:47:35 PM, on 10/10/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    EDIT by chaslang: old version of HJT, inline & unrequest log deleted

    If you can help Thanks

    Chrispy
     
    Last edited by a moderator: Oct 10, 2004
  2. PhilliePhan

    PhilliePhan Guest

    Your HijackThis is old and running from the desktop. Please download an up-to-date version and place it in a safe folder - C:\Program Files\HijackThis
    You ought to start here:
    http://forums.majorgeeks.com/showthread.php?t=35407
    This is a good start for cleaning your machine.

    Hijack this MUST be in a safe folder before you fix the following:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...6f1667345607db7
    O16 - DPF: {54771E6F-A5A2-4413-8FB8-7B8F85398174} - http://dl.lygo.com/Sidesearch/en_US.../Sidesearch.cab
    O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab

    You have a lot of 016 entries that appear to be ones you might want to keep, but are conducive to malware & popup problems. This is just a start - Run through the tutorial & post back as to the results.

    Best luck :)

    PP
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    alright, i did all the scanning and stuff. sorry about before, i neglected to read the stickys. ok i have a completely scanned comp now. just incase there are still problems i have attached the log. i had to make it into a zip file because it said the file was invalid
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The sticky tells you to post it as a text file attachment. You need to save it to a .txt file instead of a .log file.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These must not be running when you run HijackThis:
    c:\program files\internet explorer\iexplore.exe
    C:\Downloads\AboutBuster\AboutBuster.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled.
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them (if found):
    winset32.exe
    lwpo.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O4 - HKLM\..\Run: [winset16] C:\WINDOWS\System32\winset32.exe
    O4 - HKCU\..\Run: [Taru] C:\Documents and Settings\user\Application Data\lwpo.exe
    O4 - HKCU\..\Run: [winset16] C:\WINDOWS\System32\winset32.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=4e2fe0f01d3c952e6d384697f56ea291d476d6a5c3fb7feba963d66d2d60b787f8baff8b35c2c5cfc39ca44b4686764c90ad2d0ea95e2dc68c0c85897c6d99a421:1616f1ee1695779646f1667345607db7
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/bestfriends/retro64_loader.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {54771E6F-A5A2-4413-8FB8-7B8F85398174} - http://dl.lygo.com/Sidesearch/en_US/tripod/Sidesearch.cab
    O16 - DPF: {62CE3CBC-B889-423A-9457-2FE7A731BBD8} (UpdateStart Class) - http://eng.pristontale.com/autorun/pristontale.cab
    O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
    O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://mirror.worldwinner.com/games/shared/wwlaunch.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab


    Boot in safe mode and use Window Explorer to delete:
    C:\WINDOWS\System32\winset32.exe
    C:\Documents and Settings\user\Application Data\lwpo.exe


    Reboot normal mode and post a new HJT log attachment and tell me how things are working.
     
  8. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    ok. i did everything you told me to. but when i deleted winset32.exe, it came back after i rebooted from safe mode. here is the log.
     

    Attached Files:

  9. PhilliePhan

    PhilliePhan Guest

    Hey J0in_THE_NAVY,

    winset32.exe can be hard to pin down. You could try booting to Safe Mode and searching for the file. Try renaming it to something like winset32.bad.
    Then, boot normal and have HJT Fix these:

    O4 - HKLM\..\Run: [winset16] C:\WINDOWS\system32\winset32.exe
    O4 - HKCU\..\Run: [winset16] C:\WINDOWS\system32\winset32.exe
    O4 - HKCU\..\RunOnce: [*winset16] C:\WINDOWS\system32\winset32.exe


    if they are there. See if that helps.

    Best luck,

    PP
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are these running when using HijackThis?

    C:\Program Files\Kazaa Lite K++\KazaaLite.kpp
    c:\program files\internet explorer\iexplore.exe

    And personally I would not use anything related to Kazaa!
     
  11. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    ok. i did all that good stuff but im still getting this weird popup. its from http://www.ad-w-a-r-e.com/callback_ron.php?GUID={4E707E4C-50F6-484F-AFAE-F9D0E110C1EE}&country=US&type= and it comes up every like 10 minutes. is starting to piss me off here is the hijackthis log
     

    Attached Files:

  12. PhilliePhan

    PhilliePhan Guest

    I've seen it suggested that the VX2 Plugin for Ad-awareSE deals with this problem. Perhaps you should give that a try.

    Best,
    PP
     
  13. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    i tried the vx2 plugin many times. i always get the same result. it says it will try to delete it after a reboot, but then when i run it again, i find the same thing
     
  14. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    ok, i figured out what it was running on. it was something in my processes like rundll32. i stopped that, then ran the check again and it was gone, but then right after i thought i had all my popups gone, the site showed up again. and also, the vx2 module went from the .dll that i had deleted to another .dll
     
  15. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    http://www.ad-w-a-r-e.com/callback_ron.php?GUID={4E707E4C-50F6-484F-AFAE-F9D0E110C1EE}&country=US&type=

    THAT IS THE LINK I GET EVERYTIME

    angered,
    chrispy
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you try to disable the messenger service on XP it goes like:


    Windows XP

    1. Click Start->Settings ->Control Panel
    1b.Click Performance and maintanance (Only in XP home)
    2. Click Performance and Maintenance
    3. Click Administrative Tools
    4. Double click Services Scroll
    5. down and highlight "Messenger"
    6. Right-click the highlighted line and choose Properties.
    7. Click the STOP button.
    8. Select Disable or Manual in the Startup Type scroll bar
    9. Click OK


    Also run the below online scans from normal boot mode (save logs or take notes), and report them back here.

    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
     
  17. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    hm..i did what you told me and im still getting the popup and its reallllly pissing me off here are the logs
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should boot in safe mode and manually delete the below:

    C:\Documents and Settings\user\Desktop\New Text Document (4).txt
    C:\WINDOWS\system32\ayaamon.dll
    C:\Program Files\Hijackthis\backups\backup-20041011-114104-854.dll
    C:\WINDOWS\system32\tby.dll

    What do the popups say? Do they give an address?

    Post a new HJT log.
     
  19. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    http://www.ad-w-a-r-e.com/cgi-bin/PopupV2?ID={4E707E4C-50F6-484F-AFAE-F9D0E110C1EE}&AD=Freeze

    The link changes from Freeze, CyDoor, Revenue, and Stopzilla

    the link changes everytime almost. here is what it says on the link

    sendExternalEvent('EVENT:IEBROWSER:www.ad-w-a-r-e.com/cgi-bin/PopupV2?ID={4E707E4C-50F6-484F-AFAE-F9D0E110C1EE}&bidid=5');

    here is my log again.
     

    Attached Files:

    • hjt.txt
      File size:
      3.7 KB
      Views:
      6
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you able to delete those files from safe mode?
     
  21. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    Yes. Even after i had deleted these files, popups still came. I have been keeping a log of how many popups i got during a short period of time. if it is of any help, here it is
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download todays update to Ad-Aware SE and make sure you run a scan with it. First run it in normal boot mode (not safe mode) and click Scan now and then choose the Perform full system scan option then click next. This may take awhile so be patient. Fix what it finds.

    Also make sure you have downloaded, installed and run the Ad-Aware VX2 Cleaner Plug-In.

    Let me know if and what these scans find.

    If Ad-Aware has problems cleaning/fixing what it finds, make sure you note what files are the problems and boot into safe mode and delete them yourself. Make sure you empty the Recycle Bin afterwards. Then reboot and run the scans again to make sure nothing came back.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way if you have not already started your Ad-Aware SE scan, after selecting Scan now you should deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat. This will save some time. It's okay if you started without changing this selection. Don't worry about it.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If those previous steps do not fix this problem, please do the following

    Download VX2 finder and save it some place you can find it
    http://downloads.subratam.org/VX2Finder9x(126).exe

    Then shut down ALL applications especially Internet Explorer and disconnect from the internet. No run VX2finder and select "click to find abetterinternet". Then select "make log" and copy/paste the log back here as an attachment. (you will have to rename the file from a .log to a .txt file)
     
  25. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    hm..i downloaded it and ran it, but it said only compatible for 9x or something like that
     
  26. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    as i had said before, once i run the adaware scan, it finds it. then i reboot my computer and then i run the scan again and the...uh...problem makes another .dll and creates it. this is continuous and i cannot stop this. is there a way i can find the source of the problem then delete it?
     
  27. J0in_THE_NAVY

    J0in_THE_NAVY Private E-2

    i think i have rebooted my computer at 23 times now and run adaware about 50+ and i always find the same thing. and the same popup keeps coming up about www.ad-w-a-r-e.com and im really, really, really, really, getting angry. i dont feel like reformating my hard drive because it will take me too long to find everything i had on my computer already. please help me anyone
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run it with the options set like I asked? Did you run the VX2cleaner plugin for Ad-Aware as I asked?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I posted the wrong link. Use this one VX2 finder and follow the directions I gave before.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds