porn sites come up

Discussion in 'Malware Help (A Specialist Will Reply)' started by spyware sucks, Oct 11, 2004.

  1. spyware sucks

    spyware sucks Private First Class

    when im on the internet sometimes when i click a link it goes to a porn site. i think its because i haven't deleted all the spyware files. please help me.

    edit: it also saves porn sites in my favorites and saves porn sites in my recent URLs thing.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow all the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. spyware sucks

    spyware sucks Private First Class

    i've prety much done all of that stuff. but now i get this popup: http://404.99fh.com/error.html

    it even pops up when im clicking around in this forum. and when im checking yahoo email.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do ALL of it and in the order given. Do not skip the online scans. If you cannot run them in safe mode for some reason, do them in normal boot mode.

    After you complete ALL the steps, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  5. spyware sucks

    spyware sucks Private First Class

    ok sorry should i do the optional ones too?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what you have said, you do not need to do Step 5 Optional (related to HSA hijacker only).

    You could try the Alternative Scans, if still having problems. But when done with all of this if you still have a problem post your HJT log as a .txt file attachment as I said in my previous message.
     
  7. spyware sucks

    spyware sucks Private First Class

    i have done everything...ok my symptoms include that popup i mentioned before and the changing hyperlinks. there is also this one file on my computer that is showing in my scans but i can't delete it.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't follow directions, I cannot help you!
     
  9. spyware sucks

    spyware sucks Private First Class

    well the directions were to post only when i was told to. and i don't know how to save the log file as a .txt
     
  10. spyware sucks

    spyware sucks Private First Class

    heres the log..sorry for being dumb
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First note: you need to update your system. Windows XP and Internet Explorer are way out of date.
    You need to go to Microsoft update and download the updates for you system.

    Second note: The HijackThis tutorial specifically said to install it in its own directory that is not a temp folder nor on the Desktop. You have it here:
    C:\Documents and Settings\JEFF_2\Desktop\hijackthis\hijackthis\HijackThis.exe

    that is the Desktop. Please move it to a directory as we indicated. C:\Program File\HJT for example. The Documents and Settings directory is a poor choice. It is not a document nor a setting. It is a program.

    Third note, the below should have been shutdown as requested in the tutorial
    C:\Program Files\AIM\aim.exe
    C:\Utopia\Angel\Angel.exe <----- what is this anyway

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - {01CD4DDA-166D-4831-A373-ACCC27E1BB9D} - (no file)
    O1 - Hosts: 3466709097 com.org
    O1 - Hosts: 3466690378 view.atdmt.com
    O1 - Hosts: 3466690378 click.atdmt.com
    O1 - Hosts: 3466690378 leader.linkexchange.com
    O2 - BHO: NavErrRedir Class - {01CD4DDA-166D-4831-A373-ACCC27E1BB9D} - (no file)
    O2 - BHO: (no name) - {2D48A324-7458-4A35-95EB-A50A4497EB5F} - C:\WINDOWS\madopew.dll (file missing)
    O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-C1ED-EB6EA49CA83A} - C:\PROGRA~1\POWERS~1\Toolbar\gripbtss\gripbtss.dll
    O4 - HKLM\..\Run: [ASHLT] C:\WINDOWS\Ashlt.exe
    O4 - HKCU\..\Run: [winltmpv] c:\windows\winln.exe
    O8 - Extra context menu item: SirSearch - file://C:\Program Files\GRIPBTSS\Cache\SelectedContextSearch.htm

    QUESTIONS AND COMMENTS FOR YOU:
    Is this next line rquired by your ISP or something? It seems suspicious to me?
    O4 - Global Startup: Microsoft Broadband Networking.lnk = %SystemRoot%\Installer\{06B2B442-19FE-4398-BD4B-F5C00928DD8E}\_18be6784.exe
    These next two lines are regarded by many as spyware and are not really needed. It's you choice whether to remove or not.
    O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
    O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\client\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray

    Did you use a program to make this restrictions (like SpyBot S&D or SpywareBlaster)?
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\Ashlt.exe
    c:\windows\winln.exe

    No reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. Katzenjammer

    Katzenjammer Private E-2

    *sticks her nose in*

    *board lurks and sticks her nose in*
    Poop, my friend, this is what your impatience gets you. :p You need to read all the instructions and stop skipping steps. ;)

    Chas, Angel is a program we use in Utopia to format our game to enhance our playing strategies.

    Apologies if I wasn't to stick my nose in, but each time you explain something to my kingdom mate, I have to help him along out of the forum anyway. :p Which is why I'm board lurking. He doesn't mean to be a pain, I promise. He's just impatient with the problems. He's had these issues for a couple of months. :(
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: *sticks her nose in*

    No problem Katzenjammer! I don't play games so I know nothing about them. But the reason I asked what it was is just to make sure the user knows what it is and for me to know too.

    And I don't mean to be a pain either but when you do this day after day, log after log, it gets annoying sometimes when directions are not being followed. We get tired of repeating ourselves and get grumpy sometimes.
     
  14. spyware sucks

    spyware sucks Private First Class

    sorry for being such a pain. hehe but like katzenjammer said these problems are pissing me off. and after reading the tutorial thing i was afraid something bad would happen. like that keyboard thing where people can record what you type and then find out your credit card numbers and passwords... i was in a rush so i didn't read carefully.


    Questions you asked me:

    Did you use a program to make this restrictions (like SpyBot S&D or SpywareBlaster)?
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    i use spybot and spywareblaster cause it was in the instructions to download them. but i don't know anything about restrictions.



    O4 - Global Startup: Microsoft Broadband Networking.lnk = %SystemRoot%\Installer\{06B2B442-19FE-4398-BD4B-F5C00928DD8E}\_18be6784.exe

    um..no clue. i use Microsoft Broadband Networking. but i don't know what that is.
     
  15. spyware sucks

    spyware sucks Private First Class

    um i have a questions too. how long is it supposed to take for windows update? i clicked on download but the window froze or something.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the speed of you connection? You are pretty far out of date and require some pretty large updates. You may need to do it selectively (update one thing at a time) but the update to SP1 or SP2 and the IE update will still be pretty big.

    Skip Windows Update for now!
    Did you perform the other steps I gave you in message number 11?

    Ignore the O6 restrictions lines too.
     
  17. spyware sucks

    spyware sucks Private First Class

    yes i have completed all the steps in post 11. wow 30 minutes to download SP2...
     
  18. spyware sucks

    spyware sucks Private First Class

    help please. i downloaded and installed SP2 but now im getting this message that i have limited or no connectivity for my networking. should i worry about it?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check this link out:

    http://www.windows-help.net/WindowsXP/troub-13.html

    Are all the spyware issues cleaned up? Is all the stuff fixed from message #11 actually repaired (did not come back)?
     
  20. spyware sucks

    spyware sucks Private First Class

    yes i got rid of all the spyware i think. but i accidentally deleted something out of the registry so i had to reformat my comp. oh well. i'll know not to do anything like that anymore. shoot. should i download the updates over again? or is it ok to just leave my computer the same way as when i installed it?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must get the updates ASAP. Please see this thread: How to Protect yourself from malware!
     
  22. spyware sucks

    spyware sucks Private First Class

    augh. AVG takes forever to send me an activation code.
     
  23. spyware sucks

    spyware sucks Private First Class

    i'm afraid of that 'keylogging' thing. is there anyway i can check to be safe of this?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could try Avast instead.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What keylogging thing?
     
  26. spyware sucks

    spyware sucks Private First Class

    hm. im not sure what its called then. but when i was reading some info it said that there was a way for someone to record what you have been typing. and they can find out passwords and credit card numbers. etc.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! But why do you think you have a keylogger?
     
  28. spyware sucks

    spyware sucks Private First Class

    nah im not sure if i do. i was just wondering if there was a way to check.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With all the scans from the READ ME FIRST and the HijackThis scan too you are pretty safe. However, to be really safe make sure you have done all I what I gave you in message #21. And that is:
    How to Protect yourself from malware!

    A firewall is very important.
     
  30. spyware sucks

    spyware sucks Private First Class

    new spyware

    hi im back..i have a problem with spyware AGAIN. i scan with spybot to find an aurora spware in the registry and after i remove it and scan again it is gone. but once i use my internet again, an aurora pop up appears and when i scan using spybot the spyware is back. how can i get rid of this?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: new spyware

    You really should have started a new thread. This one is almost 8 months old. Even in a couple of weeks things can drastically change on a PC. You need to start over again with the below procedure:

    Now download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover Do not do anything with it yet! We will need it later in the process.


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    - Now while still in safe mode, extract the abiremover.exe file from the ZIP file downloaded earlier into the folder you created but do not run the EXE yet.

    - Run the ABIRemover.exe, press install, wait (explorer window will disapear along with your Desktop for a few seconds)

    - When it finishes just reboot into normal mode and complete the steps below.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  32. spyware sucks

    spyware sucks Private First Class

    sorry

    hello. sorry im really impatient but im in a really busy situation right now.

    i got rid of the aurora, well it isn't showing up in the scans anymore. but i get the same pop ups everytime i reboot my computer. such as: creatrixads, dotexplore, findonpage, yazifind, neededware...etc

    im really sorry i know you guys get impatient if we don't do all the steps but is there a quicker way to get rid of this problem? i appreciate your help.
     
  33. spyware sucks

    spyware sucks Private First Class

    more pop up names

    heres just more info if you need it

    other popups include: adacuity, lyricsonpage, ncontextmedia, ncontextsearch, realcasinoreview, songsonpage, spywareinfo, tinkopal.

    again im sorry for being hasty.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: more pop up names

    Sorry but you need to complete the steps! If we make exceptions for one, we would have to make them for everyone and that makes our job more difficult. We do not have time for that. The end result would be nobody having enough time to work on all the requests for help.

    Yes, we can look at HJT logs sooner. But just using HJT to fix problems does not cleanup hundreds of possible registry keys that malware may deposit and that does not show in an HJT log. The scanners do a good job of picking of stuff like that and removing them.
     
  35. spyware sucks

    spyware sucks Private First Class

    thanks

    i understand. you guys are the best help available for probelms like this. i have already scanned with pretty much all of those programs in the sticky thread. i'll post the HJT file and if you could help me that would be great
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: thanks

    What does "pretty much" mean? And when were they run?
     
  37. spyware sucks

    spyware sucks Private First Class

  38. spyware sucks

    spyware sucks Private First Class

    only the aboutbuster didn't work and online symantec scan didn't work either
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    On October 16, 2004 ( see message # 11) I said:
    Then on October 23, 2004 in message # 29 I repeat the importance:

    You never did this! You MUST update. Go to the How to Protect thread and get your system updated and get a firewall. You will continue to have these problems unless you do. Malware as changed drastically even since October of last year and had become more difficult to remove and to protect against. If you do no follow these instructions you will always be in a mode of fixing your PC.
     
  40. spyware sucks

    spyware sucks Private First Class

    yeah i've tried tupdating but after i updated something goes wrong. i think there is some conflicts with my internet and networking.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is you copy of Windows valid? Do you have a valid registered license key of your own?

    Be more explicit and provide exact error messages from Windows Update. You have very few updates if any.
     
  42. spyware sucks

    spyware sucks Private First Class

    ok i've got the firewall. but is it all right if i don't download the Microsoft Update?
     
  43. spyware sucks

    spyware sucks Private First Class

    ok i'll try again.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really and WHY?
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give the below a try. But whether it fixes your problems or not, YOU MUST GET UPDATED!

    The below item from Sony is considered to be spyware. It's up to you what you want to do with it. See: http://castlecops.com/startuplist-4638.html
    O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [jbp] C:\WINDOWS\System32\jbp.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
    O16 - DPF: {48FE89A0-486C-48DF-9DEC-BED22BDC6057} (XIsOro Control) - http://www.sinago.com/download/OroCheck.cab
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\jbp.exe
    c:\counter.cab

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  46. spyware sucks

    spyware sucks Private First Class

    ok i've got it all updated and firewalled. only thing im confused about is that the firewall always has popups wheter or not to let things in the network. i don't know what to let in and waht not to
     
  47. spyware sucks

    spyware sucks Private First Class

    so far so good. no popups

    here is the HJT file
     

    Attached Files:

  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some of the stuff form message # 45 is still there. Do it again.

    If you recognize the program name and know what it is, allow it access otherwise deny it. If you have windup having a problem later on with some particular application, you can always enable it to have acccess later.
     
  49. spyware sucks

    spyware sucks Private First Class

    i can't get rid of

    O4 - HKLM\..\Run: [jbp] C:\WINDOWS\System32\jbp.exe
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)

    and i can't find

    C:\WINDOWS\System32\jbp.exe
    c:\counter.cab
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you do this
    Also do the below:

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to System Startup Service or SvcProc ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    System Startup Service

    If that does not work, try using the short name of the service: SvcProc
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds