Random Browser Popups

Discussion in 'Malware Help (A Specialist Will Reply)' started by twurk1703, Dec 25, 2005.

  1. twurk1703

    twurk1703 Private E-2

    I have random browser popups and have tried many adaware programs and popup blockers to get rid of it. I also have adware.look2me ... i have tried the kill2me tool to remove but it says it cant find it. I just finally got rid of a surfersidekick3 adware... for some reason when i got on my computer this morning it was full of popups and adware... dont know how it got past my firewall, popup blocker etc. If you could tell me how to get ride of the random browser loads and all the adware (my antispyware picks it up and says it removes it but doesnt.) I will attach a hijack log file.
    I had a few errors while running the hijack program. Here is one of the errors below:

    An unexpected error has occurred at procedure: modMain_CheckOther1Item()
    Error #75 - Path/File access error

    Please email me at merijn@spywareinfo.com, reporting the following:
    * What you were trying to fix when the error occurred, if applicable
    * How you can reproduce the error
    * A complete HijackThis scan log, if possible

    Windows version: Windows NT 5.01.2600
    MSIE version: 6.0.2900.2180
    HijackThis version: 1.99.1

    This message has been copied to your clipboard.
    Click OK to continue the rest of the scan.
     

    Attached Files:

  2. twurk1703

    twurk1703 Private E-2

    also i am getting runtime errors... it says c++ runtime errors
    and references winlogon.exe and explorer.exe, any suggestions.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  4. twurk1703

    twurk1703 Private E-2

    ok i did all the stuff you said... i had this error running hijack this
    An unexpected error has occurred at procedure: modMain_CheckOther1Item()
    Error #75 - Path/File access error

    Please email me at merijn@spywareinfo.com, reporting the following:
    * What you were trying to fix when the error occurred, if applicable
    * How you can reproduce the error
    * A complete HijackThis scan log, if possible

    Windows version: Windows NT 5.01.2600
    MSIE version: 6.0.2900.2180
    HijackThis version: 1.99.1

    This message has been copied to your clipboard.
    Click OK to continue the rest of the scan.

    same original error... i was able to get rid of most of the problems but my norton antivirus keeps coming up with random adware that i have gotten rid of a 10000 times with adaware, spybot, ms antispyware, etc etc but it still says they are coming back for example adware.spysheriff is one of them... is there a program that will wipe these out for good? i will attach my most recent HJT log. Thanks :)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions of the READ & RUN ME. Step 6 indicates two online scanners that must be run and we also request the logs for them to be posted. This steps and these logs should be completed before using HijackThis.
    Do you have any idea what the below processes are for?

    C:\Program Files\Common Files\VCClient\VCClient.exe
    C:\Program Files\Common Files\VCClient\VCMain.exe
     
    Last edited: Dec 26, 2005
  6. twurk1703

    twurk1703 Private E-2

    Ok I ran the panda and the bit defender and will attach those, I must have accidentally skipped the step.
    When I ran HTJ i got this error again:
    An unexpected error has occurred at procedure: modMain_CheckOther1Item()
    Error #75 - Path/File access error

    Please email me at merijn@spywareinfo.com, reporting the following:
    * What you were trying to fix when the error occurred, if applicable
    * How you can reproduce the error
    * A complete HijackThis scan log, if possible

    Windows version: Windows NT 5.01.2600
    MSIE version: 6.0.2900.2180
    HijackThis version: 1.99.1

    This message has been copied to your clipboard.
    Click OK to continue the rest of the scan.

    I saw that in my process I have alot of svchost.exe I heard those were bad and I have like 6 and I cannot stop the processes.

    Also... I have no clue what the VCClient.exe and VCmain.exe process are for... i stopped them and it didnt seem to effect my computer.

    I have gotten the random browser popups to stop through running adaware etc... but I still keep getting adaware and viruses and they keep reappearing on my computer. I think i got rid of the sufersidekick virus but i could be wrong.

    Please help. Thanks - Haley :)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should look into changing all passwords for any financial institutions you connect to. Some of the trojans you have on your system may have compromised your security.

    Did you ever install a program called DeskWizz? You should see this: http://vil.nai.com/vil/content/v_137329.htm

    Empty your MS Antispyware Quarantine folder.

    c:\windows\system32\svchost.exe is avalid process that normally runs multiple times.

    We recommend uninstalling Viewpoint Manager or other Viewpoint software. It is a waste of system resources for most people because it is never used.
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    Did you want you default an main pages set to about:blank:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank

    The procedure for installing and running HJT requests that you not use msconfig to control startup so we can see all potential problems. You are running msconfig:
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Do you need to have the below items? Are they really necessary for stuff at school to work?
    O1 - Hosts: 137.99.107.146 sbvacuum
    O15 - Trusted Zone: *.uconn.edu

    Make sure you have enabled viewing of hidden and system fies per the tutorial.
    Boot into safe mode and use Windows Explorer to locate below and delete if found:
    C:\secure32.html
    C:\PROGRAM FILES\QL <--- delete the QL folder
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll <--- see this too -->>: Malware - Bancos.LU
    C:\Documents and Settings\mobile student\Favorites\Cool Stuff <--- delete the Cool Stuff favorites
    C:\WINDOWS\drsmartload.dat
    C:\WINDOWS\kl.exe
    C:\WINDOWS\timessquare1.dat
    C:\WINDOWS\system32\0waop2rk.dll
    C:\WINDOWS\system32\mljgd.dll
    C:\WINDOWS\system32\wvurs.dll
    C:\WINDOWS\system32\wvusp.dll

    I see you did something with:
    O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
    O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe

    Is that what you used msconfig for? If so, after selecting Normal Startup, just have HJT fix those two O4 lines to permanently remove them. The locate the C:\Program Files\Common Files\VCClient folder and delete it. You may need to reboot into safe mode to delete the folder after stopping the processes from loading.
     
    Last edited: Dec 29, 2005
  8. twurk1703

    twurk1703 Private E-2

    I have never downloaded DeskWizz.
    I got rid of viewpoint manager.
    I want my main page to be www.students.uconn.edu as it is.
    I need to use MSconfig due to a problem i had previously with startup.
    The items O1 and O15 are there for connecting to wireless network etc at school which i need on a daily basis.
    I deleted what you told me too except for the cool stuff favorites because that is a folder i created myself. Also the last 3 items i could not find in the systems32 folder.
    I deleted the VCclient folder in the common files... i did not see the processes in HJT to fix them when i ran it.
    The svchost.exe that are running in the processes are duplicated there is 2 running for each the system, local service and network service... i wasnt sure if there should be duplicates. Also I ran Xoftspy which just detects and wont remove unless you buy a reg code... but it was still finding cookies and reg keys that were infected... but other spyware detectors are not finding them?
    I changed my bank passwords... any other security issues i need to worry about password wise?
    My computer seems to be running pretty normal again... but programs are still finding that it is infected... do i need to get rid of anything else?
    Do you recommend any other free programs that detect and remove spyware?
    Here is my HJT log. :eek:
    Thanks for helping so much. - H
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said below multiple svchost.exe processes (if running from system32 as shown in an HJT log - Task Manager is useless) are normal. I have 5 running right now. Xoftspy is junk that you don't need especially since it won't fix anything. They are better than they used to be if you have a current version but they were noted for false positives. Uninstall it and refer to this link: How to Protect yourself from malware!

    If there are any other places you log into that you would be worried about stolen passwords or info, it would not hurt you to change them for your own piece of mind.

    You need to be more specific. This does not tell me anything useful. What programs? And exactly what and where are they finding it?

    Run HijackThis and have it fix the below lines:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to http://students.uconn.edu/ Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like http://students.uconn.edu/ Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now attach a new HJT log.
     
    Last edited: Dec 30, 2005
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds