Random pop ups?

Discussion in 'Malware Help (A Specialist Will Reply)' started by sleepygamer213, Oct 29, 2005.

  1. sleepygamer213

    sleepygamer213 First Sergeant

    Recently i started getting random pop ups every couple minutes (like 10 minutes and then i new one... im not too sure of the timing) It happened after my brother got on my PC and downloaded a torrent file :rolleyes: Ive got my PC password protected now... anyways though ive run all the scans recommended in Read first Before posting, AND ive even gone through the Alternative scanners... I used Trend Housecall and that found something but couldnt remove it, and when i tried to rescan to findout what it was, the pop up kept changing the window.. It happens when im not even using a browser, a pop up just comes up. A process called GEARsec.exe showed up in my system32 folder recently (dang popup!, well it actually changed this window and went to a different advritisment one) I tried to end it but it said that Access is denied, disk is either write protected etc etc..

    Any ideas?
     
  2. sleepygamer213

    sleepygamer213 First Sergeant

    Ok i know its a Look2Me Spyware because thats what Ewido keeps popping up with something called guard.tmp Its in my System32 folder... It keeps replicating itself and i keep getting Ewido warnings about it....

    I also get a Rundll failed warning saying

    "Could not load C:\WINDOWS\System32\guard.dll"
    A dynamic link library (dll) failed to load
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download, install and update Spy Sweeper Run it once while you are in normal boot mode.

    - The boot in safe mode from and run SpySweeper one more time.

    - Then make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    Let me know if you are still having any problems too.
     
  4. sleepygamer213

    sleepygamer213 First Sergeant

    Ran SpySweeper in normal mode and it detected icannews and Look2me.. Then i booted in safemode and it found icannews and look2me again.. Spy Sweeper keeps saying ;

    The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
    The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
    The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
    The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com

    during the scans... it says it several times..

    NOTE: I am running Spy Sweeper again in normal mode, (this is after 1st run in normal and 2nd in safe mode) and it shows up again that it has found icannews. Norton also keeps detecting and removing Look2me. I ran the Kill2Me but it didnt help.
    Heres my HJT log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kill2Me will not do anything for this form.

    Do you have System Restore disabled?

    First run HijackThis and select the below lines and click Fix (make sure your browsers are closed before clicking fix):
    O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Mike\LOCALS~1\Temp\20051029135336_mcinfo.exe /insfin
    O4 - HKLM\..\Run: [CleanUp] C:\DOCUME~1\Mike\LOCALS~1\Temp\20051029135339_mcappins.exe /v=3 /cleanup

    Then boot into safe mode and delete:
    C:\DOCUME~1\Mike\LOCALS~1\Temp\20051029135336_mcinfo.exe
    C:\DOCUME~1\Mike\LOCALS~1\Temp\20051029135339_mcappins.exe

    When you ran SpySweeper in safe mode did you disconnect your cable to the internet? If not, do that now and then run SpySweeper again. Also do not have anything else running and do not open any browsers at all while running the scan. In fact do not open a browser until after you reboot when the scan is complete.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds