Stupid Specificpop Ads!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by spl1nter, Apr 2, 2004.

  1. spl1nter

    spl1nter Private E-2

    I have a problem with huge adverts from specificpop, infopop plus others just appearing in webpages. Not popups but actually in the site.

    It's really annoying as they take basically the whole screen until you scroll down.

    Here is my hijackthis log (some of the stuff doesn't appear as I removed most of the safe stuff):

     
  2. sniper-uk

    sniper-uk Private E-2

  3. sniper-uk

    sniper-uk Private E-2

  4. spl1nter

    spl1nter Private E-2

    I've got the latest version of Spybot. The only dangerous things it comes up with are cookies.

    I've also tried Spyhunter and it comes up with a few registry inconsistencies but since I haven't got the full version it doesn't delete them or make a log.

    These are the most sever ones it found (I can't copy the object names and I can't be bothered typing them out :p):

    Seekseek
    Blnet
    2 x Downloadware
    Sidesearch

    If you want the ad-aware scan, just ask.
     
  5. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    Thats some good advice from Sniper there

    As for your specific ad problem close all browser windows and check the boxes to fix these in Hijack
    O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - (no file)
    O2 - BHO: (no name) - {00000EF1-0786-4633-87C6-1AA7A44296DA} - (no file)
    O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-AB2D-8D32436313D9} - C:\WINDOWS\bsx5.dll
    O2 - BHO: (no name) - {A85C4A1B-BD36-44E5-A70F-8EC347D9B24F} - C:\WINDOWS\bs3.dll
    O4 - HKLM\..\Run: [Bsx3] RunDLL32.EXE C:\WINDOWS\bs3.dll,DllRun
    O4 - HKLM\..\Run: [bxsx5] RunDLL32.EXE C:\WINDOWS\bsx5.dll,DllRun

    REMOVAL INSTRUCTIONS: CUT AND PASTED TO SAVE ME TYPING

    Open a DOS command prompt windows (from Start->Programs->Accessories), and enter the following commands, for the Remanent variant:

    cd "%WinDir%\System"
    regsvr32 /u "..\bs3.dll"

    Next open the registry (click 'Start', choose 'Run', enter 'regedit'), find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, and delete the entry 'BookedSpace' or 'Bsx3' (BS3 variant). OR bsx5 or any bsx5 variant.
    Restart the computer and you should be able to delete the 'rem00001.dll', 'bs2.dll' or 'bs3.dll' or 'bsx5.dll' file in the Windows folder.
    You can also open the registry and delete the key HKEY_LOCAL_MACHINE\Software\Remanent or HKEY_LOCAL_MACHINE_Software\BookedSpace to clean up, if you like.

    Your next problem is this
    O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll

    Please download this and run it just follow the instructions to remove ua_lsp.dll this is a hook for spyware

    http://www.majorgeeks.com/download4180.html
     
  6. alanc

    alanc MajorGeek

  7. spl1nter

    spl1nter Private E-2

    Thanks a lot. I did what you said. I'm not sure if it's worked just yet but I hope it has. I'll make sure to mention if it ain't worked.

    Once again, thanks.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds