Toolbar and Pop-Ups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by parad0x, Oct 16, 2004.

  1. parad0x

    parad0x Private E-2

    I have gone through the steps in the thread before posing this

    In Internet explorer popups keep coming up and they have the title about:blank, also when a page cannot be displayed it goes to a site (shown in the picture below) and there is also a toolbar, i have taken a screenshot to see if anyone can recognize it http://server5.uploadit.org/files/Paradox1-Toolbar.JPG
     
  2. jarcher

    jarcher I can't handle a title

    are you refering to this?:
    http://forums.majorgeeks.com/showthread.php?t=35407
    if not please do

    Read the HJT tutorial
    http://forums.majorgeeks.com/showthread.php?t=35407

    follow it exactly


    and the about:blank(if all else fails)
    http://forums.majorgeeks.com/showthread.php?t=38772
     
  3. parad0x

    parad0x Private E-2

    I read the HJT tutorial and this is the log
     

    Attached Files:

  4. jarcher

    jarcher I can't handle a title

    so then you read that part where it said to put HJT in its own folder
    not on the desktop
    HJt is not a document or a setting

    go ahead an move it to
    c:\program files\(its own folder)

    close all browsers (including this one)
    and run HJT again
     
  5. parad0x

    parad0x Private E-2

    Ah i thought it meant without anything in the same folder
     

    Attached Files:

  6. jarcher

    jarcher I can't handle a title

    fix these. . .
    O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSNet\RSEDNClient.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    O9 - Extra button: Medion-UK - {D9C2C299-CB45-46CE-9A9C-78EE0C616EFE} - http://www.medion.co.uk (file missing) (HKCU)

    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/bestfriends/retro64_loader.dll

    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
     
  7. parad0x

    parad0x Private E-2

    Done but the problems are still there
     
  8. jarcher

    jarcher I can't handle a title

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Do you know what this Wintab32.exe process is for?
    C:\WINDOWS\System32\Wintab32.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
    O4 - HKLM\..\Run: [New Load Spam Mapi] C:\Documents and Settings\All Users\Application Data\Ante ping new load\Bore Coal.exe
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone-dev.ubisoft.com/dev/packages/GSManager.cab
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v5.cab
    O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab


    Did you install the Soulcalibur Wall Paper Changer? If not, you should uninstall Net2Phone from Add/Remove programs. If that does not work, then fix with HJT.
    O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\soulcalibur_wpc\wpc.exe

    Do you have an account with Net2Phone? If not, you should uninstall Net2Phone from Add/Remove programs. If that does not work, then fix with HJT.
    O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\Net2Phone\Net2fone.exe
    O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\Net2Phone\Net2fone.exe

    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\All Users\Application Data\Ante ping new load <--- the whole directory

    No reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. parad0x

    parad0x Private E-2

    I think i found the problem, Ad-aware found 1 MyWay SearchBar as a registry key, I found quite a few My Way problems a while ago, and im not sure wether the new update enabled Ad-Aware to find it or it re-installed itself. I will restart later and see if it returns (I did dsable System Restore before and now), the bar has gone as well as popups, for now
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The items I gave you in my previous post were also problems. Did you fix those too?
     
  12. parad0x

    parad0x Private E-2

    The ones not in bold are used for other things, are they actual malware? I also deleted the ante ping directory, thanks for your help, and it hasnt come back so far
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ooops! My mistake on O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta . It is for USB interface for Aiptek Graphics Tablet (USB)

    Yes the following is for Sun Java but the file appears to be missing:
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    If you know the below two are okay, that's fine. Typically most people will flag these as potential problems. They will just reload when you visit the sites again so it is not typcially too big a deal to remove these O16 lines when trying to trouble shoot a problem.
    O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone-dev.ubisoft.com/d...s/GSManager.cab
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds