Home > Pop Ups > Pop Ups - HijackThis Log

Pop Ups - HijackThis Log

After the update finishes (the status bar at the bottom will display "Update successful"), exit Ewido and boot into safe mode:   Restart your computer, and begin tapping the F8 key The computer has no popups now but is getting alot of page not founds. When I search a topic, related pop-ups always appear (e.g., if I search "spybot s&d in google, I'll get pop-ups about spyware removal tools, etc.)   ***This is what I've done*** Go to add remove programmes in your control panel and uninstall anything to do with(if there). http://swiftinv.com/pop-ups/pop-ups-help-hijackthis-log-help.html

Delete all items it finds.Hope this helps and let us know how it goes..Grif Flag Permalink This was helpful (0) Back to Computer Help forum 2 total posts Popular Forums icon I uninstalled spybot. Back to top #14 whazat whazat New Member Members 9 posts Posted 25 February 2009 - 04:53 AM please find link to thread post on spykiller: http://thespykiller....17.new.html#new Back to top #15 Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quietO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /backgroundO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program have a peek at this web-site

Join thousands of tech enthusiasts and participate. There is an uninstaller here:http://www.kellys-korner-xp.com/xp_tweaks.htm#377. Glad we could help.

  1. This tool is not a toy and not for everyday use.
  2. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.
  3. Please observe these rules while we work: Please Read All Instructions Carefully If you don't understand something, stop and ask!
  4. If you have any further virus/spyware problems, please post in this thread.
  5. Here's my ewido scan report:--------------------------------------------------------- ewido anti-malware - Scan report--------------------------------------------------------- + Created on: 2:14:46 PM, 5/29/2006 + Report-Checksum: F707AF80 + Scan result: [772] C:\WINDOWS\system32\cdkdlok.dll -> Downloader.Qoologic.bj : Cleaned with backup :mozilla.31:C:\Documents
  6. Any assistance this time is appreciated.
  7. wininet.dll advpack.dll urlmon.dll Reboot and see if the problem continues.
  8. Once reported, our moderators will be notified and the post will be reviewed.

Is it possible that it is showing you things that it has already removed ? Several functions may not work. If you have any further virus/spyware problems, please post in this thread. Register now!

Dismiss Notice TechSpot Forums Forums Software Virus and Malware Removal Today's Posts HijackThis Log - Problem with Popups and possibleKeylogger Bykissmyface24_7 · 4 replies Dec 17, 2006 Hi All, Been having Have HJT fix the following, by placing a tick in the little box next to(if there). Yes, my password is: Forgot your password? This computer was running sbc dsl without any router or virus protection.

Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quietO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /backgroundO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Join the community here, it only takes a minute. Here's a fresh log Logfile of HijackThis v1.98.1 Scan saved at 10:15:04 PM, on 11/24/2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe Modem and Router help please CPU cooler Windows acting like the 'Alt' key...

The service needs to be deleted from the Registry manually or with another tool. The selected area was scanned. Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. A tutorial on installing & using this product can be found here: Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers Install Ad-Aware - Install and download

Please don`t post your own virus/spyware problems in this thread. http://swiftinv.com/pop-ups/pop-ups-and-voice-ads-hijackthis-log-included.html TechSpot Account Sign up for free, it takes 30 seconds. Your Antivirus and/or Antispyware may give a warning during the scan. Please remove all lines with the following file names.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. If it prompts you as to whether or not you want to save the settings, press the Yes button.Next press the Apply button and then the OK to exit the Internet Turn off system restore.(XP/ME only) See how HERE. http://swiftinv.com/pop-ups/pop-ups-please-help-hijackthis-log.html Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers.In case of a 'hidden' DLL loading from this Registry value

If your firewall raises a question, say OK In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active OK any prompts. About CNET Privacy Policy Ad Choice Terms of Use Mobile User Agreement Help Center Tech Support Forum Security Center Virus/Trojan/Spyware Help General Computer Security Computer Security News Microsoft Support BSOD, Crashes For the R3 items, always fix them unless it mentions a program you recognize, like Copernic.F0, F1, F2, F3 - Autoloading programs from INI filesWhat it looks like:F0 - system.ini: Shell=Explorer.exe

Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab What to do:If you don't recognize the name of the object, or the URL it was downloaded from, have HijackThis

It wasn't until after I ran some of the online scans that the pop ups started but now they are gone. Then, please go to Start > My Computer and navigate to the C:\BFU folder. Simply using a Firewall in its default configuration can lower your risk greatly. Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers.

Have HijackThis fix them.O14 - 'Reset Web Settings' hijackWhat it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.comWhat to do:If the URL is not the provider of your computer or your ISP, have Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). I do quite a bit of financial transactions from the pc so really need to know if its ok to start putting in passwords etc. weblink Spyware removal software such as Adaware or Spybot S&D do a good job of detecting and removing most spyware programs, but some spyware and browser hijackers are too insidious for even

Save it to your desktop. Register now to gain access to all of our features, it's FREE and only takes one minute. So you can always have HijackThis fix this.O12 - IE pluginsWhat it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dllWhat to do:Most hacker103, Apr 26, 2005 #3 MFDnNC Joined: Sep 7, 2004 Messages: 49,014 To get rid of nail - http://www.mypctuneup.com/evaluate.php Add remove programs remove all occurences of Viewpoint - BullsEye - Cashback

Sign In Sign In Remember me Not recommended on shared computers Sign in anonymously Sign In Forgot your password? Cheers.OT I do not respond to PM's requesting help. Contents of the 'Scheduled Tasks' folder 2009-02-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1408808739-1144760930-3172560130-1000.job - c:\users\Belinda Koshy\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-03 18:44] . . ------- Supplementary Scan ------- . My name is Sam and I will be helping you.

Both Ad-Aware SE and Spybot S&D will fix all selected problems, but within hours, they will detect other problems (something is spawning spyware/adware???) 2. Jump to content FacebookTwitter Geeks to Go Forum Security Virus, Spyware, Malware Removal Welcome to Geeks to Go - Register now for FREE Geeks To Go is a helpful hub, where Unlike typical anti-spyware software, HijackThis does not use signatures or target any specific programs or URL's to detect and block. Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.) O17 - Lop.com domain hijacksWhat

I am also getting a message on startup say "a plug in is not properly licensed". HijackThis log file is: Logfile of HijackThis v1.97.7 Scan saved at 10:56:20 PM, on 4/24/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe Files can be uploaded by anybody but not downloaded at all except for those users that have been given special permissions. I have attached a HijackThis log from before I followed the 'Viruses/Spyware/Malware, preliminary removal instructions' thread (called HijackThisOLD.txt) And one from after (called HijackThisNEW.txt).

Back to top #6 whazat whazat New Member Members 9 posts Posted 20 February 2009 - 08:33 PM After 3 attempts we finally have scan log as below: -------------------------------------------------------------------------------- KASPERSKY ONLINE Back to top #8 whazat whazat New Member Members 9 posts Posted 21 February 2009 - 01:49 PM Yes, still getting the pops up saying that it is blocking wininet.dll as This site is completely free -- paid for by advertisers and donations. Click here to join today!

After I deleted it I could run the online scan. Since this appears to be resolved I will now close this topic.