Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Pop ups  (Read 3040 times)

0 Members and 1 Guest are viewing this topic.

Jubbly

    Topic Starter


    Rookie

    Pop ups
    « on: July 07, 2008, 09:53:41 PM »
    I had a problem of bad pop ups and fake anti virus popping up.
    I just finished the scan logs.

    [recovering disk space -- attachment deleted by admin]

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: Pop ups
    « Reply #1 on: July 07, 2008, 10:07:36 PM »
    Superantispyware, and Malwarebytes did pretty good job....

    *** You need to update Java:
    http://java.sun.com/javase/downloads/index.jsp
    Java Runtime Environment (JRE) 6 Update 6
    Uninstall all previous versions of Java through Add\Remove.

    *** Go Start>Control Panel>Add\Remove, and...
    Uninstall any of the following programs associated with Viewpoint:
        * Viewpoint Manager
        * Viewpoint Media Player
        * Viewpoint Toolbar

    *** Download, and run  CTFMON-Remover: http://www.gerhard-schlager.at/en/projects/ctfmonremover/
    The CTFMON-Remover helps you removing the annoying CTFMON.EXE from your Windows operating system. The program is easy to use and displays whether the CTFMON.EXE is installed and running or not. If it was found then you can remove it within seconds. Just in case that you need the CTFMON sometime in the future there is also an option to restore the original one.
    Note:The CTFMON.EXE is among other things responsible for changing the language schema of your keyboard (e.g. for switching between the German and English keyboard layout). So in case you are using this feature you shouldn't remove or disable the CTFMON.EXE!

    *** Download, and run QuickTime Killer: http://www.softpedia.com/get/System/Launchers-Shutdown-Tools/QuickTime-Killer.shtml
    QuickTime Killer will remove QuickTime from start up and kill any running QuickTime processes. This application runs silently at start up and closes itself as soon as it takes care of QuickTime

    1. Print this post out, since you won't have an access to it, at some point.

    2. Close all windows, except for HijackThis.

    3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases [marked with *], no actual program will be removed):

    - O2 - BHO: {9d5c3da4-4580-23c8-fce4-18d79467ea71} - {17ae7649-7d81-4ecf-8c32-08544ad3c5d9} - C:\WINDOWS\system32\rnwmdk.dll (file missing)
    - *O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    - *O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    - *O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    - *O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
    - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    - *O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    - *O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    - *O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    - *O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    - *O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    - O20 - Winlogon Notify: awtusqND - awtusqND.dll (file missing)
    - O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    4. Click on Fix checked button.

    5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

    6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

    7. Delete following files/folders (if present):

    - Viewpoint folder from C:\Program Files

    8. Restart in Normal Mode.

    9. Post new HijackThis log.

    Jubbly

      Topic Starter


      Rookie

      Re: Pop ups
      « Reply #2 on: July 08, 2008, 10:26:26 AM »
      I just finished everything and got the new HJT log. Also I would like to ask two questions what was Viewpoint manager and why did I have to remove I have to remove it?
      Oops, I missed a step I forgot to download the QuickTime Killer. Sorry.

      [recovering disk space -- attachment deleted by admin]

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: Pop ups
      « Reply #3 on: July 08, 2008, 03:37:58 PM »
      Viewpoint Manager does not do anything bad such as deliver ads or spy on you, but it is considered foistware ("drive-by-install") as it is installed without your consent through programs like AOl, AIM, Compuserve, etc.



      Your computer is clean

      1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
      Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
      Run CCleaner.

      2. Turn off System Restore:

      - Windows XP:
         1. Click Start.
         2. Right-click the My Computer icon, and then click Properties.
         3. Click the System Restore tab.
         4. Check "Turn off System Restore".
         5. Click Apply.   
         6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
         7. Click OK.
      - Windows Vista:
         1. Click Start.
         2. Right-click the Computer icon, and then click Properties.
         3. Click on System Protection under the Tasks column on the left side
         4. Click on Continue on the "User Account Control" window that pops up
         5. Under the System Protection tab, find Available Disks
         6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
         7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
         8. Click OK

      3. Restart computer.

      4. Turn System Restore on.

      5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

      6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

      7. Let me know, how your computer is doing.