Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: very annoying adware  (Read 23375 times)

0 Members and 1 Guest are viewing this topic.

billh5773

  • Guest
very annoying adware
« on: May 28, 2007, 01:43:51 AM »
Hello
Its Billh5773 again. Sorry I could not get back to you last week. I went on holiday.
I have taken all your excellent advice and my PC is running a lot faster. I have Spybot S&D and HJT. but I still have an extremely annoying pop-up that will not go away. I would be grateful for any help with this.
Many thanks
Bill

oddjob



    Hopeful

    Thanked: 4
    • Experience: Beginner
    • OS: Windows 7
    Re: very annoying adware
    « Reply #1 on: May 28, 2007, 03:04:09 AM »
    Hi again Bill

    Can you do two things for us please ....

    1.  Give details of the pop up you see, when you get it on your screen, what site it's trying to move you to and so on.

    2. Download a self-extracting copy of HijackThis from here …….

    http://downloads.malwareremoval.com/hijackthis_sfx.exe
     
    Save it to your Desktop.

    Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder ……

    C:\Program Files\HijackThis

    Go to this folder and run the hijackthis.exe file.

    From the menu click on "Do a system scan and save a logfile".

    Copy and paste the HJT logfile to this thread. More specific removal instructions will follow.


    OJ

    billh5773

    • Guest
    Re: very annoying adware
    « Reply #2 on: May 29, 2007, 09:36:03 AM »
    Hello again.
    Thank you for taking the time to help. The page I keep getting is supposedly coming from blueyonder, although they are now Virgin I believe.
    I get a number of pages. One simply says sorry this offer is not available in your area. Another says it wants to scan my pc and claims to be a windows site. A third is an adult dating page with pictures of young ladies ( thankfiully dressed).
    I will do what you say with HJT and get back with the log.
    Many thanks
    Bill

    2k_dummy



      Specialist
    • A word, once spoken, can never be recalled.
    • Thanked: 14
      Re: very annoying adware
      « Reply #3 on: May 29, 2007, 09:42:50 AM »
      Once you have everything cleared up, if using IE, make use of Spybot's immunize feature.
      If you don't stand for something, you'll fall for anything.
      _______________________________________ ________
      BlackViper

      Software and utilities

      billh5773

      • Guest
      Re: very annoying adware
      « Reply #4 on: May 29, 2007, 09:47:17 AM »
      Heres half

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
      O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1171568453\ee\AOLSoftware.exe
      O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
      O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
      O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Dixons Insert Detect] C:\Program Files\Dixons\Picture Suite\InsDetect.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
      O4 - Global Startup: AOL Broadband Assistant.lnk = C:\Program Files\AOL\Broadband Assistant\bin\matcli.exe
      O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
      O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
      O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
      O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
      O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.42/WinSSWebAgent.CAB
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
      O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
      O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
      O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
      O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
      O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
      O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.blueyonder.co.uk/assets/tool/files/MotivePreQual.cab
      O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
      O16 - DPF: {FAFF0003-0A01-121A-A1C9-08032B23E0CC} - http://uk.global-acces.com/7adpower/nat2.exe
      O17 - HKLM\System\CCS\Services\Tcpip\..\{7ADF3C66-6A7D-4572-A587-EC5B831D01B3}: NameServer = 205.188.146.145
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - D:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WI


      Bill

      billh5773

      • Guest
      Re: very annoying adware
      « Reply #5 on: May 29, 2007, 09:48:07 AM »
      Heres the rest
      MSIE: Internet Explorer v7.00 (7.00.6000.16441)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      D:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
      C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\wanmpsvc.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
      C:\Program Files\QuickTime\qttask.exe
      D:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
      C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Common Files\AOL\1171568453\ee\AOLSoftware.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
      C:\WINDOWS\system32\sistray.exe
      C:\Program Files\AOL\Broadband Assistant\bin\mpbtn.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\AOL 9.0\waol.exe
      C:\Program Files\AOL 9.0\shellmon.exe
      C:\Program Files\Common Files\AOL\aoltpspd.exe
      C:\Program Files\HijackThis\HijackThis.exe

      Thanks again

      oddjob



        Hopeful

        Thanked: 4
        • Experience: Beginner
        • OS: Windows 7
        Re: very annoying adware
        « Reply #6 on: May 29, 2007, 10:08:45 AM »
        Hi

        Open HJT again ... click on scan ... put a tick/check mark next to this entry IF it's still present....

        O16 - DPF: {FAFF0003-0A01-121A-A1C9-08032B23E0CC} - http://uk.global-acces.com/7adpower/nat2.exe

        Remember to close ALL open browser windows before clicking on Fix Checked at the foot of the HJT window.

        (This is GBDialer dialing porn via your modem at a premium rate. The provider of this pay-per-minute service is Global Access S.L., known as "Global Acces".

        Get rid of it fast.)

        ***************

        Get Ccleaner to clean out your system. Get it here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …

        http://www.ccleaner.com/

        Run it and let it clean your system on its default settings.



        When done post a fresh HJT log (all of it ... including the headers ... from the top down) and an update on how the machine is operating now.


        OJ

        billh5773

        • Guest
        Re: very annoying adware
        « Reply #7 on: May 30, 2007, 03:16:58 AM »
        Hello Mr OJ.
        Okay. I have done what you requested but still have a page coming up that says Internet Security Centre and reccommends a programme Win Antivirus32. Still, my machine is running a lot faster than before.
        Log attached and thank you again.
        Bill

        [cleaning up - attachment deleted by admin]

        oddjob



          Hopeful

          Thanked: 4
          • Experience: Beginner
          • OS: Windows 7
          Re: very annoying adware
          « Reply #8 on: May 30, 2007, 04:09:32 AM »
          WinAntiVirus I've heard of (it's a real nasty) but not Win Antivirus32.

          I suggest you print this out to help you follow my advice.
           
           
          Make sure you have exposed all Hidden Files & Folders.
           
          To enable the viewing of Hidden files follow these steps:
           
             1. Close all programs so that you are at your desktop.
             2. Double-click on the My Computer icon.
             3. Select the Tools menu and click Folder Options.
             4. After the new window appears select the View tab.
             5. Put a checkmark in the checkbox labeled Display the contents of system folders.
             6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
             7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
             8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
             9. Press the Apply button and then the OK button and close My Computer.
           
          ***********************
          Superantispyware ……

          Please download and install SUPERAntiSpyware
          • Load SUPERAntiSpyware and click the Check for Updates button.
          • Once the update has finished, exit SUPERAntiSpyware. Please do NOT run a scan yet!
          IMPORTANT: Do NOT open any other windows or programs while SUPERAntiSpyware is scanning, it may interfere with the scanning process.
          • Open SUPERAntiSpyware and click the Scan your Computer button.
          • Check Perform Complete Scan and then click Next.
          • SUPERAntiSpyware will now scan your computer and when it’s finished it will list all the infections it has found.
          • Make sure that they all have a check next to them, and then click Next.
          • Click Finish and you will be taken back to the main interface.
          • It could be possible that it will ask you to reboot your computer in order to delete some files after reboot.
          • I'll need a log afterwards of what has been found.
          • To get the log, click Preferences and then click the Statistics/Logs tab. Click the dated log and press View Log and a text file will appear.
          • Please post the results of the SUPERAntiSpyware log in your next reply.
          ***********************

          Rehide Hidden Files & Folders by doing the reverse operation to that indicated at the start of this post.

          ***********************

          Post a fresh HJT log, as I said earlier, with ALL the information including the headers and an update on how things ware working now.


          OJ

          billh5773

          • Guest
          Re: very annoying adware
          « Reply #9 on: May 31, 2007, 04:02:15 AM »
          I am getting messages purely from sites trying to scan my computer for viruses. I know one was WinAntivirus and another was Anti   v I think.
          Is this any help?

          I tried to post the logs but don't know how successfull I ahve been with that. I shall look later.
          Many thanks for all your help
          Bill

          patio

          • Moderator


          • Genius
          • Maud' Dib
          • Thanked: 1769
            • Yes
          • Experience: Beginner
          • OS: Windows 7
          Re: very annoying adware
          « Reply #10 on: May 31, 2007, 09:32:57 AM »
          They may be using messenger service to send these...DLoad and run Shoot The Messenger.
          " Anyone who goes to a psychiatrist should have his head examined. "

          billh5773

          • Guest
          Re: very annoying adware
          « Reply #11 on: May 31, 2007, 11:53:02 AM »
          I'm still getting things like Security Update alerts after downloading shootthemessenger. I also get AV systemcare ads if that means anything?
          Thanks again guys.
          Bill

          CBMatt

          • Mod & Malware Specialist


          • Prodigy

          • Sad and lonely...and loving every minute of it.
          • Thanked: 167
            • Yes
          • Experience: Experienced
          • OS: Windows 7
          Re: very annoying adware
          « Reply #12 on: June 02, 2007, 06:55:29 PM »
          Hi, Bill.  Sorry you've been waiting a couple of days.  oddjob sometimes gets a bit bogged down with things.  If you still need help, could you go ahead an post a new HijackThis log and an update on how things are going with your computer?  As soon as you do, we will continue with trying to assist you.
          Quote
          An undefined problem has an infinite number of solutions.
          —Robert A. Humphrey

          billh5773

          • Guest
          Re: very annoying adware
          « Reply #13 on: June 03, 2007, 02:00:17 AM »
          I hope I have managed to post this properly. I had a small problem last time.
          If it hasn't worked, I shall try again after church.
          Thanlk you for your time.
          Bill

          [cleaning up - attachment deleted by admin]

          billh5773

          • Guest
          Re: very annoying adware
          « Reply #14 on: June 03, 2007, 02:04:18 AM »
          I forgot to say how this machine is working. I know now why they call the little arrrow a cursor. I t certainly can make you!
          I am now getting pages from
          Win Antivirus
          AVSystem care
          Globonews portal
          and something called Crazy Girls.
          My pc is running a lot better apart from this,and I could live with these (apart from Crazy Girls) if they would not interrupt.
          Bye
          Bill