Random annoying pop-ups...

  1. #11
    HJThis is offline Senior Member

    Red face Re: Random annoying pop-ups...

    Hi,SmashMan

    Opps sorry did not see your on ME it will not work
    so do this here please

    Download the L2MFix from
    http://www.downloads.subratam.org/l2mfix.exe
    or
    http://www.atribune.org/downloads/l2mfix.exe

    Save the file to your desktop and double click l2mfix.exe.

    Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop.

    Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log.

    Copy the contents of that log and paste it into this thread.

    IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until I ask you to.

    HGD

  2. #12
    SmashMan is offline Newbie
    Tried l2mfix also ...
    getting the same error:
    "Syntax Error
    Cannot execute C:\WINDOWS\COMMAND\START.EXE"

    It runs fine on my sister's Windows XP machine ..
    Maybe all these programs are just for XP and above.
    Last edited by SmashMan; 30-07-2005 at 01:06 AM.

  3. #13
    HJThis is offline Senior Member
    Hi,SmashMan

    one more thing this item here you don't need to be running this junk
    so if you want to remove it just goto Control Panel Add/Remove Programs
    & Uninstall/Remove
    KaZaA Lite

    Ok lit's try this the hard way

    Make sure you can view hidden and system files: Instructions here

    Then Boot to safe mode: Instructions here

    Once in Safe Mode lit's do a file Search for these items here if found delete them

    C:\WINDOWS\SYSTEM\IYMP.DLL
    C:\WINDOWS\SYSTEM\PoMas.dll
    C:\WINDOWS\SYSTEM\tstu\!update-2234.0000
    C:\WINDOWS\SYSTEM\utdt.exe
    C:\WINDOWS\SYSTEM\in10b6.dll
    C:\WINDOWS\SYSTEM\EVPTAPI.dll
    C:\WINDOWS\INF\BI4.INF
    C:\WINDOWS\INF\BIK.INF
    C:\WINDOWS\ru.exe
    C:\WINDOWS\m190309.exe
    C:\WINDOWS\Downloaded Program Files\installer_VENDARE.exe
    C:\WINDOWS\Downloaded Program Files\On01.inf

    & get this here out of the way

    Clear your Temp folders.
    Clear out your Temporary internet files and other temp files.
    Go to Start > Settings > Control Panel >Internet Options.
    Under the General tab click the Delete temporary internet files,
    delete all Offline content as well. Clear out Cookies.

    Also, go to Start > Find/search > Files or folders > in the named box, type: *.tmp and choose Edit > select all -> File > delete.

    Empty/delete the entire contents of the C:\Windows\temp folder and C:\temp folder, if you have one. (Contents but not the folder itself.)

    C:\Documents and Settings\username\Local Settings\Temp\

    In order to view these files you may have to select 'show hidden files/folders.' Instructions on how to here.

    Empty the Recycle Bin.

    Also do this here for me please

    To disable Windows Me System Restore

    1. Click Start > Settings > Control Panel.
    2. Double-click the System icon.
    Note: If the System icon is not visible, click "View all Control Panel options" to display it.

    3. On the Performance tab click File System.
    4.Click the Troubleshooting tab, and then check Disable System Restore
    5.Click OK. Click Yes, To restart Windows.


    To enable Windows Me System Restore

    After you have restarted, turn System Restore back on

    1. Click Start > Settings > Control Panel.
    2. Double-click System.
    3. On the Performance tab click File System.
    4. On the Troubleshooting tab, uncheck Disable System Restore.
    5. Click OK. Click Yes, when you are prompted to restart Windows.

    NOTE: please make sure to do a new System Restore Point after the restart.

    Then lit me know if this was any help at all.

    HGD
    Last edited by HJThis; 30-07-2005 at 01:52 AM.

  4. #14
    SmashMan is offline Newbie
    All of the files you listed were deleted except for PoMas.dll. I just set Hijack This to delete it on a reboot. It did, and I'm glad to say that these pop-ups are completely gone. Haven't had a single one in the past day. Thanks for all the help, it's greatly appreciated.

  5. #15
    HJThis is offline Senior Member
    Hi,SmashMan

    That is great news for sure & thanks for having
    us here at D-A-L help you with this problem

    HGD

  6. #16
    SmashMan is offline Newbie
    Sad to say this problem has returned yet again. McAfee scan so far has found the Trojan VeryLince ... very slow running scan.

    Spybot & Ad-Aware and various other scans only come up with tracking cookies

    I tried going into Windows\System and deleting UTDT but it did not seem to be there.. even though Hidden files are set to be shown.


    Here is the latest Hijack This scan ....

    Logfile of HijackThis v1.99.1
    Scan saved at 12:43:03 AM, on 8/2/2005
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    C:\WINDOWS\SOINTGR.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\RUNDLL32.EXE
    C:\WINDOWS\SYSTEM\UTDT.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\2WIRE\GATEWAY\2PORTALMON.EXE
    C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
    C:\PROGRAM FILES\AIM95\AIM.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\HIJACK THIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [2wSysTray] C:\PROGRAM FILES\2WIRE\GATEWAY\2PORTALMON.EXE
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\McAgent.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
    O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SO5 Integrator Pass One] C:\WINDOWS\SOINTGR.EXE
    O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
    O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O12 - Plugin for .MTD: C:\PROGRA~1\INTERN~1\Plugins\npmusicn.dll
    O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
    O15 - Trusted Zone: http://www.expedia.com
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnview95.cab
    O16 - DPF: {B06ECF02-E502-4737-BA32-91CA0CECFBD1} (MultiDownload Control) - http://www.samsungasc.com/include/cab/MultiDownload.cab
    O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518} (ell Class) - http://www.easports.com/downloads/ga...mmon/ieell.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/sof...iveXPlugin.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/sh...3/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/sh...20/mcgdmgr.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/assets...LStreaming.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.com/app/ST/ActiveX.ocx

  7. #17
    HJThis is offline Senior Member
    Hey,SmashMan

    Ok could you please do a Panda Active Scan

    as you had done before lit's see what if anything it may find
    then come back here with a scan logfile.

    I alos what you to download this free FireWall we will
    be installing it after we are clean not before it will not help

    http://www.zonelabs.com/store/conten...eeDownload.jsp

    again download the FireWall do not install just yet

    HGD

  8. #18
    SmashMan is offline Newbie
    I have a firewall through my SBC Yahoo DSL software, is that good enough?
    It seems that my Windows ME machine only gets hit with spyware. I have a Windows XP machine running on the same home network and it never has any spyware problems.

    Here is the Panda Active Scan result. ALL files have been deleted..either by changing file attributes in DOS and deleting or going into safe mode and deleting. The Panda Scan took about 4 hours to complete.


    (had to attach scan result as it was too many characters)

    One more question .. the display on my monitor is a little weird. Could this be because of all the spyware? (see attached jpg)
    Attached Images
    Attached Files

  9. #19
    HJThis is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    Hey,SmashMan

    Make sure you can view hidden and system files: Instructions here

    Then Boot to safe mode: Instructions here

    OK same as before one in Safe Mode do a file Search for these if found delete them all.

    C:\WINDOWS\SYSTEM\DPVENUM.DLL
    C:\WINDOWS\SYSTEM\MGG4C32.DLL
    C:\WINDOWS\SYSTEM\UJDMXFRM.DLL
    C:\WINDOWS\SYSTEM\MWYUV.DLL
    C:\WINDOWS\SYSTEM\MOPRINT2.DLL
    C:\WINDOWS\SYSTEM\OXUI400.DLL
    C:\WINDOWS\SYSTEM\SHSCLASS.DLL
    C:\WINDOWS\SYSTEM\SZMSCRPT.DLL
    C:\WINDOWS\SYSTEM\CKM.DLL
    C:\WINDOWS\SYSTEM\WCVDMOD.DLL
    C:\WINDOWS\SYSTEM\MMAWT.DLL
    C:\WINDOWS\SYSTEM\MAPRINT2.DLL
    C:\WINDOWS\SYSTEM\dmdiagn.dll C:\WINDOWS\SYSTEM\DNLPRJ32.dll
    C:\WINDOWS\SYSTEM\utdt.exe
    C:\WINDOWS\SYSTEM32\Process.exe
    C:\WINDOWS\ru.exe
    C:\aheava.exe


    now as i had said before this item here you should remove or you may
    end up doing this all over again.there are better progs to use

    To remove the 2 items goto Control Panel Add/Remove Programs & Uninstall/Remove them.

    C:\Program Files\KaZaA Lite\<--This folder this prog is just something you don't need to run on the PC as i had said there are better safer progs .

    C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe<--This file

    I also want you to do this here.

    To disable Windows Me System Restore

    1. Click Start > Settings > Control Panel.
    2. Double-click the System icon.
    Note: If the System icon is not visible, click "View all Control Panel options" to display it.

    3. On the Performance tab click File System.
    4.Click the Troubleshooting tab, and then check Disable System Restore
    5.Click OK. Click Yes, To restart Windows.


    To enable Windows Me System Restore

    After you have restarted, turn System Restore back on

    1. Click Start > Settings > Control Panel.
    2. Double-click System.
    3. On the Performance tab click File System.
    4. On the Troubleshooting tab, uncheck Disable System Restore.
    5. Click OK. Click Yes, when you are prompted to restart Windows.

    NOTE: Please make a new Restore Point as soon as you reboot.

    & get this here out of the way

    and this prog here will help keep your PC clean.

    popular programs for doing this, is a freeware program Called Crap Cleaner. Crap Cleaner is a single utility that lets you clear your Cookies, Internet Explorer History, Empty the Recycle Bin, Uninstall Programs, Clear Usage Tracks and much more. As well as this, it has an Advanced Registry Scanner. Using a program like this is one of the easiest methods.

    make sure to use the option to clean out the Downloaded Programs Files folder.

    Once you are done with all of the above do this here right away.

    Make your Internet Explorer more secure - This can be done by following these simple instructions:

    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
    1. Change the Download signed ActiveX controls to Prompt
    2. Change the Download unsigned ActiveX controls to Disable
    3. Change the Initialize and script ActiveX controls not marked as safe to Disable
    4. Change the Installation of desktop items to Prompt
    5. Change the Launching programs and files in an IFRAME to Prompt
    6. Change the Navigate sub-frames across different domains to Prompt
    7. When all these settings have been made, click on the OK button.
    8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
    5. Next press the Apply button and then the OK to exit the Internet Properties page.

    then come back here give us feedback as to how the PC is.

    & yes some spyware can do this but we will not no till we are clean.

    HGD
    Last edited by HJThis; 04-08-2005 at 06:45 PM.

+ Reply to Thread
Page 2 of 2 FirstFirst 1 2