Hey! I was looking at that! (computer problems)

Want to just shoot the breeze? Forum 42 is the place!

Moderator: Moderators

Post Reply
totokan
Senior Member
Posts: 1785
Joined: Wed May 18, 2005 12:29 pm
Location: 127.0.0.1
Contact:

Hey! I was looking at that! (computer problems)

Post by totokan »

I've got some more computer problems. I'm browsing the web (or even just watching a movie or playing a game) and all of a sudden, my browser changes what i'm looking at to an ad (or, opens up one). Sometimes, it even pops up flash things that you can't x out of (you can alt-f4 'em, though). I've closed all suspicious processes, have not used IE in a long time (here) and it still does it! even as I was writing, it changed the page! After running three virus scans (2 norton, one online) and 2 antivirus (ad-aware SE personal, twice) and deleting everything, it still persists. Any ideas? (Oh, and it sporadicly shut down and came up with an error screen that could only be fixed by inserting the XP disc and hitting enter. Then, it booted like normal.
Shhh! I'm not officially back yet.
mattb419
Posts: 79
Joined: Fri Sep 30, 2005 10:28 am
Location: WV

Post by mattb419 »

did the virus scans find anything (I"m assuming it did, because you said you deleted everything). You should run your scans, make a note of the type of virus/whatever it finds. Let the program delete it, then do a google search on the virus for manual removal instructions. There's probably something that causes it to reinstall itself, and the virus checker isn't getting that taken care of. (you have updated ad-aware and your virus checker too, right?)

-Matt
totokan
Senior Member
Posts: 1785
Joined: Wed May 18, 2005 12:29 pm
Location: 127.0.0.1
Contact:

Post by totokan »

nah, the virus scan didn't find anything. The adware scans did, though. The first was around 1,200- 1,300 high-threat files. the second only found 50, though.
Shhh! I'm not officially back yet.
bicostp
Moderator
Posts: 10491
Joined: Mon Mar 07, 2005 5:47 pm
Steam ID: bicostp
Location: Spamalot
Contact:

Post by bicostp »

Well, even browsing your hard drive uses IE. :x (I'm installing the Firefox File Manager mod later on)

Here's what I'd do:

http://www.spywareinfo.com/~merijn/downloads.html
1. ^Go here and download HijackThis!, CWSredder, and StartUP List and extract the archives.

2. Run CWSredder, it will delete all the parts of CoolWebSearch (if there are any there)

3. Run HijackThis! and save a log file.

4. go to http://forums.thatcomputerguy.us and post the HjT! log there. They'll help you pick out offending files.

5. Try going into MSconfig and disable some of the odd-looking startup items. (leave stuff like QTtask, the QuickToime taskbar, but turn off stuff for Kazaa and stuff you're not too sure about.

6. Reboot into safe mode (press F8 before the Windows logo screen appears) and run AdAware or whatever you use again.

7. Post your HiJackThis! log here too. I have to deal with it a lot, and I do mean a LOT, so maybe I can point some crapware out for you. ;)
totokan
Senior Member
Posts: 1785
Joined: Wed May 18, 2005 12:29 pm
Location: 127.0.0.1
Contact:

Post by totokan »

posted there, and i'll post it here too:
Logfile of HijackThis v1.99.1
Scan saved at 7:54:55 PM, on 11/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RE1M\command.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\windows\sp2update00.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\marc\Desktop\HijackThis1991.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Find Mode Chin Corn] C:\Documents and Settings\All Users\Application Data\Boob Deaf Find Mode\Date second.exe
O4 - HKLM\..\Run: [msresearch] C:\windows\msresearch.exe
O4 - HKLM\..\Run: [sp2update] C:\windows\sp2update00.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [free blue] C:\DOCUME~1\marc\APPLIC~1\PLUSMF~1\Owns Poke Gpl.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} - http://www.miniclip.com/bestfriends/retro64_loader.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/ ... 0_0_44.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/03634bee97e ... xIE601.cab
O16 - DPF: {97A8300E-11F1-4E44-B480-AECFF09C2A70} (XMLTimeElem Control) - http://www.driveonmars.com/atmo-worlds/ ... meElem.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://utu.popcap.com/games/popcaploader_v5.cab
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\kqdbu.dll
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Oh, now it's a lot worse since i ran the CWS shreader thing. Even the ads get knocked out into other ads.
Shhh! I'm not officially back yet.
nos_slived
Higher Idiot
Posts: 3476
Joined: Mon Mar 21, 2005 6:32 pm
Location: Burnaby, BC, Canada
Contact:

Post by nos_slived »

Use Internet Explorer to visit DoxDesk and let the script run. It's helped me find some parasites that Ad-Aware SE, Spybot S&D, and Norton combined couldn't find. It also includes manual removal instructions for most adware/spyware. If this problem has just started occuring with in the last few days, you can use the Windows System Restore, however that would cause you to lose any changes to your system(including downloads) you've made since the selected restore point.

Bic, I don't think Windows uses IE to browse your PC, it uses 'explorer.exe', not 'iexplore.exe'. Though the 2 are virtually intertwined, they stay seperate until you combine their functions(connect to net with explorer or connect to computer with IE), as far as I know.

EDIT: I was thinking, and if the problem is just with IE, you can just disable it.
Image
HotDog-Cart
Portablizer
Posts: 3804
Joined: Sat Jul 16, 2005 12:07 pm
PSN Username: Lythinca
Steam ID: scythe_king
Location: Your IP Address, Connecting...
Contact:

Post by HotDog-Cart »

I was just watching something like this one CAll for help

Try Spybot, becuase spyware can do that to you, try Adware away, to get rid of adware, if if that doesnt work, Go into Regsitry Editor and look for a command that is telling IE to do that, and disable that command (You may have to look through a lot of folders) registry command
Image
sam
Senior Member
Posts: 1746
Joined: Mon Jan 10, 2005 7:23 am
Location: toronto
Contact:

Post by sam »

bicostp wrote:Well, even browsing your hard drive uses IE. :x (I'm installing the Firefox File Manager mod later on)

Here's what I'd do:

http://www.spywareinfo.com/~merijn/downloads.html
1. ^Go here and download HijackThis!

3. Run HijackThis! and save a log file.

4. go to http://forums.thatcomputerguy.us and post the HjT! log there. They'll help you pick out offending files.

7. Post your HiJackThis! log here too. I have to deal with it a lot, and I do mean a LOT, so maybe I can point some crapware out for you. ;)
I will also take a quick sift through to see.
I'm the man, if you don't think so, you're wrong.
sniper_spike wrote:That sucks, bro's before ho's anyway man.
Image
Post Reply