Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 06-04-2005, 03:11 PM   #1 (permalink)
mayank76
Guest
 
Posts: n/a
Default Plllllllleeeeeeeeessssssseeee hELP ME


Please help me ,whenever i connect to the net after 10 minutes pop-ups of celebrety uncenssored strats, and nude pop-ups comes to my screen . i have tried to remove it many times but in vain. i know that it is due to e-dialer. it does not get installed in my computer but reinstall its entry in windows registry after conecting to net in software section .i have super ad blocker & google ad blocker but they can not block it , ihave microsoft antispyware but it only detects it on scanning does not stop it while installing in registry , pllllllleeeeeeeeeessssseeeeee help me. I am so ashamed that i have stopped browsing at my home .
 
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 06-04-2005, 03:49 PM   #2 (permalink)
Wise Old Owl
 
aadipa's Avatar
 
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
Default

Run CWShreder and HijackThis.
Post your HijackThis log file.

Get this files from http://www.spywareinfo.com/~merijn/
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
aadipa is offline  
Old 06-04-2005, 04:07 PM   #3 (permalink)
In The Zone
 
Join Date: Feb 2005
Posts: 278
Default

tried running a scan on spybot ?

http://www.spybot.info/
__________________
C2D@ 2.4Ghz,Asus P5B Dlx,2X1GB Kingston@677 Mhz,Viewsonic 20",Sparkle 7200 GS ,SB Live Audigy on Creative Inspire T7900,Leadtek WinFast XP TV Tuner,Storage :Seagate 320GB + WD My Notebook 1TB
blacklight is offline  
Old 06-04-2005, 04:45 PM   #4 (permalink)
Right Off the Assembly Line
 
Join Date: Apr 2005
Posts: 1
Default

pls go to add remove progarmes to find un authorised application and try to un install it
shankarpdrin is offline  
Old 06-04-2005, 05:11 PM   #5 (permalink)
why need title?
 
bharathbala2003's Avatar
 
Join Date: Feb 2005
Location: CONFUSED!! AM LOST
Posts: 1,134
Default

get spybot also post hijack this log..

http://www.safer-networking.org/en/index.html

also with this
AdAware
http://www.lavasoftusa.com/software/adaware/

and after these scans post the log file of HijackThis....
http://www.spychecker.com/program/hijackthis.html

Learn how to use HijackThis here....
http://www.thinkdigit.com/forum/viewtopic.php?t=15729
bharathbala2003 is offline  
Old 06-04-2005, 05:17 PM   #6 (permalink)
sunnydiv
Guest
 
Posts: n/a
Default



grniing



try adaware, and pray to god, pray pray pray
 
Old 06-04-2005, 06:01 PM   #7 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default spyware definately !

empty ur pc of cookies and temp internet files. then scan your pc with adaware, cws shredder, spybot. in future download and use spywareblaster and spywareguard, BOTH from JAVACOOL. they work very effectively and quietly in the background , when u r on the net. as far ar pop-up blockers r concerned, google is considered the best.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 06-04-2005, 09:23 PM   #8 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

Along with CWShredder, get ABout:Buster and run both of them in SAFE Mode.
http://www.majorgeeks.com/download4289.html
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 07-04-2005, 11:24 AM   #9 (permalink)
Alpha Geek
 
club_pranay's Avatar
 
Join Date: Apr 2004
Location: United States
Posts: 624
Default

using only one anti-spyware never works for me. try Lavasoft AdWare or XSoftSpy also and as told by aadipa , bharathbala2003 post hijackthis log asap.
__________________
Be not Thou far from me o Lord....o my strength....haste Thee to help me.
club_pranay is offline  
Old 07-04-2005, 09:37 PM   #10 (permalink)
In The Zone
 
himtuna's Avatar
 
Join Date: Apr 2005
Location: Delhi
Posts: 241
Default

Simple way - use another explorer like opera or firefox instead of IE . It woked with me.Iam using opera.
__________________
http://www.himtuna.com/
http://www.himanshuthakur.com/
Do good to be good !
himtuna is offline  
Old 07-04-2005, 10:03 PM   #11 (permalink)
why need title?
 
bharathbala2003's Avatar
 
Join Date: Feb 2005
Location: CONFUSED!! AM LOST
Posts: 1,134
Default

Quote:
Originally Posted by himtuna
Simple way - use another explorer like opera or firefox instead of IE . It woked with me.Iam using opera.
so leave IE corrupted huh? and make ya computer vunerable for attacks.. gr8 option

seriously id recomend u to scan with the above mentioned tools.. else u r in a danger only..
bharathbala2003 is offline  
Old 08-04-2005, 09:50 PM   #12 (permalink)
In The Zone
 
himtuna's Avatar
 
Join Date: Apr 2005
Location: Delhi
Posts: 241
Default

Quote:
Originally Posted by bharathbala2003
Quote:
Originally Posted by himtuna
Simple way - use another explorer like opera or firefox instead of IE . It woked with me.Iam using opera.
so leave IE corrupted huh? and make ya computer vunerable for attacks.. gr8 option

seriously id recomend u to scan with the above mentioned tools.. else u r in a danger only..
himtuna replys: itried spyware doctor for one week, ms anti spy , spybot(in use) and even deleted some suspecious folders but my cheaks went pink when i was etrading along with my papa
therf i tried opera .iam teerrriieeeeeeeefied to use IE
__________________
http://www.himtuna.com/
http://www.himanshuthakur.com/
Do good to be good !
himtuna is offline  
Old 09-04-2005, 10:12 AM   #13 (permalink)
why need title?
 
bharathbala2003's Avatar
 
Join Date: Feb 2005
Location: CONFUSED!! AM LOST
Posts: 1,134
Default

i dont think its not too difficult.. jus run a scan using the HJT and post the log here.. ur prob can b solved..
bharathbala2003 is offline  
Old 09-04-2005, 02:01 PM   #14 (permalink)
In The Zone
 
himtuna's Avatar
 
Join Date: Apr 2005
Location: Delhi
Posts: 241
Default

hi what is HJT and how to post log ?
__________________
http://www.himtuna.com/
http://www.himanshuthakur.com/
Do good to be good !
himtuna is offline  
Old 09-04-2005, 02:07 PM   #15 (permalink)
why need title?
 
bharathbala2003's Avatar
 
Join Date: Feb 2005
Location: CONFUSED!! AM LOST
Posts: 1,134
Default

Quote:
Originally Posted by himtuna
hi what is HJT and how to post log ?

jus scroll above to my 1st post in the thread..

Quote:
and after these scans post the log file of HijackThis....
http://www.spychecker.com/program/hijackthis.html

Learn how to use HijackThis here....
http://www.thinkdigit.com/forum/viewtopic.php?t=15729
bharathbala2003 is offline  
Old 09-04-2005, 02:35 PM   #16 (permalink)
In The Zone
 
himtuna's Avatar
 
Join Date: Apr 2005
Location: Delhi
Posts: 241
Default

himtuna posts:
StartupList report, 09/04/2005, 14:32:27
StartupList version: 1.52.2
Started from : C:\Documents and Settings\compaq\Desktop\BACK UP\hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Drivers\WTSRV.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\RConnect\RConnectDialer.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\compaq\Desktop\BACK UP\hijackthis\HijackThis.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Instant Access = rundll32.exe EGDACCESS_1058.dll,InstantAccess

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}

--------------------------------------------------

Enumerating Download Program Files:

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/s...sh/swflash.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

--------------------------------------------------
End of report, 3,757 bytes
Report generated in 0.040 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
__________________
http://www.himtuna.com/
http://www.himanshuthakur.com/
Do good to be good !
himtuna is offline  
Old 09-04-2005, 03:14 PM   #17 (permalink)
Another Brick in the Wall
 
drgrudge's Avatar
 
Join Date: Jul 2004
Location: Dubai/Chennai
Posts: 3,027
Default

Ohh? This dont look familiar... and also the version seems to be old.
Quote:
StartupList version: 1.52.2
Anyways, there don't seems to be any problem.
__________________
I Love Photography. I Love Aperture. I Love Mac.
drgrudge is offline  
Old 09-04-2005, 05:38 PM   #18 (permalink)
In The Zone
 
Join Date: Jan 2004
Location: www.solinweb.net
Posts: 333
Default

try spbyot search and destroy, it might help you! or the best cure do a freash install

format c: - the best solution!
__________________
www.Solinweb.net - Webhosting was never so cheap in India!
www.cyclone2k.net - More than wrestling....
www.myspacery.com - Myspace Layouts, Myspace Codes, Myspace Generators, Myspace Tweaks
thecyclone2k is offline  
Old 09-04-2005, 05:45 PM   #19 (permalink)
why need title?
 
bharathbala2003's Avatar
 
Join Date: Feb 2005
Location: CONFUSED!! AM LOST
Posts: 1,134
Default

was that HJT log file this looks new

ill post the report of the HIJACK THIS..
Quote:
Logfile of HijackThis v1.99.1
Scan saved at 5:45:35 PM, on 4/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\WINDOWS\system32\pctspk.exe
D:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program files\Opera\opera.exe
D:\HT\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thinkdigit.com/forum
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Bandwidth Monitor Pro] "D:\Program files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...67&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1109423309296
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - D:\WINDOWS\system32\pctspk.exe
O23 - Service: StyleXPService - Unknown owner - D:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - D:\WINDOWS\system32\ZONELABS\vsmon.exe
i suppose u posted sumthin else.. the log file appears in a notepad as soon as u finish the scan.. ill post the screenie of the HJT also and my mouse will point wher to click...

bharathbala2003 is offline  
Old 09-04-2005, 07:01 PM   #20 (permalink)
In The Zone
 
Join Date: Sep 2004
Location: Satishsays.com
Posts: 349
Default

Microsoft Anti Spyware Beta.
http://downloads.microsoft.com
This should help. It is absolutely merciless and very feature rich too.
__________________
SatishSays.com

twitter.com/satishsays
devilhead_satish is offline  
Old 14-04-2005, 10:46 AM   #21 (permalink)
In The Zone
 
himtuna's Avatar
 
Join Date: Apr 2005
Location: Delhi
Posts: 241
Default

Quote:
Originally Posted by devilhead_satish
Microsoft Anti Spyware Beta.
http://downloads.microsoft.com
This should help. It is absolutely merciless and very feature rich too.
invalid e drive that is what i get. I dont have orignal copy of XP.
__________________
http://www.himtuna.com/
http://www.himanshuthakur.com/
Do good to be good !
himtuna is offline  
Old 14-04-2005, 05:15 PM   #22 (permalink)
Another Brick in the Wall
 
drgrudge's Avatar
 
Join Date: Jul 2004
Location: Dubai/Chennai
Posts: 3,027
Default

^ u don't need a original copy, just click "validation recommend" and in the "Validate Windows and obtain the download" radio button thing, just click on "No, do not validate Windows at this time, but take me to the download." and continue.

U r done man! No need for original copy of windows xp!
__________________
I Love Photography. I Love Aperture. I Love Mac.
drgrudge is offline  
Old 14-04-2005, 05:24 PM   #23 (permalink)
Broken In
 
Join Date: Sep 2004
Location: Up, Above the world, So HIGH !!
Posts: 142
Default if only this can help

i was a victim of this too....
formatted my pc ....installed winxp with sp2 and enabled firewall....
it totally disables the pop-up windows....so no more yes and no's to click and spyware knocked out....tyr this and u will b happy....as i am for last one month..
__________________
__...:::---*Keyboard Cowboy*---:::...__
whistler is offline  
Old 15-04-2005, 12:03 AM   #24 (permalink)
anurag_online
Guest
 
Posts: n/a
Default

Hey if you r using windows xp do one simple thing
Run system restore and restore to a point when these advs were not coming will solve ur prob for sure.


P.S. it can also solve some virus problems too.
 
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by ico
- by clinton
- by icebags
- by Charan
- by Piyush

Advertisement




All times are GMT +5.5. The time now is 12:44 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2