1
   

abi popups and every thing else

 
 
dba
 
Reply Wed 20 Jul, 2005 07:28 pm
I need help getting rid of these popups. Sometimes I get a dozen at a time and when i X close them 3 more open, then sometimes the computer freezes.
ABI network is in my ad/remove and i can't get it out, but all the popups i get at the top it says "microsoft internet explorer provided by verizon online" I do have my dsl with verizon,does this mean verizon is the problem? I rarely use IE, i use firefox instead but the popups are still there. I'm going to download hijack this and some of the scanners you recommend like adaware and spybot. Any other sugestions?
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,168 • Replies: 10
No top replies

 
cicerone imposter
 
  1  
Reply Thu 21 Jul, 2005 05:28 pm
dba, Your ISP is not the problem. Go to the Computer Forum and follow the instructions prepared by timber to the letter to get rid of ABI Network worm/popups/spam. Make a hard copy, and follow his instructions step-by-step. Good luck.
0 Replies
 
timberlandko
 
  1  
Reply Thu 21 Jul, 2005 06:49 pm
dba, Click Here to see what c.i. is talking about. If you're willing to do some work, the method laid out has a fine track record, and should, if carefully and exactly followed, result not only in your machine being cleaned up, but hardened against future yuckware infestations.

If you decide to give it a shot, complete the entire process, then post your after-cleanup logs and comments to this thread. Its highly likely the first run-through will remove ABI and a buncha other stuff you neither want nor need, and it also is likely some minor tweaking and touch-up can be done which will further improve your situation.
0 Replies
 
dba
 
  1  
Reply Sat 23 Jul, 2005 09:57 pm
so far so good
i was getting 10 to 20 pop ups at a time. i couldn't keep up with them. i would get rid of one and get three more and then my comp would freeze up. so far what i've done is scanned with spybot, adaware and avg virus scan and i put in outpost firewall. i got rid of almost 200 things not suppose to be there and avg got rid of a virus. so far so good! i use my computer for work and these spyware, adware, trojans, yuckware or whatever they are have cost me time and money. i've lost research, it's taken much longer to get reports done and has raised my blood pressure i'm sure more than several points. this kind of crap has to be illegal. is there any lawyer that has a class action law suit going against any of these marketing companies? i would definitely put my name and experiences on the suit. better yet, if there was software that not only cleaned it from your computer and then protected it, and then also logged where it came from and then sent the same kind of crap right back so they would get inundated with ads and then their computer freezes up. maybe then they understand that no one appreicates it.
my 2 cents and i apologize for the rant.
0 Replies
 
timberlandko
 
  1  
Reply Sat 23 Jul, 2005 10:24 pm
Go ahead and rant. Some suits have been initiated, and some charges have been filed, against spammers and yuckware purveyors. If the principals and their place of business is in the US, they can be sbe, and increasingly are being, successfully challenged and halted legally. Unfortunately, most of them aren't in The US - to begin with - they're in places everywhere from Former Soviet Republics to tiny Pacific Rim and Carribean island nations, with servers anywhere in the world - thats how the internet works. Complicating the problem is that much yuckware is spread by unwitting private computer users, whose machines are infested and act as servers themselves.

By keeping your operating system, browser, email, chat, and messaging clients, and your security/privacy software, properly configured and currently updated, you make the job of getting onto your machine more difficult than most baddies are gonna bother to mess with.. If you are dilligent about your software and esettings, and use your head out there on the 'net, you'll find you have very few problems. Be smart, watch what you click on or download, scan anything you download - at the very least anything you did not knowingly and intentionally download from from anything other thatn a known, reputable, trustworthy, legitimate, mainstream website before installing or opening the file, never click on unexpected, unidentified attachments, even if apparently from freinds, never click on links recieved over a messaging service unless you know and trust the person sending the link and know for sure where the link goes or what it does, and just in general practice Safe Hex; if you take the effort, you'll be way ahead of the game.
0 Replies
 
dba
 
  1  
Reply Mon 25 Jul, 2005 07:40 pm
hijack log
Hi again, I cant tell you how much i enjoy your website. So far outpost firewall, spybot, adaware and avg virus scanner have helped get my computer back working. Below is a hijack this log. does everything look alright or is there more to get rid of.
thanks



Logfile of HijackThis v1.99.1
Scan saved at 9:34:22 PM, on 7/25/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\UTDT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\3DFX INTERACTIVE\3DFX TOOLS\APPS\3DFXMAN.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\UNLOAD\HPQCMON.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\WINDOWS\SYSTEM\PSOF1.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\PROGRAM FILES\CAS\CLIENT\CASCLIENT.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\DESKTOP\HJT1991.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.net/bookmarks/bmredir.asp?region=west&bw=dsl&cd=4.0&bm=ho_home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cgi.verizon.net/bookmarks/bmredir.asp?region=west&bw=dsl&cd=4.0&bm=ho_home
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\CFGMGR52.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot
O4 - HKLM\..\Run: [3dfx Task Manager] "C:\Program Files\3dfx Interactive\3dfx Tools\Apps\3dfxMan.exe"
O4 - HKLM\..\Run: [3dfx RegTool] C:\Program Files\3dfx Interactive\3dfx RegTool\RegTool.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\SYSTEM\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\SYSTEM\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\SYSTEM\wintask.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\CFGMGR52.DLL,DllRun
O4 - HKLM\..\Run: [qt5k36V] QDVMG32.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\outpost.exe /waitservice
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\outpost.exe /service
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Browser Adjustment - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\PLUGINS\BROWSERBAR\IE_BAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://cgi.verizon.net/bookmarks/bmredir.asp?region=west&bw=dsl&cd=4.0&bm=ho_home
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1785b0a9e58751fea420/netzip/RdxIE601.cab
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.com/app/ST/ActiveX.ocx
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\PROGRAM FILES\CAS\CLIENT\CASMF.DLL
0 Replies
 
timberlandko
 
  1  
Reply Thu 28 Jul, 2005 06:44 pm
No, according to that log, things are far from OK- you still have several virulent nasties. Hang in there - I'll try to write up a fix for you within the next 24 hours.
0 Replies
 
timberlandko
 
  1  
Reply Fri 29 Jul, 2005 10:33 pm
Print out these instructions, and don't do anything without fully understanding how to step through this proceedure.

If anything is unclear, please ask on this thread for clarification or further instructions, being as specific as possible what the problem might be. If any of the links don't work, please report that, also in this thread, as soon as you are able.

If, while following the steps below, you should get an error message, try to to report just what you and your machine were doing at the time of the error, what, if anything, you did about it, what the results were, and as close to the EXACT error message you received, not something like "I was doing fine, then all of a sudden I got some sort of error message". Be as specific as possible.

First, update your own resident antivirus and run a full system scan. If you have an expired subscription to a paid antivirus, either renew your subscription, or uninstall the expired version and acquire an antivirus which can be updated to current engine and pattern files. Any of the major name brand applications will work fine. If for some reason you don't wish to pay for a subscription, the following are downloadable free antivirus applications from reputable vendors. The free versions offer adequate basic protection, but will lack certain configuration and convenience features common to paid antivirus apps. Your choice, but whatever, get, update, configure and maintain (per the app's instructions) a current antivirus before going any further, and have it run a full system scan.

AntiVir Free Personal Edition

Avast! 4 Free Home Edition

AVG Free Personal Edition



If you have Ad-Aware SE, HiJackThis, Spybot S&D, or SpywareBlaster installed, I suggest you uninstall them via their own uninstall utilities, or through Add/Remove Programs, and redownload the latest versions. If you are sure you have the latest versions, you can just update them if you wish, and configure them as detailed in their respective sections below ... your call, but I do recommend starting fresh. As for the other tools linked here, if you have any version of them installed, it really is best to uninstall your copy and start fresh, to be sure of having the latest version.

Be certain you have the latest version of HiJackThis, and that it is installed to a folder of its own either in your Programs file or directly on your root drive. If you have already installed HiJackThis, be certain its in its own folder, as described, and not a temporary or desktop folder. Launch the application, then, from its splash screen, choose "Miscellaneous Tools", or from the main start page, select "Config", then select "Search for updates online", confirm, and be sure your's is the latest version. Don't run a scan or fix anything yet. When running HiJackThis to scan or fix things, run it from its own folder, WITH NO OTHER BROWSERS, WINDOWS, FILESHARING, EMAIL, OR MESSAGING APPLICATIONS OPEN OR RUNNING


Go to Windows Update and check to make certain there are no outstanding Service Packs or high-priority updates for your operating system and/or Internet Explorer.

Download WinSockFix. The documentation is available in the downloaded file, be sure to read and understand it. You may not need this, but if the repair process disables your internet connectivity, this will get you back on line. Make sure you read and understand the intructions before going any further.

Download STINGER. Again, just download it right now; we'll use it later. See this TUTORIAL.


Download, install, and update Ad-Aware SE Personal. Just install and update it (when the program has installed, click the blue-green "Planet" icon, second from the right at the top of the screen, to run the auto-update function, and follow the prompts to update the application); don't run a scan yet.

When it has updated, click on the orange-ish "Gear Icon" (second-from the left at the top right-hand side of the window) to open the Ad-Aware configuration utility.

Under the "General" tab, all radio buttons should be green; if not, click to activate them.

Click the "Scanning" bar at the left of the page. Under "Drivers, Folders & Files", only the "Scan within archives" button should be green. Under "Memory & Registry", all buttons should be green.

Click the "Advanced" bar. Under "Shell Integration", "Move deleted files to Recycle Bin" should be green, and its your call whether you want to add "Scan with Ad-Aware to Explorer".

Under "Logfile Detail Level", all 3 buttons should be green.

Under "Alternate Data Streams", both buttons should be red.

Skip the "Startup", "Default", and "Interface" bars for now.

Click the "Tweak" bar. Click the plus-sign to open "Scanning Engine". "Unload recognized processes ... ", "Obtain command line ... ", and ""Scan registry for all users ... " should be green, "Run scan as background ...", "Ignore spanned files ...", and "Use permanent ... " may be left red.

Click to open "Cleaning Engine". The first 5 buttons should be green ("Automatically check ...", "Always try ...", "During removal ... ", "Let Windows remove ... ", and "Delete quarantined ..."} should be green, the remaining 3 ("Suppress warning ...", "Suppress progress ..." and "Disable manual ...") should be red.

Skip the remaining bars, click "Proceed", then close Ad-Aware WITHOUT RUNNING A SCAN.

With Ad-Aware closed, download Ad-Aware's VX2 Cleaner Plugin, and install it per instructions found on the download page. read the instructions carefully so you'll know how to run the plugin when required. Do not run it, or Ad-Aware, yet; just exit back to your desktop.



Download, install, and update Spybot S&D. Just install and update it (when it installs, the program will give you the option to "Download all updates" - let it do so), don't run it yet. READ THE TUTORIAL. When the program has been installed and updated, select "Immunize", click the green "+" plus-sign symbol at the top of the page to install Spybot's immunization, and follow any prompts. On that same page, click to place a checkmark in the "Browser Helper to block bad downloads ... " button, then, from the dropdown below that, select "Block all bad pages silently". While you have Spybot open it would be a good time to read the tutorial available under the Help file at the top left-hand corner of the page. When done, don't run a scan yet, just close the application.

Download CWShredder, and unzip it to your desktop, but don't run it yet.


Download NAILFIX. Just download it and unzip it to a folder on your desktop; don't do anything with it right now.


Download AboutBuster 5.0, unzip it to a folder on your desktop, and read the accompanying text file. Launch and update the application, but don't run it yet; when the update has completed simply close the application and exit to your desktop.


Download Cleanup! 4 - be sure to read the FAQ HERE.

Download DelDomains.inf. When it has downloaded (should take just a few seconds), click on the file to run it. If the link above displays text instead of downloading the file, then copy & paste the text into notepad and save the file as DelDomains.inf. To use it, right-click and select "Install". Note: This will remove all entries in your "Trusted Zone" and "Ranges".


Download, install, and update Javacool Software's SpyWareBlaster. When the update has completed, select "Enable all protection", and exit back to your desktop. SpywareBlaster does not need to be running for its protection to be active, but you should should launch it at least weekly to check for updates. Read the FAQ HERE


Next, configure Windows Explorer to Show All Files

Perform at least 2 of the following free online virus scans (with your own resident antivirus disabled):

Trend Micro Free Online Scan

Panda Free Online Scan

BitDefender Free Online Scan

Symantec Free Online Scan

Kaspersky Free Online Scan

StopSign Free Online Scan

RAV Free Online Scan

McAfee Free Online Scan

IMPORTANT: DISABLE ANY OTHER ANTIVIRUS YOU MAY HAVE ON YOUR MACHINE BEFORE RUNNING ANY OF THE ONLINE SCANS. Also, if you have any popup blocking, adblocking, or actively running antispyware application, disable those as well; they can interfere with online virus scans. Should an online scan report it has detected something it cannot repair or remove, please copy the exact message received and save it to post to your help request thread at the appropriate time.

Make sure your Windows and your programs other than your browser are operating properly, then disable System Restore. Again, be sure everything else works as it should before you do this, as you will remove your previous restore points. How to Disable/re-enable System Restore, Win ME

Remember this procedure, so you can re-enable System Restore when your machine is finally clean., but do not re-enable System Restore until your system really is clean.


Now, Boot Into Safe Mode. Most of the following steps are to be carried out in safe mode until the series is completed, or you are advised to reboot normally. If at any time during the process you do reboot, boot back into safemode unless specifically advised for that step to boot normally before proceding with the next step.


Once booted into safemode, locate Stinger and run it, selecting "Fix". The process may take a fair while to complete - be patient, let it run to the end.

Locate "NAILFIX", and click on "Nailfix.cmd". Your desktop and icons will disappear and reappear, and a window should open and close very quickly.

When NAILFIX has run, locate and run AboutBuster 5.0; if either app prompts you to reboot, do so, then go on to the next step, otherwise, don't reboot.

When AboutBuster 5.0 has completed, locate and run CWShredder, selecting the "Fix" option. Don't reboot unless prompted to do so.

Locate and open Cleanup. When it opens, select "Options", set the slider to "Standard Cleanup", click "OK", then click "Cleanup" and let it scan through your system (which will take a few minutes), Cleanup is complete, you should be prompted to reboot. Reboot, back into safemode.

Locate Ad-Aware SE, and launch it. Click the "Add-ons" bar, locate, and run the VX2 Cleaner plugin. When that has been completed, close then relaunch Ad-Aware SE, select "Scan Now", select "Use custom scanning options", select "Next", and allow the scan to complete - which could take a good long while. When it has completed, have it fix all it has found, then close the application. If it requests permission to run again on reboot, permit it and reboot normally, allowing it to run, have it fix whatever, if anything it found, then reboot back into safe mode.

Locate and launch Spybot S&D, click "Check for problems", and be patient while it scans. Allow it to fix anything it finds that it lists in red. If it requests permission to run again on reboot, permit it and reboot normally, allowing it to run, have it fix whatever, if anything it found and listed in red, then reboot back into safe mode.

When Spybot S&D has finished, run Cleanup once more. When Cleanup has finished, BOOT NORMALLY, not into safemode. Do not connect to the internet yet, and do not re-enable System Restore.

Disable your resident antivirus if not still disabled, then run full system scans Ad-Aware and Spybot S&D, allowing each to fix whatever, if anything, needs fixing.

Run Cleanup once more, then reboot into safe mode again. Close all running applications, and run HiJackThis WITH NO OTHER BROWSERS, WINDOWS, FILESHARING, EMAIL, OR MESSAGING APPLICATIONS OPEN OR RUNNING.
Place a checkmark next to any of these, if found:

O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\CFGMGR52.DLL 3dfxCmn.dll,CMNUpdateOnBoot
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\SYSTEM\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\SYSTEM\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\SYSTEM\wintask.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\CFGMGR52.DLL,DllRun
O4 - HKLM\..\Run: [qt5k36V] QDVMG32.EXE
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O14 - IERESET.INF: START_PAGE_URL=http://cgi.verizon.net/bookmarks/bmredir.asp?region=westbw=dslcd=4.0bm=ho_home
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.com/app/ST/ActiveX.ocx
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\PROGRAM FILES\CAS\CLIENT\CASMF.DLL

and click "Fix".

Run Cleanup once more, then reboot back into safe mode.

Go to Start>Settings>Control Panel >Add/Remove Programs. If you find entries for Virtual Bouncer or Wintasks, remove them. Reboot into safe mode.

Using Windows Explorer - right-click "My Computer", select "Explore" then select your "C:\" drive folder, from that folder's toolbar, select View > Toolbars > Address Bar, in the address bar, type the desired path (for instance: C:\WINDOWS\System\ or C:\Windows\Program Files), click "Go", then locate the designated file or folder - look for and delete if found:

PSof1.exe which if present will be found in C:\WINDOWS\System32\ or C:\WINDOWS\System\ <--- Delete just the specific file, not the folder in which it resides

exp.exe which if present will be found in C:\WINDOWS\System32\ or C:\WINDOWS\System\ <--- Delete just the specific file, not the folder in which it resides


wintask.exe which if present will be found in C:\WINDOWS\System32\ or C:\WINDOWS\System\ <--- Delete just the specific file, not the folder in which it resides


AUNPS2.DLL which if present will be found in C:\WINDOWS\System32\ or C:\WINDOWS\System\ <--- Delete just the specific file, not the folder in which it resides


Now, still with Windows Explorer, look for and if found delete

C:\WINDOWS\cfgmgr52.dll. <--- Delete just the specific file, not the folder in which it resides

The entire folder C:\Program Files\VBouncer\ <--- Delete the entire folder

The entire folder C:\PROGRAM FILES\CAS\ <--- Delete the entire folder



Reboot back into safe mode, and run CWShredder, Ad-Aware SE, and Spybot S&D once more, letting each fix whatever is necessary.

Run Cleanup once more, and reboot normally. Run a fresh HJT scan, this time just saving the log. Now, reconnect to the internet (use WinsockFix if you cannot connect), navigate to this A2K yuckware help thread, and post the new HJT log. Also include any error messages or "could not fix" reports you may have received. Do not re-enable System Restore yet; we may not be done.
0 Replies
 
dba
 
  1  
Reply Sun 4 Sep, 2005 09:18 pm
I'm still bothered by some popups all of them from microsoft. my big problem now is I can't resize my screen or change the color setting. I go to properties - settings and the screen setting is stuck on 640 by 480 pixels (i want 800 by 600) and the collor seems to be stuck on 16 (i want it on 250). I always had them set on 800 by 600 and 250.I've run scans with spybot, lavasoft and avg and nothing. Any suggestions?
Thanks for all of your help
0 Replies
 
timberlandko
 
  1  
Reply Sun 4 Sep, 2005 10:39 pm
Without seeing a fresh HJT log, I haven't a clue what is going on. Did you follow all the steps listed above? Not sure I understand what you mean by " ... some popups all of them from microsoft"; just exactlywhat do these popups look like, and what do they say?

As for your display problem, just shooting in the dark here, but it sounds as though the drivers for your video adapter have become corrupt, or the video adapter itself is faulty, and Windows has defaulted to VGA display mode.
0 Replies
 
timberlandko
 
  1  
Reply Mon 5 Sep, 2005 11:38 am
Followup here - just wanna know if
a) you did as directed

and

b) if you're still looking for help


I'm happy to do what I can for you here, but you've gotta help me help you - unless you wanna ship me your machine and enclose creditcard info so I can bill you.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » abi popups and every thing else
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.05 seconds on 12/28/2025 at 05:11:12