![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Oct 2005
Posts: 12
OS: XP
|
Apropos Media has infected my computer
I checked out all your 'do this first stuff' and this is everything I have completed:
Ran a Microsoft Antispyware scan and deleted the AproposMedia Browser and removed it (but I've done this numerous times and it comes back) Ran Trend Micro PCcillin Internet Security 2005, but it finds nothing. Ran Ad-Aware SE Professional Edition and deleted all baddies. Ran Ad-Aware's VX2 Cleaner and it came up clean. Ran Ad-Aware's online virus scan and it too came up clean. Checked out the rogue program spywarrior.com and I'm sure I do not have any of these programs. I always update Windows, Microsoft, Office and Internet Explorer. (Mainly because I used to be a Windows 98se user with a Mozilla browser and had no problems and recently upgraded to WindowsXP -the edition for 98se with sp2 already included...i.e. not a separate disk- and even since I've been having problems of some sort, but this problem is of course my fault.) I downloaded and installed to HJT file on C drive the Hijackthis and the Analyzer and have copied the result file below: ==================================================================== Log was analyzed using KRC HijackThis Analyzer - Updated on 9/28/05 Get updates at http://www.greyknight17.com/download.htm#programs ***Security Programs Detected*** C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe" O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 12:49:46 PM, on 10/8/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe E:\IOMEGA~1\EASYCD~1\CreateCD\createcd.exe C:\Program Files\ATI Multimedia\main\launchpd.exe C:\Program Files\ATI Multimedia\main\ATIDtct.EXE C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe C:\Program Files\BELKIN-SSA\UPSData.exe O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [CreateCD] E:\IOMEGA~1\EASYCD~1\CreateCD\createcd.exe -r O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE O4 - Startup: BELKIN.lnk = C:\Program Files\BELKIN-SSA\Upsmon.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) - https://oca.microsoft.com/en/secure/ocarpt.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{3CDA5C27-FAC1-4CFB-993B-ABA632A1B85E}: Domain = Sonic.net O17 - HKLM\System\CCS\Services\Tcpip\..\{3CDA5C27-FAC1-4CFB-993B-ABA632A1B85E}: NameServer = 208.201.224.11,208.201.224.33 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = Sonic.net O17 - HKLM\System\CS1\Services\Tcpip\..\{3CDA5C27-FAC1-4CFB-993B-ABA632A1B85E}: Domain = Sonic.net O17 - HKLM\System\CS1\Services\Tcpip\..\{3CDA5C27-FAC1-4CFB-993B-ABA632A1B85E}: NameServer = 208.201.224.11,208.201.224.33 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = Sonic.net O17 - HKLM\System\CS2\Services\Tcpip\..\{3CDA5C27-FAC1-4CFB-993B-ABA632A1B85E}: Domain = Sonic.net O17 - HKLM\System\CS2\Services\Tcpip\..\{3CDA5C27-FAC1-4CFB-993B-ABA632A1B85E}: NameServer = 208.201.224.11,208.201.224.33 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = Sonic.net O23 - Service: BELKIN_Service - Unknown owner - C:\Program Files\BELKIN-SSA\UPSsrv.EXE End of KRC HijackThis Analyzer Log. ==================================================================== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Please download the file I have attached to this post - FindAP.zip
**IMPORTANT - extract/unzip the contents to a folder of it's own ** From within that folder, double-click on FindAP.bat It will produce a log for you to post back to me. Next, download RootKitRevealer.zip Unzip it to the desktop, run it, and click Scan. This will generate a log file. Please post the entire contents of the log file in your next reply. If the file is too big, place it as an attachment instead.
__________________
Question - what have you done for the community today? |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Oct 2005
Posts: 12
OS: XP
|
bat file keeps trying to run
Windows Antispyware keeps giving me an alert the 'a script requires your approval' and I keep clicking allow, this has gone on for quite some time, does it need to do this or is it not running?
what is the grep executable that was in the zip? when do I run that? |
|
|
|
|
#5 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Please post RootkitRevealer's log when you have completed running it.
__________________
Question - what have you done for the community today? |
|
|
|
|
#7 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Please download the file I have attached to this post. - fixARP.zip
**IMPORTANT - Extract/Unzip it to it's own folder Next, please reboot your computer in SafeMode by doing the following: 1. Restart your computer 2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3. Instead of Windows loading as normal, a menu should appear 4. Select the option to run Windows in Safe Mode. From within it's folder, double click on fixARP.bat Wait for it to present you with a log. Then reboot to Normal Mode & post that along with a new FindAP log.
__________________
Question - what have you done for the community today? |
|
|
|
|
#8 (permalink) |
|
Registered User
Join Date: Oct 2005
Posts: 12
OS: XP
|
done, I look clean
fixAPR:
Deletion of folder succeeded! Deletion of file C:\WINDOWS\system32\drivers\ipsparse9.sys succeeded! Deletion of file C:\WINDOWS\system32\MMSOEX32.EXE succeeded! new findAP: Running from directory: C:\FindAP ~~~~~~ Registry entries found: ~~~~~~ |
|
|
|
|
#9 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Your system is clean
Now that your system is clean, please follow these simple steps in order to keep your computer clean and secure:
Update all these programs regularly. Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released. Follow this list and your potential for being infected again will reduce dramatically. Here are some additional utilities that will further enhance your safety.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein After doing all these, your system will be optimised against future threats. It's okay to delete the Hijack This folder in a couple weeks if everything is working okay. Have a safe & happy computing day. ![]() Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Question - what have you done for the community today? |
|
|
|
|
#11 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Never EVER turn System Restore off.
If anyting had gone bad during the fix, you would have lost your only option to rescue the Operating System. You neednt re-do the fix. You're clean. Just re-enable System Restore.
__________________
Question - what have you done for the community today? |
|
|
|
|
#12 (permalink) |
|
Registered User
Join Date: Oct 2005
Posts: 12
OS: XP
|
ok re-enabled sys restore
I thought with sys restore on that anything I deleted would reappear, guess I was wrong, got it back on now.
Thanks for all your help, I will gladly send something when I get paid Thursday! |
|
|
| Thread Tools | |
|
|