Help me with annoying popup

Status
Not open for further replies.
Help me with annoying popup pls

I had the mssearchnet.exe virus/problem
I got rid of it, but now the annoying pop up is still going.
It says "System Intrusion Detected!" it pops up every few seconds

Thanks in advance
 
did you run your anti-virus and antispyware software like a good little computer user should? If not, why not?
HJT doesn't tell much.....


Do your homework before requesting help! post results after running spybot, ad-aware, and ewido and your anti-virus


thanks
 
I read through this forum before posting. I found similiar problems, and tried the solution. It got rid of some problems, but the thing still pops up.

I did ad-aware, ewido, spybot, and I even tried the spyaxe thing.

I believe its the same problem kimchi is having in the other thread.

Kimchi's thread
 
Hello and welcome to Techspot.

Boot into safe mode, and turn off system restore.

Go to add remove programmes, and uninstall anything to do with.

C:\Program Files\MSN Toolbar Suite

C:\Program Files\Spyware Cleaner

C:\Program Files\SpywareStrike

open task manager, and end the process for(if still there)

SpywareCleaner.exe
Remind_XP.exe
SpywareStrike.exe
SCService.exe

Now. Run HJT with no other programmes open, and let HJT fix the following(if still there).

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q404&bd=pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q404&bd=pavilion&pf=desktop
O2 - BHO: HomepageBHO - {27150f81-0877-42e9-af13-55e5a3439a26} - C:\WINDOWS\system32\hpD002.tmp (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-ca\msntb.dll (file missing)

O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [SpywareStrike] C:\Program Files\SpywareStrike\SpywareStrike.exe /h
O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-ca\bin\WindowsSearch.exe

O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

O23 - Service: SpywareCleanerService - Secure Computer, LLC - C:\Program Files\Spyware Cleaner\SCService.exe

Once HJT has fixed the above, close HJT.

Click start/run, and type services.msc into the run box, and hit the enter key.

Maximise the window that appears, and look through the list of services untill you see SpywareCleanerService, or anything related to it. Right click on it`s entry, and select stop if it`s running. Now select properties, and set the startup type to disabled. Click apply/ok.

Reboot your computer, and post a fresh HJT log. Oh, and don`t foget to turn on system restore again.

Regards Howard :wave: :wave:
 
Status
Not open for further replies.
Back