Adware problem

Status
Not open for further replies.

edgsam

Posts: 7   +0
Hi, I'm a newby here so be gentle. Got a pop-up problem I hope someone can help me with. I've read and followed the instructions in the thread "How to remove Begin2Search/CoolwebSearch/HomeSearch Assistant etc." This has helped, But still have pop-ups and a program called MMViewer by nLite asking to be installed(which I don't). Have attached HJT log text. Please can anyone help me with this. Thanks Ed
 
Hello Welcome to Techspot please read this

How remove coolweb can be found Here

How to post a Hijackthis log and things i need to get it doen can be found Here

Remember read all the instructions there and follow them most of time a good spyware program wil remove some of them there a good link there for a god one do everything posted above and repost your log.
 
Hi Tbrunt3, Tried to install a-squared, but never recieved code via e-mail. Oh well, thats the way things seem to go for me. lol
Anyway, I was able to perform all instructions in the "How to remove Begin2Search etc.", but still having problems. Frustration is building. Someone please help.
 
Hang on bud gave u the wrong link sorry my mistake go Here Get spybot from downloads.com update and run it with all windows closed...

your problem is here

O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe <<<< this is a worm called the RBOT-FP Worm

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE IF you do not have realteck auido this is a problem it basically still spyware if you have realteck audio becuse they use to spy one you info can be found here..

http://www.2-spyware.com/file-alcxmntr-exe.html
THese two boot in safe mod and remove

O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) <-- Always Remove (HKCU)


Have hijackthis fix this

run spybot updat and run your antivirus and repost your log
 
Hello again Tbrunt3. Well, did as you suggested and at first I thought everything was rosy, but then came little cluster of adds. Am attaching latest HJT log. Thank You
 
Ok I hope Realblackstuff takes a look at this I did get rid of the real nasties... Did you turn off system restore?
also down load and install this program called spyware blaster from Here Update this and enable all protection

Did you ever think about running firefox ?You should and just use IE for updates

Download firefox Here PLease note you will need to install JAVA and macromedia flash to use it
Let us know
 
Boot in Safe Mode.
Switch System restore OFF.
Press Ctrl/Alt/Del simultaneously, select Taskmanager/Processes, select the process (if there), click "End Process" for:
gccufem.exe

Next, run HJT on its own and let it 'fix':
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [gccufem] c:\windows\system32\gccufem.exe

When done, delete the highlighted bold files.

Empty the "Temp" folder:
C:\Documents and Settings\{user}\Local Settings\Temp

In Internet Explorer, click on Tools/Internet options and
empty your Temporary Internet Files, all Offline content and delete Cookies.

Boot normal. When all OK, switch System Restore back on.
 
Tbrunt3 and Realblackstuff... You folks are FANTASTIC!!!!
Every thing seems to be back to normal and I'm as happy as Lark in a moonshiners birdbath.. Thankey, thankey, thankey..Burp*
Now going to start using Firefox, wanted to wait till bugs were gone.

Again Thank You Both,
Ed
 
Your very welcome and the bugs been out of firefox for a while even the few bugs it once had dose not compare the the problems with IE.
 
Status
Not open for further replies.
Back