Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Sep 18 2008, 09:38 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 5 Joined: 13-September 08 Member No.: 238,505 |
Thanks for any advice you can give me Casey This post has been edited by Orange Blossom: Sep 18 2008, 11:42 PM
Reason for edit: Deactivate link and move to more appropriate forum. ~ OB
|
|
|
|
Sep 19 2008, 06:50 AM
Post
#2
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Senior Classmen Posts: 1,670 Joined: 13-December 06 From: The Netherlands Member No.: 100,987 |
Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1 alternate download link 2
-------------------- |
|
|
|
Sep 20 2008, 06:05 PM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 5 Joined: 13-September 08 Member No.: 238,505 |
Malwarebytes' Anti-Malware 1.28
Database version: 1182 Windows 5.1.2600 Service Pack 3 9/20/2008 6:03:45 PM mbam-log-2008-09-20 (18-03-45).txt Scan type: Quick Scan Objects scanned: 65997 Time elapsed: 6 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
Sep 20 2008, 07:25 PM
Post
#4
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 16,573 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
Please download hosts.zip and save it to your Desktop.
Then download and install SpywareBlaster. -------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
|
|
Sep 21 2008, 09:39 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 5 Joined: 13-September 08 Member No.: 238,505 |
Okay did that this morning and now throughout the day I am getting the same result just now it is several differnt sites instead of the usual ad.yieldmanager.com not it is pn1.adserver.yahoo and a couple of hours ago it was a differnt one and couple hours before that yet another different one than either of the two previously mentioned. Although I have not seen the ad.yieldmanager.com I now have seen 3 new sites pop up in my list of visited sites and when I press back button nothing happens. I even turned on ad-watch just the cookie setting turned on and it has detected nothing. I just don't know what else to do, I even went as far as running all my virus softwares in safe mode and still this happens.
|
|
|
|
Sep 22 2008, 07:57 AM
Post
#6
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Senior Classmen Posts: 1,670 Joined: 13-December 06 From: The Netherlands Member No.: 100,987 |
I think Quietman7 will answer here... (?)
-------------------- |
|
|
|
Sep 22 2008, 09:17 AM
Post
#7
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 16,573 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
What browser are you using? If you are using IE, have you checked the Pop-up Blocker Settings?
Check your Trusted Sites List and look for unwanted websites related to any of the pop ups you are getting. If you find any, then remove them. Please download DelDomains.inf alternate download
You may also have other malware on your system that has not been detected so lets try another scan. Please download ATF Cleaner by Atribune & save it to your desktop. alternate download link DO NOT use yet. Please download and install SUPERAntiSpyware Free
Double-click ATF-Cleaner.exe to run the program.
Scan with SUPERAntiSpyware as follows:
-------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
|
|
Sep 23 2008, 06:17 PM
Post
#8
|
|
|
New Member ![]() Group: Members Posts: 5 Joined: 13-September 08 Member No.: 238,505 |
Okay, I have completed all the steps listed and the super anti spy software found no problems, just a note in safe mode it took like 12 hours or more to complete the scan but found 0 over each scan. Also completed atf cleaner and the other item you wanted me to install I guess I will just monitor it for a couple of days and if the problem returns I will let you know.
|
|
|
|
Sep 23 2008, 06:35 PM
Post
#9
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 16,573 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
If there are no more problems or signs of infection, you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.
The easiest and safest way to do this is:
-------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
|
|
Sep 25 2008, 12:21 AM
Post
#10
|
|
|
New Member ![]() Group: Members Posts: 5 Joined: 13-September 08 Member No.: 238,505 |
Did the restore stuff the other day and haven't really used the pc that much the last few days. Got on tonight spent about a minute on ebay and here we go first item I looked at hit the back button and nothing happened pulled the drop down arrow and found the last two pages showed this address: pn1.adserver.yahoo.com/a?kw=alpi So any other thoughts about what I might do? I sure am at a loss.
|
|
|
|
Sep 25 2008, 07:15 AM
Post
#11
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 16,573 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
There may be another piece of malware on your system that we have not found so further investigation is required. Before that can be done you will need you to create and post a hijackthis log.
Please read the pinned topic titled "Preparation Guide For Use Before Posting A Hijackthis Log". If you cannot complete a step, then skip it and continue with the next. In Step 9 there are instructions for downloading the HijackThis Installer and creating a log. This is an automatic setup version which will install the program in the proper location. When you have done that, post your log in the HijackThis Logs and Malware Removal forum, NOT here, for assistance by the HJT Team Experts. A member of the Team will walk you through, step by step, on how to clean your computer. If you post your log back in this thread, the response from the HJT Team will be delayed because your post will have to be moved. This means it will fall in line behind any others posted that same day. Start a new topic, give it a relevant title and post your log along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. An expert will analyze your log and reply with instructions advising you what to fix. After doing this, we would appreciate if you post a link to your log back here so we know that your getting help from the HJT Team. Please be patient. It may take a while to get a response because the HJT Team members are very busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT "bump" your post or make another reply until it has been responded to by a member of the HJT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond. If after 5 days you still have received no response, then post a link to your HJT log in the thread titled "Haven't Had A Reply In Five Days?". -------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 4th July 2009 - 11:18 AM |