I dont know if its spyware, or viruses or what

MacThurston

New Member
:eek:

So, from reading various forums, Im going to assume my browser is being Hijacked or something.

Whenever my Computer has a connection to the internet present, Im geting Popup/popunder Ads about once every 5 minutes, on a good day. every 1-2 minutes on a bad one.

Some of the addresses that are popping up are
www.newsalone.com, yourthruths.com, gogojournalist.com goodrumor.com
Just to name a couple.

I had norton antivirus...and everytime my computer tried to install it (before this all happened) something wierd wouold happen, and some crap or another would get all screwy....Im assuming I wasnt protected.

Ive since installed AVG free edition....and it reads that I have no viruses. Yay.

Ive installed and Run a million different spy/adware removal programs...

Adaware finds some problems, asks if I want to quarrantine and remove them. I say yes, and It gives a progressbar for the quarrantine, and after its full it changes the name of the progress bar to "deleting files" but then the program ALWAYS stops responding, and sometimes freezes my Comp. So I uninstalled and Removed Adwaware

Spybot S&D finds problems and I click 'fix', and they say it was fixed. Then If I scan again, it brings up the same problems again...it dosent solve anything.

Spysweeper wouldnt even install properly, Im assuming because of the constant browser interuptions being the popups that have been plauging me.

I figured Id free up some RAM in msconfig.
You know, to help the remover programs run better.
Didnt work.

My credit card is maxed until the end of the month, so I cant buy anything to fix this as of right now, and The free programs have been sucking hard.

Im assuming I havent given enough information for anyone to accuratly asses a souloution to my problem, but If anyone can help me, Let me know the information you need from me.

and for what its worth, my MSM is [email protected]
 
A bit more involved description

this is my Hijack this logfile.......
I know something here is the problem

Logfile of HijackThis v1.99.1
Scan saved at 1:37:55 AM, on 9/22/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 SP1 (5.50.4134.0600)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\PROGRAM FILES\AMD\POWERNOW!\GEMBACK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\GREATIS\REGRUNSUITE\WATCHDOG.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMP\WZBEC\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts.../deskredir2.dll?s=consumericon&c=2C01&lc=0409
R3 - URLSearchHook: (no name) - {4F34F636-42D1-3726-A7AC-6543B564F0CA} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\EN-US\MSNTB.DLL
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AMD PowerNow!] "C:\Program Files\AMD\PowerNow!\GemBack.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [Regrun2] C:\PROGRA~1\GREATIS\REGRUN~1\WatchDog.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
 
Yes you got spyware. Try download Microsoft defender and scan your computer. If still has problem after scan and clean do it again in safe mode
 
Defender doesn't have to be run in safe mode. It is capable of stopping and then deleting processes on the fly. It really is quite nice.

If you still have problems, download Ewido and any updates, then reboot in safe mode and do a scan.
 
also try spybot and use avg free version anti virus along with zonealarm firewall it is also free google them, norton is system intensive and i got rid of it .
 
processor not supported

so, i downloaded defender, and I cant use it. Its not supported by my processor type. is there an earlier version for dinosaurs like myself?

Not to mention, it seems like the windows Im running is not supported by anything microsoft is making anymore.

Im using Windows ME
 
Last edited:
I should have asked about your OS. I guess I really wasn't on the ball on that one. Defender is only for XP.

You'll have to go with Ewido and run it in Safe Mode.
 
Ewido wont work either. It needs windows 2000, and im running ME.
(Windows ME is stupid.)

Im prepared to take drastic measures if need be.
I dont have the disk for my OS, but is there any way I can do this with drastic measures

I would be happy with a Bare bones system if I didnt have these popups. I can always make backups of my important documents.

Im at the point where Id erase everything if It would solve it. I wish I had the OS disk.
 
Ewido doesn't work on Me? lol. You're kidding me... :rolleyes: That sucks.

*sigh*

Ok, well the only thing you are left with that I know for sure works on Me is Adaware and Spybot. Spybot really isn't much use against the latest threats though, but what choices do you have left? Just update both of them and scan in safe mode.

Another trick I use is manually editing the registry, but that's because I know what I'm looking for. I dare not attempt to describe that process over the net.

Last resort? Bail and reformat. It will give you something to do on a Sunday afternoon.
 
Back
Top