1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: altbill problem

Discussion in 'Web & Email' started by MPeg3, Jan 21, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. MPeg3

    MPeg3 Thread Starter

    Joined:
    Sep 13, 2004
    Messages:
    695
    We are assuming my 14 year old grandson has clicked on something he shouldn't have on the Internet. When my daughter got online this morning, a window popped up that said since they hadn't cancelled something in 3 days, they are legally obligated to pay for it. She couldn't tell where it was coming from except it was an altbill.com address. It said she must click on it to give her financial information and she couldn't get rid of it. She, of course, didn't click on it. Does anyone know of any other way to find out what this is so we can cancel it.

    I went to altbill.com, but to get any support, they wanted my personal information and I was leary to do that.

    We have no clue as to what to do now.

    Thank you for any advice.

    Peg
     
  2. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Click here to download HJTsetup.exe: http://www.thespykiller.co.uk/files/HJTSetup.exe
    Save HJTsetup.exe to your desktop.

    Double click on the HJTsetup.exe icon on your desktop.
    By default it will install to C:\Program Files\Hijack This.
    Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
    Put a check by Create a desktop icon then click Next again.
    Continue to follow the rest of the prompts from there.
    At the final dialogue box click Finish and it will launch Hijack This.
    Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
    Click Save to save the log file and then the log will open in notepad.
    Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    Come back here to this thread and Paste the log in your next reply.
    DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
     
  3. MPeg3

    MPeg3 Thread Starter

    Joined:
    Sep 13, 2004
    Messages:
    695
    I ran Adware this morning and it found something from altbill which it removed. I don't know if that fixed it or not, but when I started their internet just now, it didn't show the window. However, I don't think it showed up every time, but not sure. I can't reach her right now to ask. Can you tell from this if it is still present? Thank you.

    Logfile of HijackThis v1.99.1
    Scan saved at 9:48:17 AM, on 1/23/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    E:\WINDOWS\System32\smss.exe
    E:\WINDOWS\system32\winlogon.exe
    E:\WINDOWS\system32\services.exe
    E:\WINDOWS\system32\lsass.exe
    E:\WINDOWS\system32\svchost.exe
    E:\WINDOWS\System32\svchost.exe
    E:\Sygate\SPF\smc.exe
    E:\WINDOWS\system32\spoolsv.exe
    E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    E:\WINDOWS\System32\inetsrv\inetinfo.exe
    E:\WINDOWS\Explorer.EXE
    E:\WINDOWS\System32\tcpsvcs.exe
    E:\WINDOWS\System32\snmp.exe
    E:\WINDOWS\System32\svchost.exe
    E:\WINDOWS\System32\MsPMSPSv.exe
    E:\WINDOWS\System32\mqsvc.exe
    E:\WINDOWS\System32\mqtgsvc.exe
    E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    G:\TimeUp\TimeUp.exe
    E:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    E:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    E:\PROGRA~1\P2PNET~1\P2PNET~1.EXE
    G:\NetZero\exec.exe
    G:\AIM\aim.exe
    G:\HP Printer\Digital Imaging\bin\hpohmr08.exe
    G:\HP Printer\Digital Imaging\bin\hpotdd01.exe
    E:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    G:\NetZero\exec.exe
    G:\HP Printer\Digital Imaging\bin\hpoevm08.exe
    G:\HP Printer\Digital Imaging\Bin\hpoSTS08.exe
    E:\WINDOWS\system32\wuauclt.exe
    E:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=...D=1108800000000&I=8.NQ2&N=PL&O=A&UT=companion
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - G:\NetZero\Toolbar.dll
    O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [TimeUp] G:\TimeUp\TimeUp.exe /T
    O4 - HKLM\..\Run: [ViewMgr] E:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [SmcService] E:\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [HookUpFinder] E:\Program Files\HookUpFinder\HookUpFinder.Exe
    O4 - HKLM\..\Run: [MediaPipe P2P Loader] "E:\Program Files\p2pnetworks\mpp2pl.exe" /H
    O4 - HKLM\..\Run: [Notification Utility] "E:\Program Files\ItBill\itbill.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKCU\..\Run: [NetZero_uoltray] G:\NetZero\exec.exe regrun
    O4 - HKCU\..\Run: [AIM] G:\AIM\aim.exe -cnetwait.odl
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Startup: Stardock ObjectDock.lnk = E:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .wav: E:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - E:\Sygate\SPF\smc.exe
     
  4. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Add remove programs remove Viewpoint – p2pnetworks

    What is hookupfinder???????????

    Fix these with HJT – mark them, close IE, click fix checked

    O4 - HKLM\..\Run: [MediaPipe P2P Loader] "E:\Program Files\p2pnetworks\mpp2pl.exe" /H
    O4 - HKLM\..\Run: [Notification Utility] "E:\Program Files\ItBill\itbill.exe"

    DownLoad http://www.downloads.subratam.org/KillBox.zip

    Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

    Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

    E:\Program Files\p2pnetworks
    E:\Program Files\ItBill
    E:\Program Files\MediaPipe

    Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

    START – RUN – type in %temp% OK - Edit – Select all – File – Delete

    Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

    Empty the recycle bin
    Boot and post a new log from normal NOT safe mode

    Please give feedback on what worked/didn’t work and the current status of your system
     
  5. MPeg3

    MPeg3 Thread Starter

    Joined:
    Sep 13, 2004
    Messages:
    695
    What is hookupfinder???????????

    I'm not sure. When I right click it in the taskbar, it gives a menu that says

    Log in as a different user
    Check messages
    Prefferences
    Load site

    In the prefferences area it looks like it is a mail checking program. My grandson or granddaughter must have installed it as I am the one who set the computer up and my daughter and son-in-law barely know how to turn it on. :rolleyes: I will have to ask about it.
     
  6. MPeg3

    MPeg3 Thread Starter

    Joined:
    Sep 13, 2004
    Messages:
    695
    My daughter tells me the window saying she had to pay, doesn't pop up every time. I will have to give it a few days to be able to report if there is any more problem or not. Thank you so much for your help with this.

    Logfile of HijackThis v1.99.1
    Scan saved at 10:24:04 AM, on 1/24/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    E:\WINDOWS\System32\smss.exe
    E:\WINDOWS\system32\winlogon.exe
    E:\WINDOWS\system32\services.exe
    E:\WINDOWS\system32\lsass.exe
    E:\WINDOWS\system32\svchost.exe
    E:\WINDOWS\System32\svchost.exe
    E:\Sygate\SPF\smc.exe
    E:\WINDOWS\system32\spoolsv.exe
    E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    E:\WINDOWS\System32\inetsrv\inetinfo.exe
    E:\WINDOWS\System32\tcpsvcs.exe
    E:\WINDOWS\Explorer.EXE
    E:\WINDOWS\System32\snmp.exe
    E:\WINDOWS\System32\svchost.exe
    E:\WINDOWS\System32\MsPMSPSv.exe
    E:\WINDOWS\System32\mqsvc.exe
    E:\WINDOWS\System32\mqtgsvc.exe
    E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    G:\TimeUp\TimeUp.exe
    E:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    E:\Program Files\HookUpFinder\HookUpFinder.Exe
    E:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    G:\NetZero\exec.exe
    G:\HP Printer\Digital Imaging\bin\hpohmr08.exe
    My daughterG:\HP Printer

    \Digital Imaging\bin\hpotdd01.exe
    G:\NetZero\exec.exe
    G:\NotesHolder\NotesHolder.exe
    E:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    G:\HP Printer\Digital Imaging\bin\hpoevm08.exe
    G:\HP Printer\Digital Imaging\Bin\hpoSTS08.exe
    G:\Starter\Starter.exe
    E:\WINDOWS\system32\wuauclt.exe
    E:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = e:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm
    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - E:\Program Files\NZSearch\SearchEnh1.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - G:\NetZero\Toolbar.dll
    O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [TimeUp] G:\TimeUp\TimeUp.exe /T
    O4 - HKLM\..\Run: [ViewMgr] E:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [SmcService] E:\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [HookUpFinder] E:\Program Files\HookUpFinder\HookUpFinder.Exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKCU\..\Run: [NetZero_uoltray] G:\NetZero\exec.exe regrun
    O4 - HKCU\..\Run: [uoltray] G:\NetZero\exec.exe regrun
    O4 - Startup: NotesHolder.lnk = G:\NotesHolder\NotesHolder.exe
    O4 - Startup: Stardock ObjectDock.lnk = E:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .wav: E:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - E:\Sygate\SPF\smc.exe
     
  7. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Log is fine

    Get all of these and/or verify you have the current versions

    SpywareBlaster 3.5.1 http://majorgeeks.com/download2859.html
    SpyBot V1.4 http://www.majorgeeks.com/download2471.html
    AdAware SE 1.06 http://www.majorgeeks.com/download506.html
    MS AntiSpy - http://www.microsoft.com/downloads/...a2-6a57-4c57-a8bd-dbf62eda9671&displaylang=en (XP and W2K only)

    DownLoad them (they are free), install them, check each for their
    definition updates
    and then run AdAware, MS AntiSpy (W2k/XP) and Spybot, fixing anything
    they say.

    In SpywareBlaster - Always enable all protection after updates
    In SpyBot - After an update run immunize
     
  8. MPeg3

    MPeg3 Thread Starter

    Joined:
    Sep 13, 2004
    Messages:
    695
    Thank you for the help, this seems to have been resolved. I appreciate all the help I have gotten from this site.

    Peg
     
  9. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/435958

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice