1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Worse than Crabs

Discussion in 'Virus & Other Malware Removal' started by ali_dheli, Feb 15, 2005.

Thread Status:
Not open for further replies.
  1. ali_dheli

    ali_dheli Thread Starter

    Joined:
    Feb 15, 2005
    Messages:
    1
    Bismillahir Rahman ir Rahim

    I can't get rid of this adware. i purchased mcafee, i've run adaware in safe mode with this and that and still the popups and desktop links and toolbar installs return. here is my hijackthis log -- HOWEVER i am getting several error messages when i start scanning, included below:

    An unexpected error has occurred at procedure:
    modRegistry_IniGetString(sFile=win.ini, sSection=windows, sValue=load)
    Error #62 - Input past end of file

    Please email me at [email protected], reporting the following:
    * What you were doing when the error occurred - scanning
    * How you can reproduce the error - um, scan again
    * A complete HijackThis scan log, if possible -- see below

    Windows version: Windows NT 5.01.2600
    MSIE version: 6.0.2800.1106
    HijackThis version: 1.99.0

    This message has been copied to your clipboard.

    An unexpected error has occurred at procedure:
    modRegistry_IniGetString(sFile=win.ini, sSection=windows, sValue=run)
    Error #55 - File already open

    Please email me at [email protected], reporting the following:
    * What you were doing when the error occurred
    * How you can reproduce the error
    * A complete HijackThis scan log, if possible

    Windows version: Windows NT 5.01.2600
    MSIE version: 6.0.2800.1106
    HijackThis version: 1.99.0

    This message has been copied to your clipboard.

    An unexpected error has occurred at procedure: modMain_CheckNetscapeMozilla()
    Error #55 - File already open

    Please email me at [email protected], reporting the following:
    * What you were doing when the error occurred
    * How you can reproduce the error
    * A complete HijackThis scan log, if possible

    Windows version: Windows NT 5.01.2600
    MSIE version: 6.0.2800.1106
    HijackThis version: 1.99.0

    This message has been copied to your clipboard.

    Logfile of HijackThis v1.99.0
    Scan saved at 12:23:26 AM, on 2/15/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\System32\winupdt.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\Prayer Times 4\Adhnqq06.exe
    C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Yahoo!\Messenger\YPager.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\CxtPls\CxtPls.exe
    C:\WINDOWS\System32\taskmgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\iISystem Wiper\SystemWiper.exe
    C:\Documents and Settings\ali\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
    http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
    http://www.begin2search.com/sidesearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://www.geminidesignjewelry.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant
    = http://www.begin2search.com/sidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant
    = http://www.begin2search.com/sidesearch.html
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} -
    C:\Program Files\CxtPls\cxtpls.dll
    O2 - BHO: ohb - {988CAFC4-DC0D-4D8C-A35E-5028ABE9E641} -
    C:\WINDOWS\System32\ic2_win.dll
    O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} -
    C:\WINDOWS\System32\dsktrf.dll
    O3 - Toolbar: McAfee VirusScan -
    {BA52B914-B692-46c4-B683-905236F6F655} -
    c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Begin2Search.com Bar -
    {207AEF46-0596-4966-A7BF-098F247E85BB} -
    C:\WINDOWS\System32\ic2_win.dll
    O4 - HKLM\..\Run: [VSOCheckTask]
    "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
    O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe
    /v=3 /cleanup
    O4 - Global Startup: Prayer Call 4.0.lnk = C:\Program Files\Prayer
    Times 4\Adhnqq06.exe
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com
    Operating System Class) -
    http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr
    Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O23 - Service: McAfee.com McShield - Unknown -
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc -
    C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks
    Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe


    ***

    thanks tech support guy
     
  2. ekim68

    ekim68

    Joined:
    Jul 8, 2003
    Messages:
    53,631
    First Name:
    Mike
    Why is this "worse than crabs"?
    What are crabs worth?
    Sorry, had to ask.....Have you done a trace back to the source?
    Do you have a firewall? And, does it have logs and dates?
     
  3. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    Hi ali_dheli, Welcome to TSG!! :)

    Download Adaware SE http://lavasoft.element5.com/software/adaware/

    Install the program and launch it.

    First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.

    From main window: Click Start then under Select a scan Mode tick Perform full system scan.

    Next deselect Search for negligible risk entries.

    Now to scan just click the Next button.

    When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

    Reboot and post another HJT log for review.
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/330730

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice