Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93101 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Zeno Adware


  • This topic is locked This topic is locked
23 replies to this topic

#16 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 01 June 2006 - 07:03 PM

Good work Christian!

Your logs appear to be clean. You need to update your Java because they just came out with new release.

It appears to me that you use AVG for your anti-virus and the Symantec is for other things. You should only have one anti-virus applications installed because they can interfere with each other. Ewido is different and is designed to work/complement anti-virus.

Are you using Windows firewall? There are firewall applications that are free for personal use so I would recommend using one over just relying on the Windows XP firewall.

You may delete the Avenger tool, let the ewido and spyspeeper trials run out, or purchase them. It's up to you.

Please do the following.

STEP 1.
======
Cleanmgr
To clean temporary files:
  • Go > start > run and type cleanmgr and click OK
  • Scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files and Recycle Bin are the only things checked.
  • Click OK to remove those files.
  • Click Yes to confirm deletion.
STEP 2.( Windows XP only)
======
Prefetch Folder
Open C:\Windows\Prefetch\
Delete All files in this folder but not the Prefetch folder

STEP 3.
======
System Restore for Windows XP
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
  • Turn off System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Reboot.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check *Turn off System Restore*.
  • Click Apply, and then click OK.

STEP 4.
======
DON’T BECOME OVERCONFIDENT WITH ANTIVIRUS APPLICATIONS INSTALLED!!!

http://forum.malware...39eba6ea0b5e8ee

Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.

"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly.
    For a tutorial on Firewalls and a listing of some available ones see the link below:
    Understanding and Using Firewalls

  • Test your Firewall - Please test your firewall and make sure it is working properly.
    Test Firewall

  • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
    A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update your Java to the latest version.
  • Go to Start > Control Panel double-click on the Software icon > add/remove programs.
  • Search in the list for all previous installed versions of Java. (J2SE Runtime Environment.... )
    It should have next icon next to it: Posted Image
    Select it and click Remove.
  • Then Download and install the newest version from here:https://sdlc6c.sun.c...4E1EA2D176EE3EA



[*]Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.


[*]More info on how to prevent malware you can also find here (By Tony Klein)
and here: http://wiki.castleco...nt_Re-infection
[/list]Follow this list and your potential for being infected again will reduce dramatically.

Thank you for allowing me to assist you.

Susan
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

    Advertisements

Register to Remove


#17 Christian

Christian

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 01 June 2006 - 08:33 PM

Thanks for all your help! Christian

#18 Christian

Christian

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 01 June 2006 - 08:39 PM

ok...i just realized I still have popups every once in a while from popuptraffic.com U sure everything is all gone?

#19 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 02 June 2006 - 03:56 AM

Could you run SpySweeper and ewido again and post(reply) with the results please. Also do you have a pop-up blocker? Google has a pop-up blocker that you can install for free.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#20 Christian

Christian

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 02 June 2006 - 01:44 PM

ok i ran them both...I dont have a popup blocker except for the one that INternet Explorer has... SpySweeper: ******** 1:24 PM: | Start of Session, Friday, June 02, 2006 | 1:24 PM: Spy Sweeper started 1:24 PM: Sweep initiated using definitions version 690 1:24 PM: Starting Memory Sweep 1:27 PM: Memory Sweep Complete, Elapsed Time: 00:03:35 1:27 PM: Starting Registry Sweep 1:28 PM: Registry Sweep Complete, Elapsed Time:00:00:12 1:28 PM: Starting Cookie Sweep 1:28 PM: Found Spy Cookie: 50881381 cookie 1:28 PM: hp_owner@50881381[1].txt (ID = 1981) 1:28 PM: Found Spy Cookie: websponsors cookie 1:28 PM: hp_owner@a.websponsors[2].txt (ID = 3665) 1:28 PM: Found Spy Cookie: yieldmanager cookie 1:28 PM: hp_owner@ad.yieldmanager[2].txt (ID = 3751) 1:28 PM: Found Spy Cookie: adecn cookie 1:28 PM: hp_owner@ad2.adecn[1].txt (ID = 2064) 1:28 PM: hp_owner@adecn[2].txt (ID = 2063) 1:28 PM: Found Spy Cookie: adknowledge cookie 1:28 PM: hp_owner@adknowledge[2].txt (ID = 2072) 1:28 PM: Found Spy Cookie: hbmediapro cookie 1:28 PM: hp_owner@adopt.hbmediapro[2].txt (ID = 2768) 1:28 PM: Found Spy Cookie: hotbar cookie 1:28 PM: hp_owner@adopt.hotbar[2].txt (ID = 4207) 1:28 PM: Found Spy Cookie: specificclick.com cookie 1:28 PM: hp_owner@adopt.specificclick[2].txt (ID = 3400) 1:28 PM: Found Spy Cookie: adprofile cookie 1:28 PM: hp_owner@adprofile[2].txt (ID = 2084) 1:28 PM: Found Spy Cookie: aff01511 cookie 1:28 PM: hp_owner@aff01511[1].txt (ID = 2185) 1:28 PM: Found Spy Cookie: aff506 cookie 1:28 PM: hp_owner@aff506[1].txt (ID = 2189) 1:28 PM: Found Spy Cookie: aff6007 cookie 1:28 PM: hp_owner@aff6007[1].txt (ID = 2193) 1:28 PM: Found Spy Cookie: tacoda cookie 1:28 PM: hp_owner@anat.tacoda[1].txt (ID = 6445) 1:28 PM: Found Spy Cookie: searchingbooth cookie 1:28 PM: hp_owner@banners.searchingbooth[1].txt (ID = 3322) 1:28 PM: Found Spy Cookie: belnk cookie 1:28 PM: hp_owner@belnk[1].txt (ID = 2292) 1:28 PM: Found Spy Cookie: bigblue cookie 1:28 PM: hp_owner@BigBlue[1].txt (ID = 2302) 1:28 PM: Found Spy Cookie: enhance cookie 1:28 PM: hp_owner@c.enhance[1].txt (ID = 2614) 1:28 PM: hp_owner@dist.belnk[2].txt (ID = 2293) 1:28 PM: Found Spy Cookie: dutchmen cookie 1:28 PM: hp_owner@Dutchmen[1].txt (ID = 2545) 1:28 PM: Found Spy Cookie: exitexchange cookie 1:28 PM: hp_owner@exitexchange[1].txt (ID = 2633) 1:28 PM: Found Spy Cookie: screensavers.com cookie 1:28 PM: hp_owner@i.screensavers[2].txt (ID = 3298) 1:28 PM: Found Spy Cookie: webtrends cookie 1:28 PM: hp_owner@m.webtrends[1].txt (ID = 3669) 1:28 PM: Found Spy Cookie: top-banners cookie 1:28 PM: hp_owner@media.top-banners[1].txt (ID = 3548) 1:28 PM: Found Spy Cookie: realmedia cookie 1:28 PM: hp_owner@network.realmedia[1].txt (ID = 3236) 1:28 PM: Found Spy Cookie: 2o7.net cookie 1:28 PM: hp_owner@partygaming.122.2o7[1].txt (ID = 1958) 1:28 PM: Found Spy Cookie: popuptraffic cookie 1:28 PM: hp_owner@popuptraffic[1].txt (ID = 3163) 1:28 PM: hp_owner@realmedia[1].txt (ID = 3235) 1:28 PM: Found Spy Cookie: adjuggler cookie 1:28 PM: hp_owner@rotator.adjuggler[2].txt (ID = 2071) 1:28 PM: Found Spy Cookie: coolsavings cookie 1:28 PM: hp_owner@sav.coolsavings[1].txt (ID = 2466) 1:28 PM: hp_owner@searchingbooth[1].txt (ID = 3321) 1:28 PM: Found Spy Cookie: reliablestats cookie 1:28 PM: hp_owner@stats1.reliablestats[1].txt (ID = 3254) 1:28 PM: hp_owner@tacoda[1].txt (ID = 6444) 1:28 PM: Found Spy Cookie: trb.com cookie 1:28 PM: hp_owner@trb[1].txt (ID = 3587) 1:28 PM: Found Spy Cookie: videodome cookie 1:28 PM: hp_owner@videodome[1].txt (ID = 3638) 1:28 PM: Found Spy Cookie: burstbeacon cookie 1:28 PM: hp_owner@www.burstbeacon[2].txt (ID = 2335) 1:28 PM: hp_owner@yieldmanager[1].txt (ID = 3749) 1:28 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01 1:28 PM: Starting File Sweep 1:33 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 1:33 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 1:33 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 1:33 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 1:34 PM: The Spy Communication shield has blocked access to: banners.pennyweb.com 1:34 PM: The Spy Communication shield has blocked access to: banners.pennyweb.com 1:34 PM: The Spy Communication shield has blocked access to: banners.pennyweb.com 1:34 PM: The Spy Communication shield has blocked access to: banners.pennyweb.com 1:42 PM: The Spy Communication shield has blocked access to: paypopup.com 1:42 PM: The Spy Communication shield has blocked access to: paypopup.com 1:42 PM: The Spy Communication shield has blocked access to: paypopup.com 1:42 PM: The Spy Communication shield has blocked access to: paypopup.com 1:43 PM: The Spy Communication shield has blocked access to: paypopup.com 1:43 PM: The Spy Communication shield has blocked access to: paypopup.com 1:43 PM: The Spy Communication shield has blocked access to: paypopup.com 1:43 PM: The Spy Communication shield has blocked access to: paypopup.com 1:45 PM: The Spy Communication shield has blocked access to: paypopup.com 1:45 PM: The Spy Communication shield has blocked access to: paypopup.com 1:45 PM: The Spy Communication shield has blocked access to: paypopup.com 1:45 PM: The Spy Communication shield has blocked access to: paypopup.com 1:48 PM: The Spy Communication shield has blocked access to: paypopup.com 1:48 PM: The Spy Communication shield has blocked access to: paypopup.com 1:48 PM: The Spy Communication shield has blocked access to: paypopup.com 1:48 PM: The Spy Communication shield has blocked access to: paypopup.com 1:48 PM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com 1:48 PM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com 1:48 PM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com 1:48 PM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com 1:50 PM: The Spy Communication shield has blocked access to: paypopup.com 1:50 PM: The Spy Communication shield has blocked access to: paypopup.com 1:50 PM: The Spy Communication shield has blocked access to: paypopup.com 1:50 PM: The Spy Communication shield has blocked access to: paypopup.com 1:54 PM: The Spy Communication shield has blocked access to: paypopup.com 1:54 PM: The Spy Communication shield has blocked access to: paypopup.com 1:54 PM: The Spy Communication shield has blocked access to: paypopup.com 1:54 PM: The Spy Communication shield has blocked access to: paypopup.com 1:55 PM: The Spy Communication shield has blocked access to: paypopup.com 1:55 PM: The Spy Communication shield has blocked access to: paypopup.com 1:55 PM: The Spy Communication shield has blocked access to: paypopup.com 1:55 PM: The Spy Communication shield has blocked access to: paypopup.com 1:58 PM: The Spy Communication shield has blocked access to: paypopup.com 1:58 PM: The Spy Communication shield has blocked access to: paypopup.com 1:58 PM: File Sweep Complete, Elapsed Time: 00:30:44 1:58 PM: Full Sweep has completed. Elapsed time 00:34:37 1:58 PM: Traces Found: 37 1:58 PM: The Spy Communication shield has blocked access to: paypopup.com 1:58 PM: The Spy Communication shield has blocked access to: paypopup.com 2:18 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 2:18 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 2:18 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 2:18 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 2:20 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 2:20 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 2:20 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 2:20 PM: The Spy Communication shield has blocked access to: count.exitexchange.com 2:31 PM: The Spy Communication shield has blocked access to: paypopup.com 2:31 PM: The Spy Communication shield has blocked access to: paypopup.com 2:31 PM: The Spy Communication shield has blocked access to: paypopup.com 2:31 PM: The Spy Communication shield has blocked access to: paypopup.com 2:33 PM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com 2:33 PM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com 2:33 PM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com 2:33 PM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com 2:44 PM: The Spy Communication shield has blocked access to: paypopup.com 2:44 PM: The Spy Communication shield has blocked access to: paypopup.com 2:44 PM: The Spy Communication shield has blocked access to: paypopup.com 2:44 PM: The Spy Communication shield has blocked access to: paypopup.com 2:45 PM: The Spy Communication shield has blocked access to: paypopup.com 2:45 PM: The Spy Communication shield has blocked access to: paypopup.com 2:45 PM: The Spy Communication shield has blocked access to: paypopup.com 2:45 PM: The Spy Communication shield has blocked access to: paypopup.com 2:48 PM: Removal process initiated 2:48 PM: Quarantining All Traces: 2o7.net cookie 2:48 PM: Quarantining All Traces: 50881381 cookie 2:48 PM: Quarantining All Traces: adecn cookie 2:48 PM: Quarantining All Traces: adjuggler cookie 2:48 PM: Quarantining All Traces: adknowledge cookie 2:48 PM: Quarantining All Traces: adprofile cookie 2:48 PM: Quarantining All Traces: aff01511 cookie 2:48 PM: Quarantining All Traces: aff506 cookie 2:48 PM: Quarantining All Traces: aff6007 cookie 2:48 PM: Quarantining All Traces: belnk cookie 2:48 PM: Quarantining All Traces: bigblue cookie 2:48 PM: Quarantining All Traces: burstbeacon cookie 2:48 PM: Quarantining All Traces: coolsavings cookie 2:48 PM: Quarantining All Traces: dutchmen cookie 2:48 PM: Quarantining All Traces: enhance cookie 2:48 PM: Quarantining All Traces: exitexchange cookie 2:48 PM: Quarantining All Traces: hbmediapro cookie 2:48 PM: Quarantining All Traces: hotbar cookie 2:48 PM: Quarantining All Traces: popuptraffic cookie 2:48 PM: Quarantining All Traces: realmedia cookie 2:48 PM: Quarantining All Traces: reliablestats cookie 2:48 PM: Quarantining All Traces: screensavers.com cookie 2:48 PM: Quarantining All Traces: searchingbooth cookie 2:48 PM: Quarantining All Traces: specificclick.com cookie 2:48 PM: Quarantining All Traces: tacoda cookie 2:48 PM: Quarantining All Traces: top-banners cookie 2:48 PM: Quarantining All Traces: trb.com cookie 2:48 PM: Quarantining All Traces: videodome cookie 2:48 PM: Quarantining All Traces: websponsors cookie 2:48 PM: Quarantining All Traces: webtrends cookie 2:48 PM: Quarantining All Traces: yieldmanager cookie 2:48 PM: Removal process completed. Elapsed time 00:00:13 ******** 1:23 PM: | Start of Session, Friday, June 02, 2006 | 1:23 PM: Spy Sweeper started 1:23 PM: Your spyware definitions have been updated. 1:24 PM: The Spy Communication shield has blocked access to: paypopup.com 1:24 PM: The Spy Communication shield has blocked access to: paypopup.com 1:24 PM: | End of Session, Friday, June 02, 2006 | Ewido: --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 3:36:55 PM, 6/2/2006 + Report-Checksum: 692DD945 + Scan result: C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@banners.searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@com[1].txt -> TrackingCookie.Com : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@media.top-banners[1].txt -> TrackingCookie.Top-banners : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup C:\Documents and Settings\HP_Owner\Cookies\hp_owner@www.adtrak[1].txt -> TrackingCookie.Adtrak : Cleaned with backup ::Report End

#21 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 02 June 2006 - 02:05 PM

Hello Christian, Looks like SpySweeper and ewido cleaned up a few things. The Spy Communication shield has blocked access to: paypopup.com, etc. Did you install the google pop-up blocker? Also in the recommendations above about the installation of SpywareBlaster-- paypopup.com is one of the sites that is blocked. So be sure to install the SpywareBlaster. Please do the above and let me know if you continue to have problems.
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#22 Christian

Christian

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 02 June 2006 - 10:05 PM

that seems to be working! thanks!

#23 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 03 June 2006 - 12:32 AM

You are welcome! :) Glad it is helping!
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

#24 Susan528

Susan528

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 3,194 posts

Posted 05 June 2006 - 07:55 AM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
Posted Image

Proud member of ASAP since 2005

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Come join us in the Class Room and learn how.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users