Thread: i hate pop ups
View Single Post
  #2  
Old 10-18-2004, 10:21 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Re: i hate pop ups

Im not much for popups as well to be honest with you..

Rescan and check these then close all browser windows and click "fix checked"



R1 - HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://searchbar.findthewebsiteyouneed.com/

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://searchbar.findthewebsiteyouneed.com

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://searchbar.findthewebsiteyouneed.com

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.findthewebsiteyouneed.com

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://search.media-search.net/nph-search....ok=stmpl1&find=

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,SearchAssistant = http://searchbar.findthewebsiteyouneed.com/

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://searchbar.findthewebsiteyouneed.com

R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://search.media-search.net/nph-search....ok=stmpl1&find=

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://searchbar.findthewebsiteyouneed.com

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=

R1 - HKLMSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = hhttp://search.media-search.net/nph-search.cgi?track=mssrc&look=stmpl1&find=

R3 - URLSearchHook: (no name) - {9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)

R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)

O1 - Hosts: 80.69.74.15 auto.search.msn.com

O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:WINDOWSmxTarget.dll

O2 - BHO: (no name) - {00041A26-7033-432C-94C7-6371DE343822} - (no file)

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:Program FilesMyWebSearchSrchAstt1.binMWSSRCAS.DLL

O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:WINDOWSsystb.dll

O2 - BHO: Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} - C:Program FilesRecommended Hotfix - 421701Dv15RH.DLL

O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:Program FilesMyWebSearchbar1.binMWSBAR.DLL

O2 - BHO: Setup.Setup1 - {2E65A557-173C-4DE9-860B-28FC5CACA542} - COCUME~1ALLUSE~1APPLIC~1SetupSetup.dll

O2 - BHO: CATLEvents Object - {60112085-E1CE-4e0e-823A-EBB1AD98804C} - COCUME~1JennaLOCALS~1Temprbarc.dat

O3 - Toolbar: &My Way Speedbar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:Program FilesMyWaymyBar1.binMYBAR.DLL

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:Program FilesMyWebSearchbar1.binMWSBAR.DLL

O4 - HKLM..Run: [HPGamesActiveMenu] C:Program FilesWildTangentActiveMenuHPGamesActiveMenu.exe

O4 - HKLM..Run: [PromulGate] "C:Program FilesDelFinPromulGatePgMonitr.exe"

O4 - HKLM..Run: [MediaLoads Installer] "C:Program FilesDownloadWaredw.exe" /H

O4 - HKLM..Run: [WT GameChannel] C:Program FilesWildTangentAppsGameChannel.exe

O4 - HKLM..Run: [redirect] C:windowsredirect9a.exe

O4 - HKLM..Run: [easywww] C:windowseasywww2.exe

O4 - HKLM..Run: [P2P Networking] C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART

O4 - HKLM..Run: [updater] C:Program FilesCommon filesupdaterwupdater.exe

O4 - HKLM..Run: [SAHAgent] C:WINDOWSSystem32SahAgent.exe

O4 - HKLM..Run: [msbb] C:WINDOWSSystem32msbb.exe

O4 - HKLM..Run: [Belt] C:WINDOWSBelt.exe

O4 - HKLM..Run: [FLSVCCWEL] C:WINDOWSFLSVCCWEL.exe

O4 - HKLM..Run: [Media-Search] "C:Program Filesmsnetv9msnet.EXE" /H

O4 - HKLM..Run: [ViewMgr] C:Program FilesViewpointViewpoint ManagerViewMgr.exe

O4 - HKLM..Run: [Search-Exe] "C:Program Filessev11se.EXE" /H

O4 - HKLM..Run: [Win Server Updt] C:WINDOWSwupdt.exe

O4 - HKLM..Run: [New.net Startup] rundll32 ,NewDotNetStartup -s

O4 - HKLM..Run: [prpzjtxyepga] C:WINDOWSSystem32jrokvj.exe

O4 - HKLM..Run: [crabr] C:WINDOWSFontscrabr.exe

O4 - HKLM..Run: [MyWebSearch Email Plugin] C:PROGRA~1MYWEBS~1bar1.binmwsoemon.exe

O4 - HKLM..Run: [WildTangent CDA] RUNDLL32.exe "C:Program FilesWildTangentAppsCDAcdaEngine0400.dll",cdaEngin eMain

O4 - HKLM..Run: [WebRebates0] "C:Program FilesWeb_RebatesWebRebates0.exe"

O4 - HKCU..Run: [eZmmod] C:PROGRA~1ezulammod.exe

O4 - HKCU..Run: [MyWebSearch Email Plugin] C:PROGRA~1MYWEBS~1bar1.binmwsoemon.exe

O4 - Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchbar1.binMWSOEMON.EXE

O4 - Global Startup: hp center UI.lnk = C:Program Fileshp center137903ShadowShadowBar.exe

O4 - Global Startup: hp center.lnk = C:Program Fileshp center137903ProgramBackWeb-137903.exe

O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchbar1.binMWSOEMON.EXE

O8 - Extra context menu item: Web Rebates - file://C:Program FilesWeb_RebatesSy1150Tp1150scri1150a.htm

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:WINDOWSSystem32Shdocvw.dll

O10 - Hijacked Internet access by New.Net

O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/D...MO1/r3un10n.cab

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

O16 - DPF: {79B96C72-C0D0-4DC8-BC7E-9F314A918228} - http://imgfarm.com/images/nocache/myspeedb...etup1.0.0.3.cab

O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab

O16 - DPF: {DCF0768D-BA7A-101A-B57A-0000C0C3ED5F} - file://C:x.cab



Then reboot into safe mode, open windows explorer, find then delete:
C:Program FilesWeb_Rebates
C:Program FilesMyWebSearch
COCUME~1ALLUSE~1
C:Program FilesMyWay
C:Program FilesWildTangent
C:windowsredirect9a.exe
C:windowseasywww2.exe
C:WINDOWSSystem32P2P Networking
C:WINDOWSSystem32SahAgent.exe
C:WINDOWSSystem32msbb.exe
C:WINDOWSBelt.exe
C:WINDOWSFLSVCCWEL.exe
C:Program Filesmsnetv9msnet.EXE" /H
C:Program FilesViewpoint
C:Program Filesse
C:WINDOWSwupdt.exe
C:WINDOWSSystem32jrokvj.exe
C:WINDOWSFontscrabr.exe
C:PROGRA~1ezula


Reboot ownload Adaware Se from http://www.lavasoftusa.com/support/download/
In Ad-aware click the Gear to go to the Settings area.
The following items should be on a green check, not on a red X.
Under the Scanning button:Scan within archives
Under Memory & Registry, Check EVERYTHING
In Check Drives & Folders, make sure all of your hard drives are selected
Under the Advanced button, Check
Move deleted files to recycle bin
Include additional object information
Include negligible object information
Include environment information
Under the defaults button Set the homepage you wish to have set as default.
Under the tweak button
Some of these may not be an available option, depending on your version of Ad-aware and your version of Windows. Do not be concerned if you cannot select a certain item.

In Scanning Engine:Unload recognized processes during scanning
Include info about ignored objects in logfile, if detected in scan
Include basic Ad-aware settings in logfile
Include additional Ad-aware settings in logfile
Include used command line parameters in logfile
In Cleaning Engine: XP/2000: Allow unloading explorer to unload shell extensions prior to deletion
Let Windows remove files in use at next reboot
UNCHECK: Automatically try to unregister objects prior to deletion
Click Proceed to save these settings. When you would like to perform a "Full Scan," switch the scan mode from SmartScan to Custom
__________________________________________________ _____________
Rescan with hijack and post a fresh log please.
Reply With Quote