AnimeSuki Forums

Register Forum Rules FAQ Community Today's Posts Search

Go Back   AnimeSuki Forum > Support > Tech Support

Notices

Reply
 
Thread Tools
Old 2007-07-09, 01:19   Link #1
Suzumiya Haruhi
Destroying the balance
 
 
Join Date: Jul 2006
Location: 西宮市... Okay, California. ;P
Exclamation Adware problems

So, this bastard "Outerinfo" keeps installing itself onto my computer. I've full-scanned my computer with Ad-Aware and I wiped out all the known infections, but I'm still getting popups from Outerinfo which is pretty annoying.

Oh, and look at this, while I made this post, I checked "Add/remove" programs and I see this "Winpop" thing. -.-

So... any suggestions on removing them? I've pretty much scanned my computer a dozen times... If it helps, I pretty much get these things after I visit sites like DaTorrents and Hongfire.
__________________

The Otaku Spot - My anime & manga reviews, musings, and pointless rants...
Suzumiya Haruhi is offline   Reply With Quote
Old 2007-07-09, 02:08   Link #2
Gundam Master
Senior Member
 
 
Join Date: Nov 2003
Location: Honolulu, Hawaii
Send a message via AIM to Gundam Master
did you check to see if it was an installed program and try to remove it?
Another thing that might help is to install spybot search and destroy. Ada-aware and spybot work great together.
Gundam Master is offline   Reply With Quote
Old 2007-07-09, 09:18   Link #3
grey_moon
Yummy, sweet and unyuu!!!
 
 
Join Date: Dec 2004
U might want to manually download the dat files for the above programs and then boot to safe mode before updating and running a scan.

Safe mode is press F8 when the PC boots to bring up a menu.

To be even more anal u do all the checks when the message pops up saying that you are in safe mode, instead of okaying it, you call up task manager (ctrl + shit + esc) and then run the checks from File, New Task.
__________________
grey_moon is offline   Reply With Quote
Old 2007-07-09, 09:46   Link #4
demonix
Senior Member
 
 
Join Date: Jul 2006
Location: Hayes, Middx UK
Age: 44
Send a message via Yahoo to demonix
You might want to do a scan with hijack this and post the log somewhere like the beeping computer or lavasoft forums where they might be able to help you out with getting this sorted.
demonix is offline   Reply With Quote
Old 2007-07-09, 13:30   Link #5
Suzumiya Haruhi
Destroying the balance
 
 
Join Date: Jul 2006
Location: 西宮市... Okay, California. ;P
Quote:
Originally Posted by Gundam
did you check to see if it was an installed program and try to remove it?
The Winpop thing, yes. Outerinfo, no. Only because I had problems trying to remove it in the past. It seemed to disappear from the programs list though, even though the program was still active.

Alright, I did what Gundam Master suggested and scanned my PC with Spybot and Ad-Aware and the problem seemed to have lifted. Didn't even need to boot to Safe Mode too.

Thanks to all of you for the help... Uh, if it occurs again later today I might post in this thread. :s
__________________

The Otaku Spot - My anime & manga reviews, musings, and pointless rants...
Suzumiya Haruhi is offline   Reply With Quote
Old 2007-07-09, 14:10   Link #6
arcadeplayer987
Senior Member
 
Join Date: Apr 2007
Quote:
Originally Posted by Gundam Master View Post
did you check to see if it was an installed program and try to remove it?
Another thing that might help is to install spybot search and destroy. Ada-aware and spybot work great together.
I agee with that one Spybot is great for adware and malware
arcadeplayer987 is offline   Reply With Quote
Old 2007-07-09, 14:55   Link #7
Claies
Good-Natured Asshole.
 
 
Join Date: May 2007
Age: 34
Get Spybot, and make sure it's updated. Disconnect from the internet (as in physically yanking the cable off).

Use HijackThis to find it, narrow it down with Spybot, go in Safe Mode, and delete it. Before you leave Safe Mode, use the Immunize feature with Spybot to get an extra layer of protection.

Best of luck!
Claies is offline   Reply With Quote
Old 2007-07-14, 12:16   Link #8
mist2123
Banned
 
 
Join Date: Jun 2006
Location: M.U
Send a message via AIM to mist2123
just get hitman pro with mcaffe total protection 2007 if not do a hijack scan. also try using combofix

* Please open hijackthis and put a check next to the following:

R3 - URLSearchHook: (no name) - {C3667E64-ECD4-CF27-D058-BE3EB72672C4} - (no file)
R3 - URLSearchHook: (no name) - {972F774B-EEA3-9C0B-F4FF-E43BF70222C6} - (no file)
R3 - URLSearchHook: (no name) - {A09B63F3-F619-8BE4-16F3-F15A113C1793} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Internet Explorer Web Content Guard - {1B77D30A-81C9-497A-8647-142F7511B1FB} - (no file)
O2 - BHO: (no name) - {972F774B-EEA3-9C0B-F4FF-E43BF70222C6} - (no file)
O2 - BHO: (no name) - {A09B63F3-F619-8BE4-16F3-F15A113C1793} - (no file)
O2 - BHO: (no name) - {C3667E64-ECD4-CF27-D058-BE3EB72672C4} - (no file)
O2 - BHO: (no name) - {F7596B6A-A686-8024-D3ED-A00FD4914EC6} - (no file)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [00kk03qo.dll] RUNDLL32.EXE 00kk03qo.dll,b 117763343
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000166.exe
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O4 - HKCU\..\Run: [mqui] C:\PROGRA~1\COMMON~1\mqui\mquim.exe
O4 - HKCU\..\Run: [Scbu] "C:\WINDOWS\system32\DOBE~1\chkdsk.exe" -vt yazr
O4 - HKCU\..\Run: [Prmhoyk] C:\WINDOWS\system32\??rss.exe

* After you check the items you want to fix, close all browsers and windows, except for HijackThis, then click on the Fix Checked button on HijackThis.

* Next, please reboot your computer in Safe Mode by doing the following:
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
Instead of Windows loading as normal, a menu should appear
Select the first option, to run Windows in Safe Mode.

* Please delete these files/folders using Windows Explorer(if present):
* Click Start>>All Programs>>Accessories>>Windows Explorer
* Navigate to the listed files/folders, then right-click to select them and click delete
ALCMTR.EXE
C:\Program Files\Common Files\Windows\mc-110-12-0000166.exe
C:\Program Files\Common Files\VCClient <== this folder
C:\PROGRAM FILES\COMMON FILES\mqui <== this folder
C:\WINDOWS\system32\DOBE~1\chkdsk.exe

* boot back into normal mode

* Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

* Copy everything inside the quote box below (starting with dir) and paste it into notepad. Go up to "File > Save As" and click the drop-down box to change the "Save As Type" to "All Files". Save it as findfile.bat on your Desktop.


QUOTE
dir C:\WINDOWS\system32\??rss.exe /a h > files.txt
notepad files.txt


Locate findfile.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the contents of that Notepad here along with a new HiJackThis log.
mist2123 is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 19:26.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
We use Silk.