Home > Pop Ups > Pop Ups - WinAntiVirusPro And Others - HELP PLEASE

Pop Ups - WinAntiVirusPro And Others - HELP PLEASE

Want to help others? Yes, my password is: Forgot your password? Microsoft Corporation 12/7/1999 8:00:00 AM 67344 C:\WINNT\SYSTEM32\access.cpl Microsoft Corporation 6/19/2003 3:05:04 PM 301328 C:\WINNT\SYSTEM32\appwiz.cpl Microsoft Corporation 6/19/2003 3:05:04 PM 237328 C:\WINNT\SYSTEM32\DESK.CPL Microsoft Corporation 12/7/1999 8:00:00 AM 31504 C:\WINNT\SYSTEM32\fax.cpl Microsoft Corporation 12/7/1999 Click here to Register a free account now!

This applies only to the original topic starter.   Everyone else please begin a New Topic. Done! *************************************************** HJT *************************************************** Logfile of HijackThis v1.99.1 Scan saved at 1:10:59 AM, on 10/26/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe link In the Privacy section, click Content settings Click All cookies and site data... No, create an account now.

Help. Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List Toolbar : {47833539-D0C5-4125-9FA8-0819E2EAAC93} = Adobe PDF : C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Synchronization Manager mobsync.exe /logon zBrowser Launcher C:\Program Files\Logitech\iTouch\iTouch.exe EM_EXEC C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE projselector "C:\Program Files\Common Files\Roxio Shared\Project Selector\projselector.exe" -r RoxioEngineUtility "C:\Program Files\Common It only appears when I use IE and when it appears is real random.

Pool 2 - http://download.game...ts/y/potf_x.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=48835O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.micr...ActiveX/odc.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Register now! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options Short URL to this thread: https://techguy.org/480871 Log in with Facebook Log in with Twitter Log in with Google Your name or email address: Do you already have an account?

It will ask for confimation to delete the file. It was running well yesterday and now starting to get sporadic pop ups. Attempting to delete C:\WINDOWS\system32\cdeeg.ini C:\WINDOWS\system32\cdeeg.ini Has been deleted! http://www.bleepingcomputer.com/forums/t/69570/winantivirus-pro-and-other-pop-ups/ Olivier Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs 1 user(s) are reading this topic 0 members, 1 guests, 0 anonymous users Reply to quoted postsClear

Sign Up This Topic All Content This Topic This Forum Advanced Search Browse Forums Calendar Staff Online Users More Activity All Activity Search More More More All Activity Home Spyware, thiefware, We apologize for the delay; our helpers have been very busy. Olivier Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs 1 user(s) are reading this topic 0 members, 1 guests, 0 anonymous users Reply to quoted postsClear It will ask if you want to reboot now, Click Yes.

cybertech, Jul 6, 2006 #8 jjjz Thread Starter Joined: Jul 6, 2006 Messages: 13 That did not get rid of the error. https://forums.whatthetech.com/index.php?showtopic=67685 So i spent the $25 usa to activate. Post a new HiJackThis log after the reboot and let me know if the pop ups are still coming. Words cannot express how appreciative I am.

I scanned the whole computer, deleted all the files and I went through the regisitry deleting suspicious stuff and ran HiJackThis and killed maybe 2 programs. Under What to Sweep, check every box. This site is completely free -- paid for by advertisers and donations. Most of them are Win AntiVirus Pro 2006, but occasionally I get one advertising that it "Pays 2 Shop" and my favorite is a blank screen with the address something like:

  1. Fabril replied Feb 22, 2017 at 3:20 AM Making a phone call on my computer lebronhuo replied Feb 22, 2017 at 3:08 AM Search function very slow/not...
  2. Please continue replying here.
  3. O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe O8 - Extra context menu item: &Google
  4. Instead, open a new thread in our Security and the Web forum.
  5. C:\WINDOWS\SYSTEM32\DVDOS Back to top #4 stonangel stonangel Members 595 posts OFFLINE Location:France Local time:11:49 AM Posted 31 October 2006 - 03:54 AM Hi luismr74, Could you post back the entire
  6. Let me know what you think.
  7. Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately.

All Rights Reserved. They done what they said they would on there web site in under the time frame.Source Administrator of Horse Racing Forums WINANTIVIRUSPRO.COM Cookie How to Remove WINANTIVIRUSPRO.COM Cookie from Your Computer Checking %WinDir% folder... Look in your control panel add/remove programs for PuritySCAN By OIN, OuterInfo, Snowballwars by OIN or similar , click on it and click remove.

Then press the OK button. Go to the WinPFind folder Locate WinPFind.txt Copy and paste WinPFind.txt in your next post here please. If you decide to clean your system after reading the above thread, do the following.

A confirmation dialog box will be shown before clearing the information.* Clean other Temporary files + Recycle bin Go to start > run and type: cleanmgr and click ok.

Please download Brute Force Uninstaller to your desktop.Right click the BFU folder on your desktop, and choose Extract AllClick "Next"In the box to choose where to extract the files to,Click "Browse"Click The files will contain the Cookie: winantiviruspro.com element. Older versions have vulnerabilities that malware can use to infect your system. Olivier Back to top #13 stonangel stonangel Members 595 posts OFFLINE Location:France Local time:11:49 AM Posted 04 November 2006 - 12:34 PM Since this issue appears resolved ...

Save it in the same folder you made earlier (c:\BFU).Do not do anything with these yet!Reboot your computer into Safe Mode. Performing Repairs to the registry. When the sweep has finished, click Remove. Check Local Disc C.

Sign in to follow this Followers 0 Go To Topic Listing Resolved or inactive Malware Removal All Activity Home Spyware, thiefware, browser hijackers, and other advertising parasites Malware Removal Resolved or cybertech, Jul 6, 2006 #6 jjjz Thread Starter Joined: Jul 6, 2006 Messages: 13 The error is: HijackThis:HijackThis.exe - Application Error (modal box) The instruction at "0x018a08c3" referrenced memory at "0x000000000". Include the address of this thread in your request. All rights reserved.

Please navigate to your HijackThis folder. Here's my hijackthis log. Consult with a knowledgable person before proceeding. Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod

I'll be leaving at 10 pm to go to work and also have class in the morning right after work, so I won't be home again until 2pm tomorrow. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover. Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cabO16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cabO16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - Winantivirus Pro Virus/ Other Pop-ups Started by luismr74 , Oct 30 2006 02:39 AM This topic is locked 12 replies to this topic #1 luismr74 luismr74 Members 10 posts OFFLINE

If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.   Thank you for your My antivirus keeps coming up with a virus that it will not quarantine, delete, or clean. Click Select All and then Next From 'Results', select the Session Log tab. Reboot into Safe Mode.

The Per site privacy actions window will be displayed In the Per site privacy actions window, enter winantiviruspro.com in the Address of Web site field Click Block To block winantiviruspro.com cookie Cookiegal, Jul 7, 2006 #14 jjjz Thread Starter Joined: Jul 6, 2006 Messages: 13 WARNING: not all files found by this scanner are bad.