1.

Solve : Help - I let the ad ware in and it is taking over!?

Answer»

Hi, I've read your instructions to give as much detail as possible. STILL, I am sorry that I am so wordy. I've attached the 3 required text files.

I've been having problems with viruses and spyware lately. My McAfee alerts have been going crazy and I have been having troubles with videos not staying in full screen and getting kicked out of Internet Explorer after having it opened for just a few minutes. Lots of pop up ad. Plus I have even got voice adware. That was weird. I wasn't even near the computer and it starts talking. I looked in the task manager and nothing was running - really spooky. I think they keep the ads really short so they are harder to track.

I must admit I do know when and probably why it got this bad. On 8/12 I found a website - TVOKAY - that I could watch the first season of a particular TV series but I had to agree to let Zango ads in to use the TVokay WEB site. I did it - dumb, dumb, dumb!! On 8/20 I finished watching that first season and tried to delete Zango. It allowed me to delete its .exe file and its folder out of the Programs file but as McAfee continues to remind me, it wasn't really gone and it had apparently brought a lot of it's playmates to explore and play inside my computer also. (another confession - before I started tracking down "watch free TV shows" I also used to bounce AROUND the web gathering free hours of game play - probably letting in all sorts of viruses, worms, trojans and other malware until I got bored play the games.)

As soon as I removed (haha!) Zango I started tighten down the security features on IE and on McAfee. I did find that using FireFox was better than IE because it wasn't closing down on me. Then after doing all your steps, today for the first time in weeks, I have been on the computer for about 6 hrs and have not had a single McAfee alert. Maybe these viruses like to kick in during the EVENING high usage hours, instead of the daytime. I know some of them are not completely gone because I find them when I do MS Explorer searches.

One thing that McAfee hasn't been able to grab is a kYyW80uN.exe.a_a file. McAfee was at first grabbing the file under Temp\kYyW80uN.exe and then it started grabbing it under System32\KyyW80uN.exe but it couldn't seem to acknowledge that other file with the a_a extension. When I did the CCleaner I let it analysis my registry and it had grabbed that file extension so I went ahead and let CCleaner clean my registry. (I know your instructions said not to but I did it anyway. Why is it so hard to follow instructions exactly?) But since then I have seen the file on the Malwarebytes log.

Also this week I have been having problems logging in to the computer. I don't know if it is related to viruses or not. If I do a restart, it will usually work and if I do a power off and then turn it right back on, it will start; but if I turn off the computer overnight then the next morning I only get a black screen (with a faint background flickering) on the monitor with everything else (laser on mouse, light on speaker, computer case lights and sounds) seeming to be coming up okay. After turning the computer on and off about 4 or 5 times, it will come on (at least so far). I think it seems to come on usually after I pull the main surge suppressor power plug which pulls down all the peripherals also and leave it off for awhile then power it up. I kind of think this might have something to do with the internet always-on accessibility and the viruses or maybe I have hardware (motherboard??) problems too.

Recent hardware changes:
1. In May my power supply fried with lots of fireworks and was replaced - same wattage - 600.

2. Last month when I started having the videos not staying in full screen problems I was told I probably needed to replace my graphic drivers, with the first step being removing the old drivers. Got the black screen after the removal and could not get in to download the new drivers so after some in-the-case testing with a phone tech it was decided that I needed to replace both my 256 mb graphic cards. I got one 516 mb card to replace them.

My system: AMD Athlon 64 X2 Dual Core Processor 4600+, ViewSonic VX922 monitor, Asus A8N32-SLI Deluxe nForce4 motherboard, PNY NVidia GEForce 8800 GT 516 mb graphics card, 2GB memory, 250GB x2 hard drives, Creative Labs SB Audigy 4 SE sound system, Cooler Master Extreme Power Supply 600 watt, Windows XP Media Center 2005

Thanks a lot for whatever help you can give me and again I am sorry that I am so wordy and this is so long.

K


[recovering disk space -- attachment deleted by admin]Welcome to CH.

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe

Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Now go to Add or Remove Programs and uninstall Boonty Games.

You went over the problems you were having, are there any you are still noticing? The log looks clean but that doesn't always indicate everything is actually gone.Thanks for getting back to me. I did what you said but the Boonty file was not in Add or Remove Programs, so I checked back into HijackThis and it is gone from there. Next I checked in MS Explorer under Program Files and it is still sitting there.

Nothing else has been showing up - no popups or alerts. FireFox had to do a shut down once this evening but it was done with one of those apologetic messages from the service, not a sudden closing like the viruses were causing.

I don't know if my morning startup problem is gone, but Hijackthis required a restart and that worked fine.

I just did a check on one other problem area I didn't mention earlier, probably not virus related, but maybe so. I have a TV tuner card and CyberLink Power Cinema version 4.0.1725 and for the last 6 months or so the interface has been continually deteriorating. At first it started stopping in the middle of recording, then it started stopping in middle of watching live TV and now I can’t even get into the TV module without it freezing the computer and requiring a ctrl/alt/delete, although the video and music sections still works. CyberLink doesn’t seem to give free upgrades – expects one should buy their latest version instead (how quaint is that!). I haven’t tracked down the problem since I have never been sure which area has the problem – tv tuner, the CyberLink software or my tv service provider). Anyway, I just gave it a try now to see if it is still messed up and at first everything froze, then I got this full size blue screen message and had to do a hard shutdown to break out of the screen

Message:
A problem has been detected and Windows has been shut down, to prevent damage to your computer.

Machine_check_exception

If this is the first time you’ve seen this stop error screen, restart your computer. If this screen appears again, follow these steps:

Check to make sure any new hardware or software is properly installed. If this is a new installation, ask your hardware or software manufacturer for any windows updates you might need.

If problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advance Startup options, and then select Safe Mode.

Technical Information:
*** STOP: 0X0000009C (0X00000004, 0X8054D5F0, 0XB2000000, 0X00070F0F)


Do you think I might have complicated things when I ccleaner-ed my registry and dumped some component that I needed? I think I should probably pull out the CyberLink software and reinstall it if you don’t think the problem could be virus related or something I messed up with ccleaner.

K
I'm not that good with hardware problems so you might want to ask in that forum.

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it EASILY should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.Hey, thanks a lot! It feels so good to have my computer all squeaky clean and have all these new anti-virus program downloads to keep it that way.

I think I will have to head over to the hardware forum and see if they can help me as efficiently as you have. I am still having major problems getting into the computer after logging off for very long. At least now I know it isn’t virus connected. I even bought a new monitor to graphics card cable today to see if that would help, but it hasn’t. I think I just won’t shut down overnight until I get this fixed.

Secunia directed me to an Adobe Flash Player update and your last tip to go to MS Windows Updates snagged me the XP Service Pack 3 – a major update and also a new driver update for my Canon printer – great! Thanks, K


Discussion

No Comment Found