Author Topic: adaware can`t remove altnet!  (Read 24355 times)

0 Members and 1 Guest are viewing this topic.

Omar

  • Guest
adaware can`t remove altnet!
« on: October 29, 2004, 11:35:31 AM »
I am using XP home edition SP2 and adaware se 1.05,  keeps finding Altnetbde reg key, i keep removing it but it keeps showing up!

I went into the registry: HKEY_LOCAL_MACHINE: software\altnet

i tried to delete the yellow altnet folder but it said "error while deleting key"

please help me! someone:

Logfile of HijackThis v1.98.2

Scan saved at 23:33:39, on 25/10/2004

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashserv.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZONELABS\vsmon.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\SAMSUNG\SAMSUNG AHT-E310\CnxDslTb.exe

C:\Program Files\Alwil Software\Avast4\ashDisp.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe

C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe

C:\WINDOWS\system32\rundll32.exe

C:\DOCUME~1\james\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ush.net/board

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = www.ush.net

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.timecomputers.com/

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\Status.exe

O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\SAMSUNG\SAMSUNG AHT-E310\CnxDslTb.exe

O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - Global Startup: hp psc 1000 series.lnk = ?

O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html

O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html

O14 - IERESET.INF: START_PAGE_URL=http://www.timecomputers.com

O17 - HKLM\System\CCS\Services\Tcpip\..\{A860EBB1-22CD-42F1-A309-6 7ACB7E8A92D}: NameServer = 213.40.66.126 213.40.130.126

 







GYL

  • Guest
Re:adaware can`t remove altnet!
« Reply #1 on: October 29, 2004, 12:10:41 PM »
hi! try with ERASOR,you'll find it by google. tell us result please

inthewildteam

  • Guest
Re:adaware can`t remove altnet!
« Reply #2 on: October 29, 2004, 03:54:44 PM »
Manual removal instructions can be found here

http://www.pestpatrol.com/PestInfo/t/topsearch.asp

Might be useful as a double check after using Erasor

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31080
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:adaware can`t remove altnet!
« Reply #3 on: October 29, 2004, 06:20:58 PM »
This is the result of my log file analyzer.

--------------------------------------------------------------------------------
THESE ITEMS ARE HARMFULL AND SHOULD BE FIXED/REMOVED :
--------------------------------------------------------------------------------
\windows\system32\slserv.exe
\program files\msn apps\updater\01.02.3000.1001\en-gb\msnappau.exe
o4 - hklm\..\run: [supastatus] c:\program files\internet explorer\connection wizard\status.exe
o4 - hklm\..\run: [msnappau] "c:\program files\msn apps\updater\01.02.3000.1001\en-gb\msnappau.exe"

--------------------------------------------------------------------------------
THE FOLLOWING ITEMS ARE NOT NEEDED FOR THE SYSTEM TO WORK
PROPERLY. WE RECOMMEND THEM TO BE REMOVED FROM STARTUP :
--------------------------------------------------------------------------------
o4 - hkcu\..\run: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background

--------------------------------------------------------------------------------
WE HAVE NO INFO ON THE FOLLOWING ITEMS. THEY CAN BE BAD OR GOOD.
YOU HAVE TO VERIFY THEM MANUALLY. PLEASE TELL US IF YOU HAVE INFO ON THEM :
--------------------------------------------------------------------------------
o4 - hklm\..\run: [supastatus] c:\program files\internet explorer\connection wizard\status.exe

Omar

  • Guest
Re:adaware can`t remove altnet!
« Reply #4 on: October 29, 2004, 08:26:52 PM »
This is the result of my log file analyzer.

--------------------------------------------------------------------------------
THESE ITEMS ARE HARMFULL AND SHOULD BE FIXED/REMOVED :
--------------------------------------------------------------------------------
\windows\system32\slserv.exe
\program files\msn apps\updater\01.02.3000.1001\en-gb\msnappau.exe
o4 - hklm\..\run: [supastatus] c:\program files\internet explorer\connection wizard\status.exe
o4 - hklm\..\run: [msnappau] "c:\program files\msn apps\updater\01.02.3000.1001\en-gb\msnappau.exe"

--------------------------------------------------------------------------------
THE FOLLOWING ITEMS ARE NOT NEEDED FOR THE SYSTEM TO WORK
PROPERLY. WE RECOMMEND THEM TO BE REMOVED FROM STARTUP :
--------------------------------------------------------------------------------
o4 - hkcu\..\run: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background

--------------------------------------------------------------------------------
WE HAVE NO INFO ON THE FOLLOWING ITEMS. THEY CAN BE BAD OR GOOD.
YOU HAVE TO VERIFY THEM MANUALLY. PLEASE TELL US IF YOU HAVE INFO ON THEM :
--------------------------------------------------------------------------------
o4 - hklm\..\run: [supastatus] c:\program files\internet explorer\connection wizard\status.exe


is it enough to fix these entries with hijackthis? or is it necessary to remove any files as well?

also is \windows\system32\slserv.exe bad? The reason why i ask is becuase hijackthis log analyzer says the following:

"If you have SiS Drivers installed, this entry is normal. It could also mean that you have been infected by the W32/Gaobot.CR virus. Use an Antivirus to check this".

if it is bad how do i remove it?
« Last Edit: October 29, 2004, 08:36:10 PM by Omar »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31080
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:adaware can`t remove altnet!
« Reply #5 on: October 29, 2004, 08:43:08 PM »
Quote
is it enough to fix these entries with hijackthis?
Yes

Quote
if it is bad how do i remove it?
You already gave the answer yourself > "Use an Antivirus to check this"

Omar

  • Guest
Re:adaware can`t remove altnet!
« Reply #6 on: November 01, 2004, 09:23:00 AM »
Logfile of HijackThis v1.98.2
Scan saved at 23:47:32, on 31/10/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashserv.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SAMSUNG\SAMSUNG AHT-E310\CnxDslTb.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\New Folder\HijackThis19802.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ush.net/board
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = www.ush.net
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.timecomputers.com/
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SUPASTATUS] C:\Program Files\Internet Explorer\Connection Wizard\Status.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\SAMSUNG\SAMSUNG AHT-E310\CnxDslTb.exe
O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O14 - IERESET.INF: START_PAGE_URL=http://www.timecomputers.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{A860EBB1-22CD-42F1-A309-67ACB7E8A92D}: NameServer = 213.40.66.126 213.40.130.126


C:\WINDOWS\system32\slserv.exe

This was checked against a virus checker and came out clean.


However, my big problem remains, adaware keeps finding "altnet"

I went into the registry: HKEY_LOCAL_MACHINE: software\altnet

i tried to delete the yellow altnet folder but it said "error while deleting key".

 I have tried alternative spy ware programmes, like spy bot (didn`t pick up altnet). I also have used a free trial of "spy sweeper" (found altnet but couldn`t remove it)and "giant anti spyware" (didn`t fix the problem).

I am desperate for help.



Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31080
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:adaware can`t remove altnet!
« Reply #7 on: November 01, 2004, 12:44:22 PM »
Click on the link in my signature and use my HJT log analyzer and the online one. Fix the things they report as bad/nasty and reboot.

Let us know if you still have problems after doing so.

Omar

  • Guest
Re:adaware can`t remove altnet!
« Reply #8 on: November 01, 2004, 12:55:10 PM »
Click on the link in my signature and use my HJT log analyzer and the online one. Fix the things they report as bad/nasty and reboot.

Let us know if you still have problems after doing so.


i used the HJT log analyzer. The only entry that came up as nasty was:

C:\WINDOWS\system32\slserv.exe

I have checked this at http://virusscan.jotti.dhs.org/

no virus was found

i ran the online HJT but it gave a error message!
« Last Edit: November 01, 2004, 12:59:54 PM by Omar »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67195
Re:adaware can`t remove altnet!
« Reply #9 on: November 01, 2004, 01:41:17 PM »
Omar, did you try another anti spy applications such SpyBot Search & Destroy?
Spyware Blaster avoids infection of a lot of pests...  8)
Some spy cleaning tools are available in Internet and you can find on-line scanning too.
The best things in life are free.

Omar

  • Guest
Re:adaware can`t remove altnet!
« Reply #10 on: November 01, 2004, 03:33:36 PM »
Omar, did you try another anti spy applications such SpyBot Search & Destroy?
Spyware Blaster avoids infection of a lot of pests...  8)
Some spy cleaning tools are available in Internet and you can find on-line scanning too.

i tried spy bot, that didn`t find altnet.

I tried "spy sweeper" it found altnet but didn`t delete it.


Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48523
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re:adaware can`t remove altnet!
« Reply #11 on: November 02, 2004, 12:53:03 AM »
Omar
Take a look HERE and see if that helps you.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Omar

  • Guest
Re:adaware can`t remove altnet!
« Reply #12 on: November 02, 2004, 12:55:38 AM »
Omar
Take a look HERE and see if that helps you.

i have seen that already, i`m not confident, to delete all those!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48523
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re:adaware can`t remove altnet!
« Reply #13 on: November 02, 2004, 01:12:43 AM »
Omar
Remember, Altnet isn't one program. It's an invasion.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Omar

  • Guest
Re:adaware can`t remove altnet!
« Reply #14 on: November 02, 2004, 08:53:23 AM »
Omar
Remember, Altnet isn't one program. It's an invasion.

i would prefer if there was a programme i could use that did the cleaning or pehaps something that would allow me to delete altnet on reboot, otherwise i may end up having to delete all those things