zipzappromos

R

Retselal

The site www.zipzappromos.com keeps poping up and I can't
stop it.
I've run antispyware,spysweeper and ad-aware with noluck.
Sometimes magic control and mc and mc||sa are in the
registry. I've rmoved then and run scans in safe mode and
with restore off.
ther seems ti be a 'hitbox' label in front af cookie
addresses found in temp internet at owner.
Any ideas?
 
A

Andre Da Costa

Have you checked in Add/Remove Programs to see if there are any installers
relating to that particular spyware program? Also, click start > run > type
in msconfig > startup tab > under startup items, check to see if its there,
uncheck and restart the system.

Or this:
Save this to text where you can access it in safe mode.

Download Pocket Killbox from here:
http://www.downloads.subratam.org/KillBox.zip

Unzip the files to a folder, then open and double-click on Killbox.exe to
run it. In the "Paste Full Path of File to Delete" box, copy and paste the
following:

C:\WINDOWS\System32\qjpcbtsnx.exe

Check the box to delete on reboot and click the red X to the right. Click
OK, then NO to reboot now. Copy the next filepath and paste it in the box,
and repeat the above steps. When all of the below filepaths are done, close
the Killbox.

C:\WINDOWS\Downlo~1\EGDACCESS.inf
C:\WINDOWS\system32\EGDACCESS_1057.dll



Download and install Reglite.


Scan again with HijackThis and place a check next to the following entries.
Close ALL other windows and click fix.

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKCU\..\Run: [Instant Access] rundll32.exe
EGDACCESS_1057.dll,InstantAccess
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocach...up1.0.0.8-2.cab
O16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} -
http://akamai.downloadv3.com/binari...ESS_1057_XP.cab


Right click My Computer and choose properties. On system restore tab, check
the box to turn off. OK out.

Go to start>run and type msconfig, hit enter. On the boot.ini tab, check the
box next to /safeboot and OK. Yes to restart. This will restart your
computer in safe mode. Logon to your user account.

Now in safe mode, you will need to show hidden files and folders, as well as
system files and extensions for known file types.


Open RegLite and copy/paste the following string in the address window then
click go.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
The forum format puts a space in the word current that you will need to edit
out before clicking Go.

Right click the "qjpcbtsnx"="c:\\windows\\system32\\qjpcbtsnx.exe -start"
value in the right pane and delete. Then copy/paste the following.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\qjpcbtsnx

Right click the qjpcbtsnx key in the left pane and delete.

Then paste,

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\Instant Access

click go and delete the Instant Access key in the left pane.

Exit Reglite.


Open C:\Temp if present, select all and delete.
Open C:\Windows\Temp, select all and delete.
Open C:\Windows\Prefetch, select all and delete.
Open C:\Documents and Settings\username\Local Settings\temp, select all and
delete. Do this for all usernames.
Open the control panel, then internet options and delete the temporary
internet files, checking the box for offline content.
Open My Computer, right click Local disk C: and choose properties, then disk
cleanup. Check all boxes except compress old files and click OK.
Uncheck the /safeboot box in msconfig and ok to reboot.


Run another HijackThis scan and post the log. Let us know if the popups
stop.
 
G

Guest

-----Original Message-----
The site www.zipzappromos.com keeps poping up and I can't
stop it.
I've run antispyware,spysweeper and ad-aware with noluck.
Sometimes magic control and mc and mc||sa are in the
registry. I've rmoved then and run scans in safe mode and
with restore off.
ther seems ti be a 'hitbox' label in front af cookie
addresses found in temp internet at owner.
Any ideas?
.
Try a program called hijack this.
Also spybot search and destroy
cwshredder.exe
 
G

Guest

-----Original Message-----
-----Original Message-----
Have you checked in Add/Remove Programs to see if there are any installers
relating to that particular spyware program? Also,
click
start > run > type
in msconfig > startup tab > under startup items, check to see if its there,
uncheck and restart the system.

Or this:
Save this to text where you can access it in safe mode.

Download Pocket Killbox from here:
http://www.downloads.subratam.org/KillBox.zip

Unzip the files to a folder, then open and double-click on Killbox.exe to
run it. In the "Paste Full Path of File to Delete" box, copy and paste the
following:

C:\WINDOWS\System32\qjpcbtsnx.exe

Check the box to delete on reboot and click the red X
to
the right. Click
OK, then NO to reboot now. Copy the next filepath and paste it in the box,
and repeat the above steps. When all of the below filepaths are done, close
the Killbox.

C:\WINDOWS\Downlo~1\EGDACCESS.inf
C:\WINDOWS\system32\EGDACCESS_1057.dll



Download and install Reglite.


Scan again with HijackThis and place a check next to
the
following entries.
Close ALL other windows and click fix.

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF- 000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758- 209B6AD74ACC} - (no file)
O4 - HKCU\..\Run: [Instant Access] rundll32.exe
EGDACCESS_1057.dll,InstantAccess
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocach...up1.0.0.8-2.cab
O16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} -
http://akamai.downloadv3.com/binari...ESS_1057_XP.cab


Right click My Computer and choose properties. On
system
restore tab, check
the box to turn off. OK out.

Go to start>run and type msconfig, hit enter. On the boot.ini tab, check the
box next to /safeboot and OK. Yes to restart. This will restart your
computer in safe mode. Logon to your user account.

Now in safe mode, you will need to show hidden files
and
folders, as well as
system files and extensions for known file types.


Open RegLite and copy/paste the following string in the address window then
click go.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
The forum format puts a space in the word current that you will need to edit
out before clicking Go.

Right click the "qjpcbtsnx"="c:\\windows\\system32 \\qjpcbtsnx.exe -start"
value in the right pane and delete. Then copy/paste the following.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\qjpcbtsnx

Right click the qjpcbtsnx key in the left pane and delete.

Then paste,

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
entVersion\Uninstall\Instant Access

click go and delete the Instant Access key in the left pane.

Exit Reglite.


Open C:\Temp if present, select all and delete.
Open C:\Windows\Temp, select all and delete.
Open C:\Windows\Prefetch, select all and delete.
Open C:\Documents and Settings\username\Local Settings\temp, select all and
delete. Do this for all usernames.
Open the control panel, then internet options and
delete
the temporary
internet files, checking the box for offline content.
Open My Computer, right click Local disk C: and choose properties, then disk
cleanup. Check all boxes except compress old files and click OK.
Uncheck the /safeboot box in msconfig and ok to reboot.


Run another HijackThis scan and post the log. Let us know if the popups
stop.

--

Andre
http://spaces.msn.com/members/adacosta
FAQ for MS AntiSpy http://www.geocities.com/marfer_mvp/FAQ_MSantispy.htm
get 'killbox' or 'reglite'.
So I reran antispyware again in the safe mode and it
fixed the following.
Spyware Scan Details
Start Date: 3/5/2005 5:37:26 PM
End Date: 3/5/2005 6:09:23 PM
Total Time: 31 mins 57 secs

Detected Threats

Instant Access Dialer more information...
Details: InstantAccess is a dialer that gives a user
access to premium services of a third-party Web site by
dialing high-cost numbers using a modem.
Status: Removed
Severe threat - Severe-risk items have an extreme
potential for harm, such as a security exploit, and
should be removed.

Infected files detected
c:\windows\system32\netslv32.dll

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F72BC3F0-6C20-
4793-9DDA-258589D8A907}
HKEY_CLASSES_ROOT\clsid\{F72BC3F0-6C20-4793-9DDA-
258589D8A907}
HKEY_CLASSES_ROOT\clsid\{F72BC3F0-6C20-4793-9DDA-
258589D8A907}\InprocServer32 C:\WINDOWS\system32
\netslv32.dll
HKEY_CLASSES_ROOT\clsid\{F72BC3F0-6C20-4793-9DDA-
258589D8A907}\InprocServer32 ThreadingModel Apartment


Possible Browser Hijack Browser Modifier more
information...
Details: Possible Browser Hijack redirects Internet
Explorer.
Status: Removed
High threat - High-risk items have a large potential for
harm, such as loss of computer control, and should be
removed unless knowingly installed.


Detected Spyware Cookies
No spyware cookies were found during this scan.

Now I haven't been attached for two days.

Thanks, I hope I'm safe!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top