Close

Results 1 to 17 of 17
  1. #1
    DF VIP Member lombie's Avatar
    Join Date
    Jul 2001
    Location
    In a house
    Posts
    2,214
    Thanks
    62
    Thanked:        20
    Karma Level
    499

    Default FAO Mule re: Hijack this PM

    deleted
    Last edited by lombie; 11th February 2009 at 03:30 PM. Reason: google searched for my name and it led to this thread

  2. #2
    DF VIP Member
    Mule's Avatar
    Join Date
    Mar 2004
    Location
    Surrey
    Posts
    9,210
    Thanks
    460
    Thanked:        979
    Karma Level
    1050

    Default Re: FAO Mule re: Hijack this PM

    Uninstall winfixer and make sure that the installer for it is not in your startup folder, if it is then check where the target file is, delete the shortcut in the startup folder and the target file itself.

    If it's not then go Start>Run type 'MSconfig' and press return. Click the startup tab and see if the installer for it is listed there, if it is then uncheck it and look to see where it's installed, go to that directory and delete the file.

    Run HJT and have it kill these;

    C:\Program Files\etea\rpen.exe
    O4 - HKLM\..\RunServices: [Microsoft Crs Fix Serv] wincrs.exe
    O4 - HKCU\..\Run: [Usrr] C:\Program Files\etea\rpen.exe

    Reboot into safe mode, run a full AVG scan and a full MS antispyware scan.

    If you're still having problems after that post another HJT log.


    EDIT: It may go under the name of "UWFX5LP_0001_0614NetInstaller" if it's in the msconfig startup list.
    Last edited by Mule; 15th August 2005 at 01:48 PM.

  3. #3
    DF VIP Member lombie's Avatar
    Join Date
    Jul 2001
    Location
    In a house
    Posts
    2,214
    Thanks
    62
    Thanked:        20
    Karma Level
    499

    Default Re: FAO Mule re: Hijack this PM

    deleted
    Last edited by lombie; 4th August 2009 at 03:00 PM.

  4. #4
    DF VIP Member
    Mule's Avatar
    Join Date
    Mar 2004
    Location
    Surrey
    Posts
    9,210
    Thanks
    460
    Thanked:        979
    Karma Level
    1050

    Default Re: FAO Mule re: Hijack this PM

    Is winfixer still there?





  5. #5
    DF VIP Member lombie's Avatar
    Join Date
    Jul 2001
    Location
    In a house
    Posts
    2,214
    Thanks
    62
    Thanked:        20
    Karma Level
    499

    Default Re: FAO Mule re: Hijack this PM

    Quote Originally Posted by Mule
    Is winfixer still there?
    Nope - that appears to have gone.

    I think i may have made an error though so am just going back through your processes again.

    where i was so used to pressing 'block' on the adwatch thingy i've just seen that one of the requests was for permission to delete the etea thing from the registry and me being a halfwit and not reading just keep pressing block, block, block and therefore keeping the bastard file there:whistle .

    I'll try again and hopefully re-post in a minute with some success.

    Cheers Mule

  6. #6
    DF VIP Member
    Mule's Avatar
    Join Date
    Mar 2004
    Location
    Surrey
    Posts
    9,210
    Thanks
    460
    Thanked:        979
    Karma Level
    1050

    Default Re: FAO Mule re: Hijack this PM

    If you're going through it all again then do it all in safe mode and before you do anything else turn off system restore.

    So, reboot into safe mode,

    turn off system restore, Start>Programs>accessories>system tools>system restore click 'system restore settings' tick 'turn off system restore' and click apply

    Uninstall winfixer and make sure that the installer for it is not in your startup folder, if it is then check where the target file is, delete the shortcut in the startup folder and the target file itself.

    If it's not then go Start>Run type 'MSconfig' and press return. Click the startup tab and see if the installer for it is listed there, if it is then uncheck it and look to see where it's installed, go to that directory and delete the file.

    Run HJT and have it kill these;

    C:\Program Files\etea\rpen.exe
    O4 - HKLM\..\RunServices: [Microsoft Crs Fix Serv] wincrs.exe
    O4 - HKCU\..\Run: [Usrr] C:\Program Files\etea\rpen.exe

    run a full AVG scan and a full MS antispyware scan.

    Turn system restore back on.

    Reboot.

  7. #7
    DF VIP Member lombie's Avatar
    Join Date
    Jul 2001
    Location
    In a house
    Posts
    2,214
    Thanks
    62
    Thanked:        20
    Karma Level
    499

    Default Re: FAO Mule re: Hijack this PM

    Ok

    All done again mule while turning off the system restore as described.

    When i've rebooted this time i'm still getting an alarm saying that an attempt to add a registry value as before except this has 'new data' and not 'data':-

    Root: HKEY_CURRENT_USER
    Key: Software\Microsoft\Windows\CurrentVersion|Run
    Value: Usrr
    Data:
    New Data: C:\Program Files\etea\rpen.exe

    The ad's are not coming up anymore though!

  8. #8
    ABCMan
    Guest ABCMan's Avatar

    Default Re: FAO Mule re: Hijack this PM

    open msconfig
    youll see that there is a line somewhere with a regedit command it should point you to the location of the file that is being recopied to your system and also allow you to remove that command.

    mostly these will execute a command to copy a file and rename it as well as adding it to your registry.

    webroots spysweeper should be run in safe mode if you want to remove all traces once you've killed the regedit / loader command.

  9. #9
    DF VIP Member lombie's Avatar
    Join Date
    Jul 2001
    Location
    In a house
    Posts
    2,214
    Thanks
    62
    Thanked:        20
    Karma Level
    499

    Default Re: FAO Mule re: Hijack this PM

    Quote Originally Posted by ABCMan
    open msconfig
    youll see that there is a line somewhere with a regedit command it should point you to the location of the file that is being recopied to your system and also allow you to remove that command.

    mostly these will execute a command to copy a file and rename it as well as adding it to your registry.

    webroots spysweeper should be run in safe mode if you want to remove all traces once you've killed the regedit / loader command.
    I've done the msconfig and get a 'System Configuration Utility' but can't see any regedit?

    I get 'General' 'System.ini' 'WIN.INI' 'Boot.INI' 'Services' and 'Startup'

    The problem does seem to have disappeared for the time being though but i'll get the spysweeper just in case

    Thanks

  10. #10
    DF VIP Member
    Mule's Avatar
    Join Date
    Mar 2004
    Location
    Surrey
    Posts
    9,210
    Thanks
    460
    Thanked:        979
    Karma Level
    1050

    Default Re: FAO Mule re: Hijack this PM

    If it's there it would be under the 'startup' tab, have a look through all the things listed there and post anything that you don't recognise, which may well be most of it, unfortunately you cant cut and paste it so it might be easier to do a couple of screenshots of it instead, up to you.

    I expect you'll get the same alarm every time you reboot until it's removed.

  11. #11
    DF VIP Member lombie's Avatar
    Join Date
    Jul 2001
    Location
    In a house
    Posts
    2,214
    Thanks
    62
    Thanked:        20
    Karma Level
    499

    respect Re: FAO Mule re: Hijack this PM

    a
    Last edited by lombie; 4th August 2009 at 03:13 PM. Reason: coming up with my details in a google search

  12. #12
    DF VIP Member
    Mule's Avatar
    Join Date
    Mar 2004
    Location
    Surrey
    Posts
    9,210
    Thanks
    460
    Thanked:        979
    Karma Level
    1050

    Default Re: FAO Mule re: Hijack this PM

    My poor eyes!


    It looks ok actually, I'm not sure where else it could be running from.

  13. #13
    DF VIP Member lombie's Avatar
    Join Date
    Jul 2001
    Location
    In a house
    Posts
    2,214
    Thanks
    62
    Thanked:        20
    Karma Level
    499

    Default Re: FAO Mule re: Hijack this PM

    Quote Originally Posted by Mule
    My poor eyes!


    It looks ok actually, I'm not sure where else it could be running from.
    Thanks for all your efforts anyway mule - its been much appreciated.

    You were right about the warning everytime on startup but i can live with that as the pop-ups and virus stuff have all gone.

    :thumbs

  14. #14
    DF VIP Member
    Mule's Avatar
    Join Date
    Mar 2004
    Location
    Surrey
    Posts
    9,210
    Thanks
    460
    Thanked:        979
    Karma Level
    1050

    Default Re: FAO Mule re: Hijack this PM

    I'm sure someone will come up with a way to get rid of it for you, my brain has melted for the day which means it's time for a glass of wine.

  15. #15
    DF VIP Member flumperino's Avatar
    Join Date
    Jan 2004
    Location
    Isle of flumps
    Posts
    9,612
    Thanks
    521
    Thanked:        679
    Karma Level
    882

    Default Re: FAO Mule re: Hijack this PM

    Quote Originally Posted by lombie

    mHotkey
    gcasServ
    dumpprep 0-k
    gsicon
    Datalayer
    SVChost
    gcasServ is to do with MS Antispyware mate
    svchost is a system process that runs dll's or something. You don't want to stop it, put it that way

    the others I don't know, sorry

    Shooooooo-ryuken!

  16. #16
    DF VIP Member
    Mule's Avatar
    Join Date
    Mar 2004
    Location
    Surrey
    Posts
    9,210
    Thanks
    460
    Thanked:        979
    Karma Level
    1050

    Default Re: FAO Mule re: Hijack this PM

    Quote Originally Posted by lombie
    Thanks for all your efforts anyway mule - its been much appreciated.

    You were right about the warning everytime on startup but i can live with that as the pop-ups and virus stuff have all gone.

    :thumbs
    If you still haven't got rid of it then this program lists all auto-starting apps on your computer;

    http://www.lurkhere.com/~nicefiles/startuplist1521.zip

  17. #17
    DF VIP Member lombie's Avatar
    Join Date
    Jul 2001
    Location
    In a house
    Posts
    2,214
    Thanks
    62
    Thanked:        20
    Karma Level
    499

    Default Re: FAO Mule re: Hijack this PM

    Quote Originally Posted by Mule
    If you still haven't got rid of it then this program lists all auto-starting apps on your computer;

    http://www.lurkhere.com/~nicefiles/startuplist1521.zip
    Touch wood Mule things have been fine over the last couple of weeks after your previous effort the pop-ups and registry alterations have even stopped
    Last edited by lombie; 2nd September 2005 at 04:22 PM.

Similar Threads

  1. check over this hijack log...
    By Spennyboy in forum System Security
    Replies: 11
    Last Post: 30th April 2005, 11:18 PM
  2. internet crash - now low ID with mule, port 4662??
    By QfanatiQ in forum PC Problems
    Replies: 0
    Last Post: 22nd February 2005, 10:43 PM
  3. Sharereactor--Edonkey/Mule safety??
    By knee doc in forum PC Software
    Replies: 2
    Last Post: 25th April 2004, 04:52 PM
  4. muffin the mule
    By God is a DJ in forum The Comedy Club
    Replies: 2
    Last Post: 12th January 2004, 01:08 PM
  5. Hijack
    By Hobbit in forum The Comedy Club
    Replies: 2
    Last Post: 26th September 2002, 12:19 AM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •