bremsech,
Try remove winfixer and winatnispyware with Control Panel > Add/Remove Programs. Delete all temporary internet files. I will look at your HijackThis log next.
Main Topics
Browse All TopicsI hope this is the right place for this problem. tried adaware, spybot, spydoctor, and also tried to follow someone elses directions to use the vundofix, but to no avail. It is my daughters computer at school and I am only here until tomorrow, so I hope someone can help me fix it.
Any advice is appreciated, here is her hijackthis log
<< Hijack This log removed by humeniuk PE >>
Thanks,
Charlotte
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
bremsech,
Here is a link to the analyzed log
http://hijackthis.de/logfi
You have an older version of HijackThis. Download the latest version and run HJT to get the log. Use http://hijackthis.de to analyze the log. Save the analysis and post link here.
Have HJT remove all items marked "Nasty" and "Unnecessarily".
R1 - HKCU\Software\Microsoft\In
Look at the items marked "Possibly Nasty" and "Unknown". If you do not recognized them, have HJT delete them.
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5
O9 - Extra button: Start EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-8
O9 - Extra 'Tools' menuitem: &EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-8
I downloaded the eidow and ran the scan:
--------------------------
ewido security suite - Scan report
--------------------------
+ Created on: 6:08:28 PM, 9/17/2005
+ Report-Checksum: EBB92C55
+ Scan result:
C:\Documents and Settings\David\Cookies\dav
C:\Documents and Settings\David\Cookies\dav
C:\Documents and Settings\David\Cookies\dav
C:\Documents and Settings\David\Cookies\dav
C:\Documents and Settings\David\My Documents\Weekly Computer Maintenance\backups\backup
C:\Documents and Settings\David\My Documents\Weekly Computer Maintenance\backups\backup
C:\Documents and Settings\David\My Documents\Weekly Computer Maintenance\backups\backup
C:\Documents and Settings\David\My Documents\Weekly Computer Maintenance\backups\backup
C:\WINDOWS\$NtUninstallKB8
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCa
C:\WINDOWS\SYSTEM32\vturr.
::Report End
I also deleted most of the item you suggested after I updated hijackthis. I had already deleted all my IE temp files and cookies, but I did it again anyway. Here is the new hijackthis file after all of the above was done.
<< Hijack This log removed by humeniuk PE >>
Thanks for your help, let me know if you think I need to do anything else. Otherwise I'll let you know later if the popups have gone away.
Thanks
http://hijackthis.de/logfi
It is getting cleaner.
Did you try to delete the following? If you did and they came back, try to delete with HJT in Safe Mode
R1 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5
O20 - Winlogon Notify: runwin - C:\WINDOWS\$N7AD2~1\runwin
http://www.hijackthis.de/l
Here is the link to my most recent hijackthis log. I wasn't able to delete two of the entries you listed in safe mode either.
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5
(this one I had tried to delete when I did the vundofix also and it wouldn't go anywhere.)
O20 - Winlogon Notify: runwin - C:\WINDOWS\$N7AD2~1\runwin
Any more advice?
Thanks
Ok, we have to delete the file
C:\WINDOWS\$N7AD2~1\runwin
1. Use Killbox to remove stuborn files
http://www.scancomplete.co
OR
Unlocker
http://www.majorgeeks.com/
Killbox has the option to delete on reboot.
2. If no joy, go to a command prompt, navigate to the file, and delete it.
Go to Start > Run and type cmd. Navigate to the C:\WINDOWS\$N7AD2~1. Type DEL runwin.dll.
3. If still no joy, disable the file. Right click on the runwin.dll file and select Security > Advanced. Uncheck "Inherent from Parent". Now the file is unusable.
Here is what I suggest:
(0) If running XP Home, boot in safe mode, if XP Pro or 2000, then start with step (1)
(1) Right click on the file (runwun.dll) in Windows Explorer or My Computer, select Properties
(2) Click on the Security tab.
(3) Click on the Advanced button.
(4) Uncheck the box labeled "Inherit from Parent...", then click "Remove"
(5) Close all windows.
(6) Reboot.
After reboot the file will be unable to run (because no one can access it any more). The symptoms will be gone.
Do not delete the file. Instead, run Hijackthis again and have it remove the O2 entry that refers to runwin.dll
I followed r-K's directions and they worked (I do have windows home xp so I needed to do it in safe mode) the security tab didn't show otherwise.
I could not find the file using explorer or my computer even when I could see hidden files. I had to use the search to find it. There were two of them, one in a !submit file and one by itself, I disabled both and was able to have hijackthis delete them. Thank you both. Now I hope this solves the popup problem.
Hey, should I uninstall ewido? It kept deleting adware in real time and it was almost as annoying as popups. I did disable the realtime protection, but since it is only a 14 day trial I assume I shoud uninstall? My daughter would have no clue how to once I am gone.
In addition any advice on how to have her avoid this in the future? Other than never downloading ANYTHING :)
Thanks,
Charlotte
Glad the files are disabled. If you could have found the files, you could have deleted them in command prompt.
>> Hey, should I uninstall ewido? It kept deleting adware in real time
Yes, go ahead an uninstall it. But deleting adware in real time is a good thing.
>> In addition any advice on how to have her avoid this in the future?
If you are using Internet Explorer, disable the two Download on Demand options in Options > Advanced tab.
Be careful what you download. I know that is difficult with a daughter who likes to download music files. Scan each file you download with anti-virus and anti-spyware.
Run anti-virus and adware scanners often.
Glad things are better. If you want to uninstall Ewido, I would suggest installing Microsoft anti-spyware in its place. It is a free program you can download and install from:
http://www.microsoft.com/a
Charlotte, glad the problem is fixed. Did I not contribute to the solution?
You wrote to me: " I wasn't able to delete two of the entries you listed in safe mode either.
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5
(this one I had tried to delete when I did the vundofix also and it wouldn't go anywhere.)
O20 - Winlogon Notify: runwin - C:\WINDOWS\$N7AD2~1\runwin
How did you know to delete this file if I did not analyze the HJT log for you?
you definitely helped me clean up her computer, I just wasn't able to delete the files the way you indicated. Probably my fault, I'm just not that good with the DOS stuff. I couldn't find the point list to have them spit the points when I posted earlier today. Please advise me how to do this.
Thanks,
Charlotte
Business Accounts
Answer for Membership
by: war1Posted on 2005-09-17 at 14:05:36ID: 14905097
Greetings, bremsech!
Try using Ewido to remove hard to remove spyware
http://www.ewido.net/en/
Cheers!