home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

Media Tickets Browser HiJack

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2508
Discussions: 200,996, Posts: 2,379,942, Members: 246,364
Old July 2nd, 2004, 05:59 PM   Digg it!   #1 (permalink)
Junior Member
 
Join Date: Jul 2004
Location: Brazil
Posts: 3
Send a message via ICQ to NatanielKlug Send a message via MSN to NatanielKlug
Exclamation
Media Tickets Browser HiJack

Hello Everyone,

I have Microsoft Windows XP Pro installed at my notebook (Sony Vaio PCG-FRV35) but every minute it opens a web page to join Media Tickets. I looked all over the internet and found many other guys who have the same problem, but no one was the same file or program that has been doind this pop-up.

Right now, when I am typing this message, it's the third time I have to log in techimo forum to finish this.

I have instaled HiJack Software and this is the log it returns to me when I am logged with my personal login (it has administrative rights).

Any help will be apreciated.

Att,

Nataniel Klug

---- HIJACK LOG ----
Logfile of HijackThis v1.98.0
Scan saved at 17:37:00, on 02/07/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\tcpsvcs.exe
D:\WINDOWS\Explorer.EXE
D:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\WINDOWS\System32\carpserv.exe
D:\Arquivos de programas\Sony\HotKey Utility\HKserv.exe
D:\WINDOWS\System32\oavsznv.exe
D:\WINDOWS\System32\fep.exe
D:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
D:\Arquivos de programas\Sony\HotKey Utility\HKWnd.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Arquivos de programas\MSN Apps\Updater\01.02.0000.2693\pt-br\msnappau.exe
C:\Cyber Nett\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com.br/0SEPTBR/SAOS01
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.drumcash.com/click.cgi?christanhalfman
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 200.163.208.11:3128
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=D:\WINDOWS\system32\userinit.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - D:\Arquivos de programas\MSN Apps\ST\01.02.0000.2693\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.0000.2693\pt-br\msntb.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - D:\WINDOWS\Downloaded Program Files\gbieh.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Arquivos de programas\MSN Apps\MSN Toolbar\01.02.0000.2693\pt-br\msntb.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] D:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [HKSERV.EXE] D:\Arquivos de programas\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [Microsoft Update] oavsznv.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [Microsoft Update Machine] fep.exe
O4 - HKLM\..\Run: [Updater] "D:\Arquivos de programas\MSN Apps\Updater\01.02.0000.2693\pt-br\msnappau.exe"
O4 - HKLM\..\RunServices: [Microsoft Update] oavsznv.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] fep.exe
O4 - HKCU\..\Run: [Microsoft Update] oavsznv.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] fep.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://D:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Arquivos de programas\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Arquivos de programas\ICQLite\ICQLite.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399F83} (GbPluginObj Class) - https://www14.bancobrasil.com.br/plugin/GbPluginBb.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3276E82C-C39F-4A41-BFFD-5B0362E9415B}: NameServer = 200.163.208.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{42A8488C-E744-4097-B677-2900E0198350}: NameServer = 200.163.208.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{6C91CCDA-4034-45E1-8013-DE1C42CFBB51}: NameServer = 200.163.208.4
NatanielKlug is offline   Reply With Quote
Old July 2nd, 2004, 06:32 PM     #2 (permalink)
Ultimate Member
 
twistedbrntucker's Avatar
 
Join Date: Aug 2002
Location: Cincinnati, Ohio
Posts: 2,016
http://www.avast.com/


Go here and load this antivirus and update. Set to run at startup and see if it will get it.

Last edited by twistedbrntucker : July 2nd, 2004 at 06:40 PM.
twistedbrntucker is offline   Reply With Quote
Old July 3rd, 2004, 08:15 AM     #3 (permalink)
Junior Member
 
Join Date: Jul 2004
Location: Brazil
Posts: 3
Send a message via ICQ to NatanielKlug Send a message via MSN to NatanielKlug
Quote:
Originally Posted by twistedbrntucker
http://www.avast.com/


Go here and load this antivirus and update. Set to run at startup and see if it will get it.

Twisted,

Thanks for your help but this program did not get any virus in my computer. Its more like a worm.

Att,

Nataniel Klug
NatanielKlug is offline   Reply With Quote
Old July 3rd, 2004, 09:59 AM     #4 (permalink)
Ultimate Member
 
LeftCoast's Avatar
 
Join Date: Sep 2002
Location: Tampa
Posts: 1,918
Hey Nataniel,

Welcome to the forums.

Try these two free programs; they work on a lot of stuff.

http://www.webroot.com (Spy sweeper)

and http://www.safer-networking.org/index.php?page=spybotsd (Spybot search and destroy)


Both progs give you options to immunize your system. Also, have you run your AV program in safe mode yet? Sometimes you need to...
__________________
Millions long for immortality who don't know what to do with themselves on a rainy Sunday afternoon.
Susan Ertz
LeftCoast is offline   Reply With Quote
Old July 3rd, 2004, 11:33 AM     #5 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Posts: 10,821
also of course..make sure you have dome all the windows critical updates
__________________
"Even a fool is thought to be wise if he is silent"
John Prophet is offline   Reply With Quote
Old July 3rd, 2004, 11:42 AM     #6 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Posts: 10,821
there is a forum where peeps help you read those hijack this lists

http://forums.net-integration.net/in...p?showforum=32

evidently that "media tickets" is a lil hard ot get rid off

-----

I have seen this file mentioned several times

C:\WINDOWS\System32\systemse.exe

do you have that one? it could be "hidden" so you might need to set your folders to display all files including hidden ones

it is also shown that you might need to delete these registry entries

O4 - HKLM\..\Run: [Microsoft Update Machine] systemse.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] systemse.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] systemse.exe


for example http://www.security-forums.com/forum...&view=previous

Last edited by John Prophet : July 3rd, 2004 at 11:47 AM.
John Prophet is offline   Reply With Quote
Old July 5th, 2004, 10:13 AM     #7 (permalink)
Junior Member
 
Join Date: Jul 2004
Location: Brazil
Posts: 3
Send a message via ICQ to NatanielKlug Send a message via MSN to NatanielKlug
John e LeftCoast,

Thanks for your help. That programs I have already used and did not work for that what I want.

I read all messagens in forum and they where all diferent kinds of Media Tickets problem. I will try to learn it by my self and them I will post the results.

Thnks again.

Att,

Nataniel Klug
NatanielKlug is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Media-tickets popup Chrisvst Security and Privacy Issues 5 June 22nd, 2004 12:43 PM
Spyware HELL! Plz Help!!!! CJDMaster804 General Tech Discussion 24 June 10th, 2004 03:38 PM
Netzero hijacked my autosearch waynezo Security and Privacy Issues 1 May 6th, 2004 10:25 AM
Help with IE Problem maximus01can Networking and Internet 12 December 8th, 2003 02:07 PM
Ad-Aware has picked up something new... crazyray General Tech Discussion 6 May 2nd, 2002 04:13 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (3092)
Foxconn Blackops x48 MoBo (5)
Charges against non-tippers dropped.. (22)
Health Care Rationing (16)
Nvidia GTX 260 problem (13)
Delete an OS (17)
Laptop with wireless problem. (13)
Wireless Televisions. (12)
windows vista security holes (19)
CPU fan stops spinning randomly (11)
Regular Build (11)
Point and Shoot Camera Suggestions. (9)
[F@H SPAM 11/16/09] ! 1/2 months to.. (41)
windows 7 problem (7)
Recent Discussions
add ram to existing (0)
Nvidia GTX 260 problem (13)
Laptop with wireless problem. (13)
Point and Shoot Camera Suggestions. (9)
Is the PSU I received dead? (16)
FreeAgent drive software not x64 comp.. (1)
Intel 5100 AGN issues fixed yet? (28)
Foxconn Blackops x48 MoBo (5)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (41)
Print spooler problem (17)
Q9650 vs. Q9550 (2)
Desktop Calendar Application (2)
Looking for new motherboard (1)
soundmon.exe (8)
Jedi Academy Problem (3)
Can a page file be "too big".. (1)
Size after cutting 700Mb file is 2.5 .. (0)
Delete an OS (17)
windows vista security holes (19)
updating BIOS via winflash, claims fi.. (1)
New Server Configuration Suggestions (0)
cheap gaming laptop? (12)
Unallocated Space (2)
help me pls laptop just stopped worki.. (1)
C# + LINQ Help (7)


All times are GMT -4. The time now is 11:21 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28