Home > Help With > Help With Pokapoka78

Help With Pokapoka78

Here is the WinPFind report. Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exeO23 - Service: Windows Overlay Components - Unknown Several functions may not work. PC Person BSOD's 121916 [SOLVED] Nero 8 Install Networking Help Block out going...

Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exeO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cabO16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} (CInstall Class) - http://adserver.sharewareonline.com/adserver/Install.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com/PhotoUpload/MsnPUpld.cab?10,0,910,0O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} Double Click on "Track qoo.vbs" Note - If you Antivirus has Script Blocking, you will get a Pop Up Windows asking you what to do. Be sure to uninstall the previous version. 1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.) 2.

Wait a few seconds and a notepad page will pop up, Copy & Paste those results in your next reply. * If your Antivirus has Script Blocking, you will get a All rights reserved. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item:

Click Start Scan 3. It's a bad case of multiple infections which requires extensive work. BLEEPINGCOMPUTER NEEDS YOUR HELP! It also comes up and says pokapoka78.exe has to close.

In your next post, please include fresh logs from:HiJackThis log Online Scan Ewido WinPfind TrackQoo1.vbs Please provide details of any problems you encountered whilst performing the above steps & update Place a check against each of the following:R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.clicktomakeasearch.com/sp2.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.clicktomakeasearch.com/sp2.phpF3 - REG:win.ini: load="C:\WINDOWS\svhost32.exe"O4 - HKLM\..\Run: [vvdfbvd] C:\WINDOWS\vvdfbvd.exeO4 - HKCU\..\Run: [CAS2] "C:\Program Files\System HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\mkmxqxfg HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run winsync C:\WINDOWS\system32\popckc.exe reg_run Close Regedit Run Ewido:Click [Scanner] Click [Complete System Scan] to begin scanning. Click next > Click OK. 12.

Once you've moved HijackThis to a safe location, go to post #14 and follow the instructions for removing yupsearch. iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Intel AQ710A USB Charging cable Crazy ad sound in background! WARNING: not all files found by this scanner are bad.

That makes sense then. Can someone help me get rid of this stupid Pokapoka78 crap I tried nortons free trial, it doesnt work. A case like this could easily cost hundreds of thousands of dollars. Submit a fresh HijackThis log for review.

Cann't kill pokapoka78.exe Started by hubinwrite , Oct 25 2005 04:39 PM Please log in to reply #1 hubinwrite Posted 25 October 2005 - 04:39 PM hubinwrite New Member Member 1 Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs 0 user(s) are reading this topic 0 members, 0 guests, 0 anonymous users Reply to quoted postsClear BleepingComputer.com Logfile of HijackThis v1.99.1 Scan saved at 1:21:57 PM, on 11/4/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe An illegal version maybe?

User Name Remember Me? Reboot into Safe Mode, scan with HJT, and have it fix the following entries: O4 - HKCU\..\Run: [SVC Service] svc32.pif O4 - HKCU\..\Run: [HTML32 Help System] hhs32.pif O4 - HKCU\..\RunServices: [SVC It is good when you're Product Id changed when you reinstall the OS?but still … Slow computer, pop up in web browser 3 replies Help require to clean up my laptop. I think my problems should be solved....

Checking %WinDir% folder... Please help me out. In the popup box that appears, type in "Service name" & then click on the OK button * * * * * * * * * * * * * *

You really need the updates though, because you'll get infected again and again and again, because you really need the security patches.You don't like SP1 or SP2, so you can never

Perform an online scan with Internet Explorer with Panda ActiveScan ** click on "Free use ActiveScan" located on the top right hand corner Click Scan your PC & a 'pop up' Once the Scan is complete, it will create a report in a text file 4. Adam Smith Glasgow, 1760 Back to top Back to Resolved or inactive Malware Removal 0 user(s) are reading this topic 0 members, 0 guests, 0 anonymous users Reply to quoted postsClear As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. Make sure just “My Computer” is showing in the left pane and click..FILE….EXPORT…and save a copy some were in case you make a mistake. If you are having problems with the updater, you can use this link to manually update Ewido When you have finished updating, EXIT Ewido. 'UNPLUG'/DISCONNECT YOUR COMPUTER FROM THE INTERNET WHEN Here's the Hijackthis log: Logfile of HijackThis v1.99.1Scan saved at 4:38:22 PM, on 10/25/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program

I need the log from the second scan/clean...NOT the first...as this will contain what’s left in the system. Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List There are safer and better alternatives available.

PTech 8/3/2004 11:41:38 PM 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts Checking the Windows folder and sub-folders for system and hidden files within the last 60 days... 11/5/2005 10:13:38 AM S 2048 All Users Click OK Press the CleanUp! Back to top Back to User to User Help 0 user(s) are reading this topic 0 members, 0 guests, 0 anonymous users Reply to quoted postsClear PC Pitstop Forums → Let's clear out your restore points now.Disable System Restore;1.

pokapoka78.exe is a process associated with EliteBar Adware, which is an advertising program by EliteBar.