Click to See Complete Forum and Search --> : pop up


Ky.Rose
January 20th, 2005, 01:36 PM
I keep getting a pop up when I am on the Internet says: ( bling .exe ) wants to know if I want to send a report or not. can anyone tell me what it means and how to get rid of it? Also I have a icon for windows messenger on my task bar I don't even have windows messenger on my computer does anyone know how I can get that off?



Thanks for any help !!!!!

TechZ
January 20th, 2005, 02:07 PM
bling.exe is a W32 worm

Do an Online AV scan (when in safe mode) from

Trend Micro Online Scan: http://housecall.trendmicro.com/
or/and
Panda Online Scan: http://www.pandasoftware.com/activescan/

then run theses two application (update them first) so that your system is spyware free

Spybot Search & Destroy: http://www.safer-networking.org/index.php?page=download
AND
Adaware SE: http://www.lavasoftusa.com/software/adaware/

Remember to have an antivirus always installed on your system, for a free one try AVG (http://www.grisoft.com/) or Avast(http://www.avast.com/eng/avast_4_home.html)

geoscomp
January 20th, 2005, 02:15 PM
Also, if you have windows xp, you have windows messenger..it is automatically included unless you remove it manually.

(hey TechZ..can you run an online scanner in safe mode?)

Ky.Rose
January 20th, 2005, 02:49 PM
How do I remove the messenger? I have AVG 7.0 and spy bot on my computer so I run them to get rid of the pop up?

TechZ
January 20th, 2005, 03:00 PM
I was wondering that too geoscomp, no harm in trying ;)

update AVG7.0 Ky.Rose, and then in Safe Mode, run a full system scan.

Also go here http://mirror.edskes.com/
and download the NOD32 AV standalone file and run a scan in Safe Mode. its just a standalone exe version, not a replacement for AVG. And yes run Spybot and install and run Adaware.

Ky.Rose
January 20th, 2005, 03:14 PM
I was wondering that too geoscomp, no harm in trying ;)

update AVG7.0 Ky.Rose, and then in Safe Mode, run a full system scan.

Also go here http://mirror.edskes.com/
and download the NOD32 AV standalone file and run a scan in Safe Mode. its just a standalone exe version, not a replacement for AVG. And yes run Spybot and install and run Adaware.





How do I start it in safe mode?,and which one do I download shows two?

a1.edskes.com
c2.edskes.com NOD32 Anti-Virus a1.edskes.com/nod32_20041229.exe
c2.edskes.com/nod32_20041229.exe

Ky.Rose
January 20th, 2005, 03:31 PM
I wanting to if there is a way that I tell how many times windows xp is on my computer? I had a trojan in it a couple of days ago, and I reinstalled the windows Xp about 3 times and now my computer is real slow.

TechZ
January 21st, 2005, 05:41 AM
Virus/Trojans wont go away by reinstalling xp, unless you format your pc and then install xp. To boot into safe mode, http://www.pchell.com/support/safemode.shtml
scroll down to XP.

and for NOD32, try any of them.

NooNoo
January 22nd, 2005, 09:20 AM
for trojans and worms get a-squared www.emsisoft.com They have a free version as well as a paid version.

Ky.Rose
January 22nd, 2005, 11:40 AM
I have the spybot and avast anti-virus on my computer and I am still getting that bling.exe pop up:here a HJT log can anyone tell what is bad on it?



Logfile of HijackThis v1.99.0
Scan saved at 11:39:21 AM, on 1/22/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Propel Accelerator\PropelAC.exe
C:\WINDOWS\System32\Sygate.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 6 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=localhost:8080
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\Propel Accelerator\prpl_IePopupBlocker.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [Propel Accelerator] C:\Program Files\Propel Accelerator\PropelAC.exe
O4 - HKLM\..\Run: [LsasS] Sygate.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall] host32.exe
O4 - HKLM\..\RunServices: [LsasS] Sygate.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O8 - Extra context menu item: Allow pop-ups from this site - C:\Program Files\Propel Accelerator\pac-addwl.html
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\Propel Accelerator\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\Propel Accelerator\pac-image.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1106258815703
O17 - HKLM\System\CCS\Services\Tcpip\..\{EE080AA5-1CF4-412D-9F77-28F75B674FC4}: NameServer = 204.68.227.1 204.68.227.2
O23 - Service: avast! iAVS4 Control Service - Unknown - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe



Thanks For Any Help !!!!