caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
what kind of popups are they . 2 things in you log that look suspicious
O4 - HKCU\..\Run: [Lerm] C:\Documents and Settings\Steven\Application Data\cacp.exe
O4 - HKCU\..\Run: [WNST] C:\WINDOWS\System32\wnsapisv.exe
can't find any info on them and that makes them suspicious,do you ahve any idea what they are
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
what kind of popups are they . 2 things in you log that look suspicious
O4 - HKCU\..\Run: [Lerm] C:\Documents and Settings\Steven\Application Data\cacp.exe
O4 - HKCU\..\Run: [WNST] C:\WINDOWS\System32\wnsapisv.exe
can't find any info on them and that makes them suspicious,do you ahve any idea what they are
CACP.EXE is OK, I checked it out earlier. wnsapisv.exe is suspect, however. I have not found anything by searching on it and the filename sounds a bit dangerous.
At the very least, you should download and run the following utilities from Gibson Research : DCOMbob.exe, ShootTheMessenger.exe, and uPNP.exe. The first one shuts off the DCOM/RPC function that Blaster/Nachi/Welchia uses to infect systems, the second shuts off the Messenger service (which is not the same as AIM, MSN Messenger. or Yahoo! Messenger) to prevent spam pop-ups (and is likely giving you your problems), and the third turns off Universal Plug-and-Play, a security risk. All of these procedures are reversible, of course.
TallCool1
Practically a Posting Shark
865 posts since May 2003
Reputation Points: 149
Solved Threads: 45
Those are all good windows files .the carpserve one is associated with your a Zoltrix modem ,ccApp.exe ,and ccEvtMgr.exe are norton ,csrss.exe is client server releated .lsass.exe is legit system file ,but some can be virus releated if they are in the wrong folder,it gets complicated !!.If you are worried about viruses run a online virus scan .
http://housecall.trendmicro.com/
And this [popups about popup and how to get rid of them .]can be stopped by getting stop the messenger fro the GRC site mentioned in TallCool1 post
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812