943,975 Members | Top Members by Rank

Ad:
Dec 18th, 2003
0

Hijack this log - can't get rid of pop ups

Expand Post »
I am getting crazy amounts of pop ups. I run ad-aware daily. Can anyone help?

Thank you so much! Here is my log:
Logfile of HijackThis v1.97.7
Scan saved at 4:23:49 PM, on 12/17/2003
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
C:\Program Files\Trend Micro\PC-cillin 2003\Pop3trap.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Cyberpwr\PanPlus.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe
C:\Program Files\Common files\updater\wupdater.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Zinio\ZDLM.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ntvdm.exe
C:\VSTASCAN\vsaccess.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\OPLIMIT\ocrawr32.exe
C:\WINNT\System32\rsvp.exe
C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\YisZ12.exe
C:\WINNT\system32\YisZ12.exe
C:\Program Files\WinZip\WINZIP32.EXE
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\unzipped\hijackthis[1]\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8081
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://start.earthlink.net/channel/START
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\Pop3trap.exe"
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Power Panel plus] C:\Cyberpwr\PanPlus.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Propel Accelerator] C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe
O4 - HKLM\..\Run: [caqvevch] C:\WINNT\SYSTEM32\sefss.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [4WGW#Q23HAX4HK] C:\WINNT\system32\MztYif2.exe
O4 - HKCU\..\Run: [Zinio DLM] C:\PROGRA~1\Zinio\ZDLM.exe /hide
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://zinio.earthc.net/images.zinio...der/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C8548FC5-6B6A-420A-A142-5316A1C01725}: NameServer = 207.69.188.187 207.69.188.186
Reputation Points: 10
Solved Threads: 0
Newbie Poster
jdonisthorpe is offline Offline
5 posts
since Dec 2003
Dec 18th, 2003
0

Re: Hijack this log - can't get rid of pop ups

Do you run a popup blocker such as the one built into the google toolbar?
Administrator
Staff Writer
Reputation Points: 1422
Solved Threads: 162
The Queen of DaniWeb
cscgal is offline Offline
13,645 posts
since Feb 2002
Dec 18th, 2003
0

Re: Hijack this log - can't get rid of pop ups

Hi.
Yes, I do run Google's pop up blocker. The minute I get on the internet I get about 10 popups just when I go to my home page (my yahoo dot com)

Thanks!
Jennifer
Reputation Points: 10
Solved Threads: 0
Newbie Poster
jdonisthorpe is offline Offline
5 posts
since Dec 2003
Dec 18th, 2003
0

Re: Hijack this log - can't get rid of pop ups

Sorry, I don't think I can be much help. A lot of the stuff you have loaded I know what it is. But there's a bunch of programs I've never heard of - so I wouldn't know what's hijacked and what isn't, etc. Why do you have an Earthlink popup blocker and a Google popup blocker?
Administrator
Staff Writer
Reputation Points: 1422
Solved Threads: 162
The Queen of DaniWeb
cscgal is offline Offline
13,645 posts
since Feb 2002
Dec 18th, 2003
0

Re: Hijack this log - can't get rid of pop ups

Thanks for looking. I actually got rid of earthlink blocker this morning. It is just terrible, I can't do anything!
Reputation Points: 10
Solved Threads: 0
Newbie Poster
jdonisthorpe is offline Offline
5 posts
since Dec 2003
Dec 18th, 2003
0

Re: Hijack this log - can't get rid of pop ups

try running cwshredder,after unziping and running don't click scan ,click next
http://www.spywareinfo.com/~merijn/files/cwshredder.zip
Team Colleague
Reputation Points: 1056
Solved Threads: 792
I hate 20 Questions
caperjack is offline Offline
12,725 posts
since Aug 2003
Dec 18th, 2003
0

Re: Hijack this log - can't get rid of pop ups

check this site for highjack log help ,the best i've seen so far ,Bulldog is really good at reading them .
http://www.tweakxp.com/forum/forum_topics.asp?FID=29
Team Colleague
Reputation Points: 1056
Solved Threads: 792
I hate 20 Questions
caperjack is offline Offline
12,725 posts
since Aug 2003
Dec 18th, 2003
0

Re: Hijack this log - can't get rid of pop ups

I will try both, thank you
Reputation Points: 10
Solved Threads: 0
Newbie Poster
jdonisthorpe is offline Offline
5 posts
since Dec 2003
Dec 19th, 2003
0

Re: Hijack this log - can't get rid of pop ups

Bulldog solved my problem. Thanks!
Reputation Points: 10
Solved Threads: 0
Newbie Poster
jdonisthorpe is offline Offline
5 posts
since Dec 2003
Dec 19th, 2003
0

Re: Hijack this log - can't get rid of pop ups

He is Good !But you should go back and post a new log and the content of the file he requested .
Last edited by caperjack; Dec 19th, 2003 at 9:50 pm.
Team Colleague
Reputation Points: 1056
Solved Threads: 792
I hate 20 Questions
caperjack is offline Offline
12,725 posts
since Aug 2003

This thread is solved

Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
This thread is currently closed and is not accepting any new replies.
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: HiJackThis-log for viewing - please help :-)
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: HiJackThis! Results - need assistance.





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC