Hi, i have a whole lot of pop ups on my computer whenever i surf the web, i've dl'ed Adaware and spybot sd updated the both and it finds a couple of entries which i end up deleting and removing, although the problems comes back every time i reboot. Any suggestions on what i should do ?

Dani AI

Generated

Persistent pop-ups that return after removal almost always mean an autostarting adware/toolbar component (BHOs, Run keys, services or scheduled tasks) is reinstalling itself at boot. 's suggestion to use HijackThis and 's note about running it from a permanent folder are on target; 's browser-swap idea is also a practical way to reduce exposure while cleaning the system.

Recommended cleanup sequence (do these in order):

  • Isolate the machine from the network (unplug or disable network) to stop further downloads or control traffic.
  • Reboot to Safe Mode (use the OS boot menu) and run updated scanners: an AV plus at least one dedicated anti‑malware/anti‑spyware scanner. Run full scans and let each tool remove what it finds.
  • Run HijackThis from a permanent folder so its backups can be restored. Save the full log (do not paste partial output). Use HijackThis fixes only for items confirmed by experienced helpers — do not delete things unless their purpose is understood.
  • Run an autorun/startup inspector (shows Run keys, services, scheduled tasks and BHOs) and disable clearly malicious entries. Empty temp folders and check the Hosts file and browser add‑on lists.
  • Reboot normally and re-scan. If the same entries reappear, suspect a persistent service, scheduled task, or installer in the Program Files area and investigate those folders and service entries.

Cautions and fallbacks: always create a restore point or export the registry before manual removals. Avoid deleting system-signed items unless verified. If rootkit behavior is suspected or the infection resists multiple removals, back up personal data and consider a repair install or full OS reinstall — this is often faster and safer than chasing a stealthy reinfecter.

When requesting further help, include: OS/version, which scanners were run and their results, a complete HijackThis log saved from a permanent folder, and a short timeline of actions already taken.

Recommended Answers

All 6 Replies

download hijack this from softpedia.com and scan it and post your log here

How about using something other than Internet Explorer, such as Firefox or Mozilla? Works for me.

How about using something other than Internet Explorer, such as Firefox or Mozilla? Works for me.

Yeah mostly 99% of problems relating to malware are caused by bad security using internet explorer and in my opinion mozilla firefox is the better web browser but some people would rather use IE. Just set your security level higher get the google toolbar and make sure you have the most up to date IE.

alright, i just ran hijackthis, what should i remove or do ? Those browsers Firefox or Mozilla .. is it free ? And if it is, where can i dl it ?


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Free Surfer\fs20.exe
C:\WINDOWS\System32\xbjowv.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\SIMONG~1\LOCALS~1\Temp\Rar$EX00.484\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sportsline.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: Setup.Setup1 - {2E65A557-173C-4DE9-860B-28FC5CACA542} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Setup\Setup.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Others\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [freesurfer] C:\Program Files\Free Surfer\fs20.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cabysmo] C:\WINDOWS\System32\xbjowv.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe
O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -

ok you need to save hijack this to your hard drive and post the log exactly as it is you left part out and smushed two partd together.

Hijackthis needs to be in a permanent folder in order for it to save backups (in case something goes wrong), right now you're running it from a temp folder.

You can download Mozilla-Firefox free from here:
http://www.mozilla.org/

To continue using Internet Explorer more safely, make sure it is updated (using Windows Update) and install Spyware Blaster from here:
http://www.zerosrealm.com/index.php?page=downloads

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.