I tried hijackthis will that help with pop ups because im not kidingfor like 20 minutes I got a pop up ever 5 to 15 seconds. I also have Ad-aware and spyware blaster. Is there anything else iI should do?

Dani AI

Generated

This thread shows a very common, persistent-adware pattern: frequent popups, a toolbar and startup entries that keep reappearing. correctly called out a bundled advertising component, and ’s advice about alternate blockers/browsers addresses the immediate nuisance. The short checklist below focuses on stopping autorun re-creation, doing a thorough offline/online cleanup, and recovering safely.

  • Boot into Safe Mode first so most Run/RunOnce autorun entries won’t execute while cleaning; that prevents simple autostart helpers from immediately recreating themselves. (Run and RunOnce Registry Keys — Microsoft).
  • Use a full autorun cataloging tool to find startup items (Run keys, services, scheduled tasks, browser helpers) and disable unknown entries; note full file paths before deleting so removals can be verified. (Autoruns — Sysinternals/Microsoft).
  • Empty temporary folders and browser caches, then run up-to-date on‑demand anti‑malware scans plus a full antivirus pass — many remnants hide in temp or reinstall from leftover helpers. (See Microsoft’s temp-file cleanup guidance and vendor on-demand scanners for current tools). (Delete Temporary Internet Files — Microsoft, Malwarebytes Help Center).
  • Remove unknown toolbars and search helpers through Add/Remove Programs and the browser’s add‑on manager; check Scheduled Tasks and the HOSTS file for tampering. Community removal walkthroughs document common persistence locations and safe manual removal steps. (BleepingComputer removal guides).
  • If the infection resists live cleaning, boot a trusted rescue/rescue-disk environment and scan offline (bootable scanners avoid active malware interference). (Kaspersky Rescue Disk docs).

After cleaning, verify persistence is gone, enable updates/firewall, and treat credentials as potentially exposed — change passwords if there’s evidence of capture and enable multi‑factor authentication where available (current authentication guidance covers compromise-driven password changes). (NIST SP 800-63B). Diagnostic artifacts that help responders are full Autoruns/HijackThis reports plus the on‑demand scanner logs.

Recommended Answers

All 13 Replies

The 3 things at the bottom won't go away ive tried and tried i had 101 other things on it but I got rid of those. Is this bad?

Logfile of HijackThis v1.98.2
Scan saved at 7:58:05 PM, on 8/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\PROGRA~1\HTMPLA~1\axis wait.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINNT\gcesrmpc.exe
C:\docume~1\owner\locals~1\temp\taCQu.exe
C:\WINNT\SM1BG.EXE
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\WINNT\wt\updater\wcmdmgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WebSphere\AppServer\installedApps\cfusion.ear\cfusion.war\WEB-INF\cfusion\db\slserver52\bin\swagent.exe
C:\WebSphere\AppServer\installedApps\cfusion.ear\cfusion.war\WEB-INF\cfusion\db\slserver52\bin\swstrtr.exe
C:\WebSphere\AppServer\installedApps\cfusion.ear\cfusion.war\WEB-INF\cfusion\db\slserver52\bin\swsoc.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
C:\WINNT\System32\gearsec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\System32\Emis.exe
C:\WINNT\System32\Bpr5o82k.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", ""); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ix0hs42o.slt\)
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\System32\Pvd8k13.exe
O4 - HKLM\..\Run: [owns dart] C:\PROGRA~1\HTMPLA~1\axis wait.exe

one of them I can delete but it comes back

spybot search and destroy if using internet explorer then try mozilla which has better pop up blocking tech in it or if u dont want mozilla then get panicware popup stopper. When sp2 is finally released in its full version the internet explorer has a pop up blocking.
One question is this happening while browsing or just connected to the internet?

Our computer is always connected to the internet. We do not have to log on.

You got the peper trojan. Once you run the following tool you may want to post the entire log. You have other stuff that I can see that needs to be removed.

Clear the contents of the following folder in safe mode;
C:\docume~1\owner\locals~1\temp

In order to view these files you may have to select 'show hidden files/folders.' Instructions on how to here.

Uninstal *Mywebsearch* from add remove programs. Also uninstall 'Window Search', 'Window Searching', '', 'LOP SEARCH', 'Browser Enhancer', or 'Ultimate Browser Enhancer' if listed. You may be given a code to insert, do so and reboot when done. If not listed there, run this uninstaller:

Download the PeperFix.exe tool from here:

Click on the PeperFix.exe to launch it.

Click the Find and Fix button.

It will scan the %Systemroot% folder and locate all the peper files. You will be prompted to reboot. Reboot and it will delete the peper files.
Ensure that you are online before starting the fix. Make sure to run the fix twice.

Merged your two threads. Please do not post in more than one forum with the same problem :) . Thank you.

Thank so much!How did I get the peper trojan I have norton and spyware blaster and adaware and hijackthis?

which ones are the same problem

Both issues are spyware related. Peper trojan is bundled with memorywatcher.
From the vendor: "By installing the Memory Watcher Software on your computer, you understand that: (i) Several ADVERTISING CONSOLES may be launched for the duration of time you spend online."

thaks much I gave you a positive rep.

Cool :) . You should still post your entire log when you have completed all of the above.

thats all that showed up i had 101 but they were easily removed so I didnt bother after that it came up with those again and again and woould delete

i am still gettting pop ups there is a blue tool bar on the bottom of my screen when ever I strat internet explorer and i get 1 other pop too is this a different problem?

Edit:nevermind I forgot the 2nd part

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.