Hi, annoying showups keep coming back [HJT LOG]

Logfile of HijackThis v1.98.2
Scan saved at 10:42:36 AM, on 3/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\csrss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\System32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\spoolsv.exe
I:\PROGRA~1\Iomega\System32\AppServices.exe
I:\WINDOWS\system32\pctspk.exe
I:\WINDOWS\System32\wdfmgr.exe
I:\Program Files\Iomega\AutoDisk\ADService.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\System32\directs.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\SOUNDMAN.EXE
I:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\program files\ahead\media player\InCD.exe
I:\Program Files\Microsoft Hardware\Mouse\point32.exe
E:\Program Files\Winamp\winampa.exe
I:\WINDOWS\szqf.exe
I:\Program Files\ATI Multimedia\main\launchpd.exe
I:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
I:\WINDOWS\System32\rundll32.exe
D:\Program Files\Steam\Steam.exe
C:\Program Files\AIM\aim.exe
I:\PROGRA~1\COMMON~1\qrzk\qrzkm.exe
I:\PROGRA~1\COMMON~1\qrzk\qrzka.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
I:\WINDOWS\System32\wuauclt.exe
I:\Documents and Settings\Shane\Desktop\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - i:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - I:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - i:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ADUserMon] I:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [Iomega Automatic Backup 1.0.1] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - HKLM\..\Run: [ATIPTA] I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount
O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] I:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [InCD] C:\program files\ahead\media player\InCD.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [szqf] I:\WINDOWS\szqf.exe
O4 - HKCU\..\Run: [ATI Launchpad] "I:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI Remote Control] I:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
O4 - HKCU\..\Run: [Steam] d:\Program Files\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] I:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - HKCU\..\Run: [qrzk] I:\PROGRA~1\COMMON~1\qrzk\qrzkm.exe
O4 - Startup: Registration-INSDVD.lnk = C:\Program Files\Pinnacle\InstantCDDVD\SharedFiles\Pixie\RegTool.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: &Google Search - res://i:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://i:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://i:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://i:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://i:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - I:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - I:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - I:\WINDOWS\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - I:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: I:\Program Files\Internet Explorer\Plugins\NPDocBox.dll


Hello, I've already removed some stuff with Spy Sweeper but they just keep coming back and I need to know exactly what to get rid of because I'm a noob at this. Thanks !

Comments

  • wildthing423wildthing423 Virginia beach, Virginia
    edited March 2005
    Distovol,

    Hi and welcome to the forums. please download the latest version of the program HJT from here...http://www.short-media.com/download.php?d=245 and delete or uninstall the old version , which ever is applicable, and setup or run the new version and post a new log file by replying to your own thread. Please give some more info as to the problems that you are experiencing as this will make it somewhat easier for us to assist you.

    Have a great day.

    Wildthing423
    :Canflag:
  • edited March 2005
    okay, the problems that I am experiencing are things like every 20 minutes, a windows error msg will come up and say qrzka.exe has run into some problems da da da da. That's only when I use IE because i have to either go to an FTP or watch a movie through IE. And also there are some annoying spyware utilities that Spy Sweeper detects running in memory so I gotta reboot up in softmode, however I just need to know which files to get rid of. Thanks for your reply!
    Logfile of HijackThis v1.99.1
    Scan saved at 12:40:23 PM, on 3/31/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    I:\WINDOWS\System32\smss.exe
    I:\WINDOWS\system32\winlogon.exe
    I:\WINDOWS\system32\services.exe
    I:\WINDOWS\system32\lsass.exe
    I:\WINDOWS\System32\Ati2evxx.exe
    I:\WINDOWS\system32\svchost.exe
    I:\WINDOWS\System32\svchost.exe
    I:\WINDOWS\system32\spoolsv.exe
    I:\PROGRA~1\Iomega\System32\AppServices.exe
    I:\WINDOWS\system32\pctspk.exe
    I:\Program Files\Iomega\AutoDisk\ADService.exe
    I:\WINDOWS\system32\Ati2evxx.exe
    I:\WINDOWS\Explorer.EXE
    I:\WINDOWS\SOUNDMAN.EXE
    I:\Program Files\Iomega\AutoDisk\ADUserMon.exe
    C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
    C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
    I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
    C:\program files\ahead\media player\InCD.exe
    I:\Program Files\Microsoft Hardware\Mouse\point32.exe
    E:\Program Files\Winamp\winampa.exe
    I:\Program Files\ATI Multimedia\main\launchpd.exe
    I:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
    I:\WINDOWS\System32\rundll32.exe
    D:\Program Files\Steam\Steam.exe
    C:\Program Files\AIM\aim.exe
    I:\PROGRA~1\COMMON~1\qrzk\qrzkm.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    I:\PROGRA~1\COMMON~1\qrzk\qrzka.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    I:\Documents and Settings\Shane\Desktop\HijackThis.exe

    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - i:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - I:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - i:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ADUserMon] I:\Program Files\Iomega\AutoDisk\ADUserMon.exe
    O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
    O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
    O4 - HKLM\..\Run: [Iomega Automatic Backup 1.0.1] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
    O4 - HKLM\..\Run: [ATIPTA] I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\InstantDrive\InstantDrive.exe /remount
    O4 - HKLM\..\Run: [IW ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
    O4 - HKLM\..\Run: [PinnacleDriverCheck] I:\WINDOWS\System32\PSDrvCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\program files\ahead\media player\InCD.exe
    O4 - HKLM\..\Run: [POINTER] point32.exe
    O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe
    O4 - HKCU\..\Run: [ATI Launchpad] "I:\Program Files\ATI Multimedia\main\launchpd.exe"
    O4 - HKCU\..\Run: [ATI Remote Control] I:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
    O4 - HKCU\..\Run: [Steam] d:\Program Files\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Weather] I:\Program Files\AWS\WeatherBug\Weather.exe 1
    O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
    O4 - HKCU\..\Run: [qrzk] I:\PROGRA~1\COMMON~1\qrzk\qrzkm.exe
    O4 - Startup: Registration-INSDVD.lnk = C:\Program Files\Pinnacle\InstantCDDVD\SharedFiles\Pixie\RegTool.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O8 - Extra context menu item: &Google Search - res://i:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://i:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://i:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://i:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://i:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - I:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - I:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - I:\WINDOWS\web\related.htm
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - I:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
    O12 - Plugin for .spop: I:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1112208979906
    O23 - Service: Ati HotKey Poller - Unknown owner - I:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: FAH@I:+Documents and Settings+Shane+Desktop+FAH502-Console.exe - Unknown owner - I:\Documents and Settings\Shane\Desktop\FAH502-Console.exe (file missing)
    O23 - Service: Iomega App Services - Iomega Corporation - I:\PROGRA~1\Iomega\System32\AppServices.exe
    O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - I:\WINDOWS\system32\pctspk.exe
    O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - I:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
    O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - I:\Program Files\Iomega\AutoDisk\ADService.exe
  • A2IA2I
    edited April 2005
    Hi download

    go to http://housecall.trendmicro.com/housecall/start_corp.asp

    do a full scan of your system.

    afterwards go to http://www.avast.com/eng/down_home.html
    download install, its a virusscanner for free, register 14months active after you can just re-register and so on and so on stays free.

    Download

    http://download.microsoft.com/download/8/1/5/815d2d60-49b5-44dc-ae35-fca2f2c6f0cc/MicrosoftAntiSpywareInstall.exe

    Do a full scan.

    You need to update your windows service pack to sp2

    Download from the following link
    http://www.microsoft.com/downloads/details.aspx?FamilyId=049C9DBE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en

    If you encounter any problems while updating or scanning plz post.

    Ty.
  • edited April 2005
    WOW WHY did you make me download that STUPID avast.com dll stupid spyware program..you tricked me
    wow i trusted this place and now you fools deceived me into freaking downloading more spyware onto my computer. I cannot delete ashshell.dll in the AVAST FOLDER WOW MAN COMEON UR MAKING MY LIFE MISERABLE bro I can't delete it in safe mode nor normal mode. why would you do that? WHY THE HECK would you do that? you force me to reformat.
    thank you short-media for screwing me over
    last time im coming here
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited April 2005
    Distovol,

    Exactly as you stated, Why the heck would we do that?

    Avast is a reputable antivirus program that does NOT contain spyware of any kind. If you want to get rid of it, you must uninstall it from Add/Remove programs. Did you do that?

    You can not get rid of a program just by deleting the folder. If that is what you've done then the problems you've created are your own fault.

    A2I is no longer giving advice at Short-Media, but if you'd like help with your problem I'll be happy to help you out, assuming you can tone down the accusations a bit. :)
Sign In or Register to comment.