New to the group...{solved}
Hi...
I have a Messenger box that pops up, warns of dire consequences if I don't go to the following sites for immediate attention, and says that "This pop-up will disappear if I go to:
URL removed due to malware site
The other sites I am told to go to are:
URL removed due to malware site
regfixiti.com
regpro32.com
registrycleaner.
Logfile of HijackThis v1.99.1
Scan saved at 11:40:52 AM, on 10/5/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Filzip\Filzip.exe
C:\Documents and Settings\Robert Miles\Local Settings\Temp\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Thnks,
Kromedome
(yeah, totally bald...)
I have a Messenger box that pops up, warns of dire consequences if I don't go to the following sites for immediate attention, and says that "This pop-up will disappear if I go to:
URL removed due to malware site
The other sites I am told to go to are:
URL removed due to malware site
regfixiti.com
regpro32.com
registrycleaner.
Logfile of HijackThis v1.99.1
Scan saved at 11:40:52 AM, on 10/5/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Filzip\Filzip.exe
C:\Documents and Settings\Robert Miles\Local Settings\Temp\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Thnks,
Kromedome
(yeah, totally bald...)
0
This discussion has been closed.
Comments
You have HijackThis in your Temp folders, where we do not want it. Please delete them if you can find them, and then follow these instructions:
Click here to download HJTsetup.exe. Save it to your Desktop!
Jmoney 3457
Thank you for your reply and instructions. I shall do as you suggest and get back with a new HJT scan. You must remember that you're dealing with the seriously brain-deprived, so be patient with me.
Thanks,
Krome
Heah's the new logfile. You from maine? I'm in new hampsha...gotta share a lobsta some day.
Thank you....
krome
Logfile of HijackThis v1.99.1
Scan saved at 9:03:23 AM, on 10/6/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common
Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
c:\program files\common
files\installshield\updateservice\isuspm.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\Documents and Settings\Robert Miles\Desktop\Old HP
files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\All
Users\Desktop\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Local Page =
N1 - Netscape 4: user_pref("browser.startup.homepage",
"www.mozilla.com"); (C:\Program
Files\Netscape\Users\default\prefs.js)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -
{8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe
/logon
O4 - HKLM\..\Run: [AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program
Files\PureEdge\Viewer 6.0\masqform.exe
-UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe
-startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program
Files\Common
Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program
Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition]
"C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINNT\web\related.htm
O9 - Extra button: (no name) -
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O17 -
HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0
BC-605C1E68F384}: NameServer = 64.136.173.5
64.136.164.77
O20 - Winlogon Notify: nwprovau -
C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) -
GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) -
GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative
Service (dmadmin) - VERITAS Software Corp. -
C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) -
Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
I'm just outside Durham, NH...spent some time at the UNH biomed lab, have a few papers published, ADD research, now working on photon therapy research. Kinda interesting...
Thank you for the instructions...WILCO,
K-Dome.
Scan saved at 8:47:15 AM, on 10/7/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Money..If this doesn't reproduce properly @ your location,
do preivate message, request email attachment and I''l comply.
Thank you.
The Dome
I just tried to email a reply to a notification from the Forum that I had a response from you...but my email was returned, "Undeliverable." I used the "Short-Media Forums" <shorty@short-media.com> address and tried to attach a non-word wrapped logfile. Sorry...looks like I will have to communicate through this channel. If the logfile still appears unusable to you, kindly email me privately and I will reply with the non-word-wrapped version as an attachment.
Thanks again,
Krome
- Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
- Once the setup is complete you will need to run ewido and update the definition files.
- On the main screen select the "Update" icon then click "Start Update". The update will start and a progress bar will show the updates being installed.
- Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
- Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
- Under "Reports"
- Select "Automatically generate report after every scan"
- Un-Select "Only if threats were found"
Close ewido anti-spyware and reboot your computer into Safe Mode.IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess.
I have just returned and executed your instructions. About to run ewido scan...took a while to download, I have a primitive dial-up heah in the boonies. But, we gonna have indoah plumbing next yeah...
Incidentally, I used ewido some time ago...brought it aboard when I added Grisoft AVG virus software. Don't know why I stopped using it...maybe when I bought Spyware Doctor. Hmmmm, and dumped that...and mebbe that's when the pop-ups started....
I am too soon old, too late smart....
Thanks.
Krome
Thanks for the patience...here's the ewido scan. I haven't "cleaned" or "fixed" any of these medium security clunks. I'll 'til I hear from you.
Yeah, I DID have ewido before...prob'ly quit it when they wanted money. I supported grad students for a number of years while we worked together (they worked, I watched...)
and that's why I have holes in my underwear...been broke ever since! Great bunch of people...they brought the pizza, I supplied the beer and we put out some pretty decent work. Yeah, and I do miss it...
Thanks...
The Krome
AVG Anti-Spyware - Scan Report
+ Created at: 5:27:44 PM 10/7/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.
:mozilla.53:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.54:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.147:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.148:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.185:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.186:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.29:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.30:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.31:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.32:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.32:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.33:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.33:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.34:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.35:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.189:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Adviva : Ignored.
:mozilla.36:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Atdmt : Ignored.
:mozilla.110:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.73:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Clickbank : Ignored.
:mozilla.46:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.8:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.25:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.26:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.27:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.115:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.148:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.149:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.167:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.168:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.177:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.178:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.236:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.241:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.242:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.243:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.262:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.75:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.160:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.161:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.248:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.12:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.84:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.113:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.119:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.120:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.121:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.285:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.48:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.49:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.47:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.48:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.49:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.50:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.67:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.68:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.69:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.70:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.45:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.46:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.63:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.64:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.74:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.75:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.76:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.77:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.65:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.66:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.67:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.71:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.72:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.73:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.130:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.192:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Web-stat : Ignored.
:mozilla.193:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Web-stat : Ignored.
:mozilla.180:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.181:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.182:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.55:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
::Report end
Did the scan...here it is. BUT, sorry to say, the pop-up occurred several times as the scan was taking place...
Krome
******************************************
AVG Anti-Spyware - Scan Report
+ Created at: 12:21:41 AM 10/8/2006
+ Scan result:
Nothing found.
::Report end
Please excuse my lame brain...here's the highjackthis scan...
Logfile of HijackThis v1.99.1
Scan saved at 12:26:10 AM, on 10/8/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Please navigate (using Internet Explorer, other browsers won't work) to the following site: http://support.f-secure.com/enu/home/ols3.shtml
Just returned...will comply with your most recent note.
Thank you for your kind attention...
El Dome de Krome
I just tried to load F-Secure Online Scanner Next Generation Beta. The menu with the small language menu comes up, but the two botton/boxes at the bottom are blank. If I click on the left one, nothing happens. If I click on the right one, the screen snaps back to the F-Secure home user page, and this message...
*********************************************
F-Secure Online Scanner Next Generation Beta
This is the beta version of the next generation of the F-Secure Online Scanner. Please remember this is a beta version and does not yet include all the features. Also note that it does not yet support Windows 98/ME.
F-Secure Online Scanner Next Generation Beta
You may send your problem reports and questions to: ols-beta-feedback@f-secure.com
Best regards,
F-Secure Online Scanner development team
*******************************************
I am unable to download the scanner...
Ideas???
Krome
Shoot the f******g messenger loaded and executed.
HJT scan follows:
Logfile of HijackThis v1.99.1
Scan saved at 4:50:01 PM, on 10/9/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Thank you...
Krome
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) also hows the pc now?
Here's the HJT! file after Shoot the Messenger assassinated the helpful piece of Microsoft nonsense.
The "fix" removed the lines you mentioned...
Logfile of HijackThis v1.99.1
Scan saved at 5:56:23 PM, on 10/9/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
I'll keep you in the loop as I watch the computer over the next few days.
So, I owe ya a lobsta roll...next time yer in the area, do me an email and I'll grab the wicked witch of the West and we'll meet ya somewhere in Portsmouth.
I do twenty mile bike rides on my Jamis mountain bike at Pease AFB, Diane tries to keep up but we often wind up at the Spring Hill Tavern for a suds.
Again, thanks for all the help...I'll keep fingers crossed that we exorcised the sneaky little barsterd...
Cheers,
Bob M.
Fixed last line, HJT! logfile follows, computer seems to be totally free of the pop-ups. If anything changes, I'll come begging for help...again.
Really do want to thank you...it was either fix the damn computer or give it a flying lesson.
Cheers,
Kromedome
Logfile of HijackThis v1.99.1
Scan saved at 10:00:12 PM, on 10/9/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe
N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Detect and Remove Programs:
- How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
- How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
Prevention Programs:- Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
- Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
- IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
- MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
- Google Toolbar <= Get the free google toolbar to help stop pop up windows.
Other necessary Programs:- AntiVirus Program<= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kapersky, this is a must have.
- Firewall<= A firewall is definatley a must have. Two good free versions are Kerio and ZoneLabs.
- More Secure Browser<= Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
And also see TonyKlein's good adviceSo how did I get infected in the first place?