New to the group...{solved}

Hi...
I have a Messenger box that pops up, warns of dire consequences if I don't go to the following sites for immediate attention, and says that "This pop-up will disappear if I go to:
URL removed due to malware site
The other sites I am told to go to are:
URL removed due to malware site
regfixiti.com
regpro32.com
registrycleaner.

Logfile of HijackThis v1.99.1
Scan saved at 11:40:52 AM, on 10/5/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Filzip\Filzip.exe
C:\Documents and Settings\Robert Miles\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

Thnks,
Kromedome
(yeah, totally bald...)

Comments

  • jmoney3457jmoney3457 Maine
    edited October 2006
    krome,

    You have HijackThis in your Temp folders, where we do not want it. Please delete them if you can find them, and then follow these instructions:

    Click here to download HJTsetup.exe. Save it to your Desktop!
    • Double click on the HJTsetup.exe icon on your desktop.
    • By default it will install to C:\Program Files\Hijack This.
    • Continue to click Next in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
    • Put a check by Create a desktop icon then click Next again.
    • Continue to follow the rest of the prompts from there.
    • At the final dialogue box click Finish and it will launch Hijack This. please scan again and post new log
  • edited October 2006
    jmoney3457 wrote:
    krome,

    You have HijackThis in your Temp folders, where we do not want it. Please delete them if you can find them, and then follow these instructions:

    Click here to download HJTsetup.exe. Save it to your Desktop!
    • Double click on the HJTsetup.exe icon on your desktop.
    • By default it will install to C:\Program Files\Hijack This.
    • Continue to click Next in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
    • Put a check by Create a desktop icon then click Next again.
    • Continue to follow the rest of the prompts from there.
    • At the final dialogue box click Finish and it will launch Hijack This. please scan again and post new log

    Jmoney 3457
    Thank you for your reply and instructions. I shall do as you suggest and get back with a new HJT scan. You must remember that you're dealing with the seriously brain-deprived, so be patient with me.
    Thanks,
    Krome
  • edited October 2006
    Hi money3457...
    Heah's the new logfile. You from maine? I'm in new hampsha...gotta share a lobsta some day.
    Thank you....
    krome

    Logfile of HijackThis v1.99.1
    Scan saved at 9:03:23 AM, on 10/6/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common

    Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    c:\program files\common

    files\installshield\updateservice\isuspm.exe
    C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
    C:\Documents and Settings\Robert Miles\Desktop\Old HP

    files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
    C:\Program Files\Microsoft Office\Office\WINWORD.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\All

    Users\Desktop\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Local Page =
    N1 - Netscape 4: user_pref("browser.startup.homepage",

    "www.mozilla.com"); (C:\Program

    Files\Netscape\Users\default\prefs.js)
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -

    {8E718888-423F-11D2-876E-00A0C9082467} -

    C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe

    /logon
    O4 - HKLM\..\Run: [AVG7_CC]

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [masqform.exe] C:\Program

    Files\PureEdge\Viewer 6.0\masqform.exe

    -UpdateCurrentUser
    O4 - HKLM\..\Run: [ISUSPM Startup]

    C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe

    -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program

    Files\Common

    Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

    Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program

    Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition]

    "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program

    Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: Related -

    {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

    C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links -

    {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

    C:\WINNT\web\related.htm
    O9 - Extra button: (no name) -

    {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O17 -

    HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0

    BC-605C1E68F384}: NameServer = 64.136.173.5

    64.136.164.77
    O20 - Winlogon Notify: nwprovau -

    C:\WINNT\SYSTEM32\nwprovau.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) -

    GRISOFT, s.r.o. -

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) -

    GRISOFT, s.r.o. -

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative

    Service (dmadmin) - VERITAS Software Corp. -

    C:\WINNT\System32\dmadmin.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) -

    Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
  • jmoney3457jmoney3457 Maine
    edited October 2006
    LOL well hello neighbor:wave: ..where bouts in NH? i live rite outside capital (augusta)...but could you please scan another log only this time when notepad opens click format and make sure wordwrap is NOT checked and post that new log:)
  • edited October 2006
    Morning Money...
    I'm just outside Durham, NH...spent some time at the UNH biomed lab, have a few papers published, ADD research, now working on photon therapy research. Kinda interesting...
    Thank you for the instructions...WILCO,
    K-Dome.
  • edited October 2006
    Logfile of HijackThis v1.99.1
    Scan saved at 8:47:15 AM, on 10/7/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
    C:\Program Files\mozilla.org\Mozilla\mozilla.exe
    C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
    O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

    Money..If this doesn't reproduce properly @ your location,
    do preivate message, request email attachment and I''l comply.
    Thank you.
    The Dome
  • edited October 2006
    Hi Money...
    I just tried to email a reply to a notification from the Forum that I had a response from you...but my email was returned, "Undeliverable." I used the "Short-Media Forums" <shorty@short-media.com> address and tried to attach a non-word wrapped logfile. Sorry...looks like I will have to communicate through this channel. If the logfile still appears unusable to you, kindly email me privately and I will reply with the non-word-wrapped version as an attachment.
    Thanks again,
    Krome
  • jmoney3457jmoney3457 Maine
    edited October 2006
    no prob, log came out fine..unh eh? that's cool I have couple classmates i graduated w/ in 05 goin there-->First download ewido anti-spyware from HERE and save that file to your desktop.
    1. Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Once the setup is complete you will need to run ewido and update the definition files.
    3. On the main screen select the "Update" icon then click "Start Update". The update will start and a progress bar will show the updates being installed.
    4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    Close ewido anti-spyware and reboot your computer into Safe Mode.
    1. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
      IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess.
    2. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan"
    3. Ewido will now begin the scanning process, be patient this may take a little time.
    4. Ewido will list any infections found on the left hand side. When the scan has finished, it should automatically set the recommended action to Quarantine--if not click on Recommended Action and set it there. Click the Apply all actions button. Ewido will display "All actions have been applied" on the right hand side.
    5. Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).
    6. Close ewido & post that report please
  • edited October 2006
    Hi Money...
    I have just returned and executed your instructions. About to run ewido scan...took a while to download, I have a primitive dial-up heah in the boonies. But, we gonna have indoah plumbing next yeah...
    Incidentally, I used ewido some time ago...brought it aboard when I added Grisoft AVG virus software. Don't know why I stopped using it...maybe when I bought Spyware Doctor. Hmmmm, and dumped that...and mebbe that's when the pop-ups started....
    I am too soon old, too late smart....
    Thanks.
    Krome
  • jmoney3457jmoney3457 Maine
    edited October 2006
    kromedome wrote:
    Hi Money...
    I have just returned and executed your instructions. About to run ewido scan...took a while to download, I have a primitive dial-up heah in the boonies. But, we gonna have indoah plumbing next yeah...
    Incidentally, I used ewido some time ago...brought it aboard when I added Grisoft AVG virus software. Don't know why I stopped using it...maybe when I bought Spyware Doctor. Hmmmm, and dumped that...and mebbe that's when the pop-ups started....
    I am too soon old, too late smart....
    Thanks.
    Krome
    no problem heah! lol sorry the mainah in me!..take your time yes dial up is last century but it hasn't gotten to all of the parts yet:)
  • edited October 2006
    Hi Money person...
    Thanks for the patience...here's the ewido scan. I haven't "cleaned" or "fixed" any of these medium security clunks. I'll 'til I hear from you.
    Yeah, I DID have ewido before...prob'ly quit it when they wanted money. I supported grad students for a number of years while we worked together (they worked, I watched...)
    and that's why I have holes in my underwear...been broke ever since! Great bunch of people...they brought the pizza, I supplied the beer and we put out some pretty decent work. Yeah, and I do miss it...
    Thanks...
    The Krome
    AVG Anti-Spyware - Scan Report

    + Created at: 5:27:44 PM 10/7/2006

    + Scan result:



    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.
    :mozilla.53:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Adbrite : Ignored.
    :mozilla.54:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Adbrite : Ignored.
    :mozilla.147:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
    :mozilla.148:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
    :mozilla.185:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
    :mozilla.186:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
    :mozilla.29:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.30:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.31:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.32:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.32:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.33:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.33:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.34:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.35:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
    :mozilla.189:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Adviva : Ignored.
    :mozilla.36:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Atdmt : Ignored.
    :mozilla.110:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Burstnet : Ignored.
    :mozilla.73:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Clickbank : Ignored.
    :mozilla.46:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
    :mozilla.8:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
    :mozilla.25:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Fastclick : Ignored.
    :mozilla.26:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Fastclick : Ignored.
    :mozilla.27:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Fastclick : Ignored.
    :mozilla.115:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.148:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.149:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.167:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.168:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.177:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.178:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.236:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.241:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.242:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.243:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.262:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.75:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
    :mozilla.160:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Liveperson : Ignored.
    :mozilla.161:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Liveperson : Ignored.
    :mozilla.248:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Liveperson : Ignored.
    :mozilla.12:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
    :mozilla.84:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
    :mozilla.113:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
    :mozilla.119:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
    :mozilla.120:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
    :mozilla.121:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
    :mozilla.285:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
    :mozilla.48:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
    :mozilla.49:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Overture : Ignored.
    :mozilla.47:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
    :mozilla.48:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
    :mozilla.49:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
    :mozilla.50:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
    :mozilla.67:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
    :mozilla.68:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
    :mozilla.69:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
    :mozilla.70:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
    :mozilla.45:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
    :mozilla.46:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
    :mozilla.63:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
    :mozilla.64:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
    :mozilla.74:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Specificclick : Ignored.
    :mozilla.75:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Specificclick : Ignored.
    :mozilla.76:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Specificclick : Ignored.
    :mozilla.77:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Specificclick : Ignored.
    :mozilla.65:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
    :mozilla.66:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
    :mozilla.67:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
    :mozilla.71:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
    :mozilla.72:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
    :mozilla.73:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Tacoda : Ignored.
    :mozilla.130:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
    :mozilla.192:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Web-stat : Ignored.
    :mozilla.193:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Web-stat : Ignored.
    :mozilla.180:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
    :mozilla.181:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
    :mozilla.182:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Users50\default\bsh7la2d.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
    :mozilla.55:C:\Documents and Settings\Robert Miles\Application Data\Mozilla\Profiles\default\h1814ba3.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.


    ::Report end
  • jmoney3457jmoney3457 Maine
    edited October 2006
    no problem, yes please go under settings and select quarentine as the recommended action then rescan and post that new log :)
  • edited October 2006
    Hi Money...
    Did the scan...here it is. BUT, sorry to say, the pop-up occurred several times as the scan was taking place...
    Krome
    ******************************************
    AVG Anti-Spyware - Scan Report

    + Created at: 12:21:41 AM 10/8/2006

    + Scan result:



    Nothing found.



    ::Report end
  • edited October 2006
    Money...
    Please excuse my lame brain...here's the highjackthis scan...
    Logfile of HijackThis v1.99.1
    Scan saved at 12:26:10 AM, on 10/8/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
    C:\Program Files\mozilla.org\Mozilla\mozilla.exe
    C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
    O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
  • jmoney3457jmoney3457 Maine
    edited October 2006
    Please perform an online virus scan with F-Secure Online Scanner.

    Please navigate (using Internet Explorer, other browsers won't work) to the following site: http://support.f-secure.com/enu/home/ols3.shtml
    • Click the F-Secure Online Scanner Next Generation Beta link.
    • When prompted, choose to install the software.
    • After the software has installed, click Accept.
    • Click Custom Scan and check the option for Scan inside archives, then click Start.
    • The necessary databases will then be downloaded, and the scan will then start automatically. Please be patient as this scan will take a while to complete.
    • If any infections are found then once the scan has finished the "cleaning" screen will be displayed. Choose Automatic cleaning (recommended).
    • After cleaning has finished, then the Finish screen will be displayed. Choose Show Report.
    • In order to post the report, press CTRL+A on your keyboard to highlight all the text. Then copy and paste that information into this thread, along with a new HijackThis log.
  • edited October 2006
    Hi Money...
    Just returned...will comply with your most recent note.
    Thank you for your kind attention...
    El Dome de Krome
  • edited October 2006
    Hello again Money...
    I just tried to load F-Secure Online Scanner Next Generation Beta. The menu with the small language menu comes up, but the two botton/boxes at the bottom are blank. If I click on the left one, nothing happens. If I click on the right one, the screen snaps back to the F-Secure home user page, and this message...
    *********************************************
    F-Secure Online Scanner Next Generation Beta
    This is the beta version of the next generation of the F-Secure Online Scanner. Please remember this is a beta version and does not yet include all the features. Also note that it does not yet support Windows 98/ME.

    F-Secure Online Scanner Next Generation Beta

    You may send your problem reports and questions to: ols-beta-feedback@f-secure.com

    Best regards,

    F-Secure Online Scanner development team
    *******************************************
    I am unable to download the scanner...
    Ideas???
    Krome
  • jmoney3457jmoney3457 Maine
    edited October 2006
    for the messenger pop ups try this-->Download Shoot The Messenger, and run it. This will block the port that is used to alert you. On that same page you can read about that. also don't worry about the fsecure scan..let me know how the shoot the messenger goes and also please post new HJT log
  • edited October 2006
    Hi Money...
    Shoot the f******g messenger loaded and executed.
    HJT scan follows:
    Logfile of HijackThis v1.99.1
    Scan saved at 4:50:01 PM, on 10/9/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Documents and Settings\Robert Miles\Desktop\Old HP files1\Program Files\Qualcomm\Qualcomm\Eudora\Eudora.exe
    C:\Program Files\mozilla.org\Mozilla\mozilla.exe
    C:\Program Files\Microsoft Office\Office\WINWORD.EXE
    C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4DE03B99-8A6F-4240-B0BC-605C1E68F384}: NameServer = 64.136.173.5 64.136.164.77
    O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

    Thank you...
    Krome
  • jmoney3457jmoney3457 Maine
    edited October 2006
    no problem.. glad Shoot the messenger worked that should take care of those messenger popups..next please fix *check* the following entries in hijackthis! then reboot and post new hjt log (make sure NO windows except for hijackthis! itself is open during the fix of these lines):O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    also hows the pc now?
  • edited October 2006
    Hi Money...
    Here's the HJT! file after Shoot the Messenger assassinated the helpful piece of Microsoft nonsense.
    The "fix" removed the lines you mentioned...

    Logfile of HijackThis v1.99.1
    Scan saved at 5:56:23 PM, on 10/9/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe


    I'll keep you in the loop as I watch the computer over the next few days.
    So, I owe ya a lobsta roll...next time yer in the area, do me an email and I'll grab the wicked witch of the West and we'll meet ya somewhere in Portsmouth.
    I do twenty mile bike rides on my Jamis mountain bike at Pease AFB, Diane tries to keep up but we often wind up at the Spring Hill Tavern for a suds.
    Again, thanks for all the help...I'll keep fingers crossed that we exorcised the sneaky little barsterd...
    Cheers,
    Bob M.
  • jmoney3457jmoney3457 Maine
    edited October 2006
    thank you much :) just 1 last line to fix -->R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = then reboot and post new HJT log with also how the computer is doing:thumbup
  • edited October 2006
    Hi Money...
    Fixed last line, HJT! logfile follows, computer seems to be totally free of the pop-ups. If anything changes, I'll come begging for help...again.
    Really do want to thank you...it was either fix the damn computer or give it a flying lesson.
    Cheers,
    Kromedome

    Logfile of HijackThis v1.99.1
    Scan saved at 10:00:12 PM, on 10/9/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Documents and Settings\All Users\Desktop\Hijackthis\HijackThis.exe

    N1 - Netscape 4: user_pref("browser.startup.homepage", "www.mozilla.com"); (C:\Program Files\Netscape\Users\default\prefs.js)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\All Users\Desktop\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
  • jmoney3457jmoney3457 Maine
    edited October 2006
    your welcome i'll leave this final note of prevention and mark this resolved:thumbsup: -->Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:

    Detect and Remove Programs:
    • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
    • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
    Prevention Programs:
    • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
    • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
    • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
    • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
    • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
    Other necessary Programs:
    • AntiVirus Program<= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kapersky, this is a must have.
    • Firewall<= A firewall is definatley a must have. Two good free versions are Kerio and ZoneLabs.
    • More Secure Browser<= Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
    And also see TonyKlein's good advice
    So how did I get infected in the first place?
This discussion has been closed.