Hi eli290,
Further to PeteLong's comments another HijackThis log analyser is available at http://www.help2go.com/mod
Cheers!
Main Topics
Browse All TopicsI seem to have issues with popups even when the browser is closed. they are IE windows that popup. I have used every remover out there including, adaware, noadware, spybot. nothing gets rid of them. i downloaded hijack this and saved the log. any help would be greatly appreciated.
Thanks
Logfile of HijackThis v1.98.2
Scan saved at 7:33:09 AM, on 3/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
C:\WINDOWS\DOWNLO~1\WebEx\
C:\WINDOWS\system32\cisvc.
C:\WINDOWS\DOWNLO~1\WebEx\
C:\WINDOWS\system32\CTsvcC
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTEC
C:\WINDOWS\system32\svchos
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
C:\Program Files\RealVNC\WinVNC\winvn
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Ideazon\Zboard Software\Driver\ZboardTray
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\reals
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\j2re1.4.2_03\bi
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\SBAudigy2ZS
C:\Program Files\Creative\SBAudigy2ZS
C:\WINDOWS\system32\CTHELP
C:\WINDOWS\system32\dla\tf
C:\Program Files\Logitech\MouseWare\s
C:\windows\system32\fjljpu
C:\WINDOWS\sixtypopsix.exe
C:\PROGRA~1\AWS\WEATHE~1\W
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon
C:\Program Files\Ideazon\Zboard Software\Driver\Zboard.exe
C:\WINDOWS\osk.exe
C:\Documents and Settings\eli\Application Data\snci.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\DOWNLO~1\WebEx\
C:\Program Files\Nikon\NkView6\NkvMon
C:\windows\system32\calc.e
C:\WINDOWS\system32\cidaem
C:\WINDOWS\system32\cidaem
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\eli\Local Settings\Temp\HijackThis.e
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\SYSTEM32\j?vaw.
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-0
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-7
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: (no name) - {FBF28874-6B99-3612-B1DE-1
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTo
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bi
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [xLQErD533] C:\WINDOWS\asbcnak.exe
O4 - HKLM\..\Run: [PeZbyOA.exe] C:\documents and settings\eli\local settings\temp\PeZbyOA.exe
O4 - HKLM\..\Run: [TSL.exe] C:\documents and settings\eli\local settings\temp\TSL.exe
O4 - HKLM\..\Run: [dpuzRA.exe] C:\documents and settings\eli\local settings\temp\dpuzRA.exe
O4 - HKLM\..\Run: [ff117eb17dc9] C:\WINDOWS\system32\ati2ed
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\QdgL.e
O4 - HKLM\..\Run: [upddat'egon] Ad-Aware.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [fjljpu] c:\windows\system32\fjljpu
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [sixtysix] C:\WINDOWS\sixtypopsix.exe
O4 - HKLM\..\RunServices: [upddat'egon] Ad-Aware.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\W
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [Clock] C:\WINDOWS\mshta.exe
O4 - HKCU\..\Run: [Tair] C:\Documents and Settings\eli\Application Data\snci.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Mkw] C:\WINDOWS\system32\l?gonu
O4 - Global Startup: MyWebEx PC Agent.LNK = ?
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-0
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-9
O16 - DPF: {17492023-C23A-453E-A040-C
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-E
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hi eli290,
Further to PeteLong's comments another HijackThis log analyser is available at http://www.help2go.com/mod
Cheers!
fix these immediately
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C
(Description: An unknown URL Search Hook.)
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-7
(Description: IEPlugin adware.)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E
(Description: A blank toolbar entry. Possibly an adware toolbar that was removed by an anti-virus or anti-spyware program.)
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
(Description: Viewpoint Manager advertising program.)
O4 - HKLM\..\Run: [PeZbyOA.exe] C:\documents and settings\eli\local settings\temp\PeZbyOA.exe
(Description: Registry key running programs on start-up from user's temporary folder.)
O4 - HKLM\..\Run: [TSL.exe] C:\documents and settings\eli\local settings\temp\TSL.exe
(Description: Registry key running programs on start-up from user's temporary folder.)
O4 - HKLM\..\Run: [dpuzRA.exe] C:\documents and settings\eli\local settings\temp\dpuzRA.exe
(Description: Registry key running programs on start-up from user's temporary folder.)
O4 - HKLM\..\Run: [ff117eb17dc9] C:\WINDOWS\system32\ati2ed
(Description: Unknown trojan/virus.)
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
(Description: Adware downloader - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Stu
O4 - HKCU\..\Run: [Tair] C:\Documents and Settings\eli\Application Data\snci.exe
(Description: PurityScan/ClickSpring adware trojan.)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F
(Description: File of this button is missing -- probably a remnant of adware or spyware. OK to remove this entry.)
O9 - Extra \'Tools\' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F
(Description: File of this button is missing -- probably a remnant of adware or spyware. OK to remove this entry.)
O15 - Trusted Zone: *.media-motor.net
(Description: Search engine hijacker)
O15 - Trusted Zone: *.popuppers.com
(Description: Search engine hijacker)
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-9
(Description: Advertising delivery service.)
C:\windows\system32\fjljpu
C:\WINDOWS\sixtypopsix.exe
C:\Documents and Settings\eli\Application Data\snci.exe
C:\WINDOWS\SYSTEM32\j?vaw.
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-7
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
O4 - HKLM\..\Run: [xLQErD533] C:\WINDOWS\asbcnak.exe
O4 - HKLM\..\Run: [PeZbyOA.exe] C:\documents and settings\eli\local settings\temp\PeZbyOA.exe
O4 - HKLM\..\Run: [TSL.exe] C:\documents and settings\eli\local settings\temp\TSL.exe
O4 - HKLM\..\Run: [dpuzRA.exe] C:\documents and settings\eli\local settings\temp\dpuzRA.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\QdgL.e
O4 - HKLM\..\Run: [fjljpu] c:\windows\system32\fjljpu
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [sixtysix] C:\WINDOWS\sixtypopsix.exe
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-0
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-9
O4 - HKCU\..\Run: [Mkw] C:\WINDOWS\system32\l?gonu
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-E
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A
Ok.... above is what I would remove using HiJaak. And, once you are done removing the entries, prior to rebooting, I'd go to the file locations and make sure the files are deleted.
Then, when you are done, I'd spend some money getting the Pro version of Adaware SE at the very least (if you have not already) and install it. Configure AdWatch to start automatically, and configure it to block popups and block unauthorized installs.
Of course, any good virus scanner these days will help as well (if you dont have one) I use Symantec AV, which helps a lot as well.
That should prevent you from having such problems again.
Hope that helps.
-Peace
Business Accounts
Answer for Membership
by: PeteLongPosted on 2005-03-04 at 04:38:12ID: 13458236
Browser Hijacking/Spyware/Adware/M alware Removal instructions
/Tech/Brow sers/hijac k.htm
ndex.php?l angselect= english
783
Full removal and Prevention instructions are available on my website,
http://www.petenetlive.com
Please don't "Gum up" the TA's here by posting Hijack This Logs
go here and have it analysed.
http://www.hijackthis.de/i
The EE Official Link to info is,
http:Q_20975384.html#10973