I seem to have issues with popups even when the browser is closed. they are IE windows that popup. I have used every remover out there including, adaware, noadware, spybot. nothing gets rid of them. i downloaded hijack this and saved the log. any help would be greatly appreciated.
Thanks
Logfile of HijackThis v1.98.2
Scan saved at 7:33:09 AM, on 3/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\DOWNLO~1\WebEx\
319\atntho
st.exe
C:\WINDOWS\system32\cisvc.
exe
C:\WINDOWS\DOWNLO~1\WebEx\
319\RAAGTA
PP.EXE
C:\WINDOWS\system32\CTsvcC
DA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTEC
T.EXE
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\Program Files\RealVNC\WinVNC\winvn
c.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Ideazon\Zboard Software\Driver\ZboardTray
.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\j2re1.4.2_03\bi
n\jusched.
exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\SBAudigy2ZS
\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS
\DVDAudio\
CTDVDDET.E
XE
C:\WINDOWS\system32\CTHELP
ER.EXE
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\Program Files\Logitech\MouseWare\s
ystem\em_e
xec.exe
C:\windows\system32\fjljpu
.exe
C:\WINDOWS\sixtypopsix.exe
C:\PROGRA~1\AWS\WEATHE~1\W
eather.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Ideazon\Zboard Software\Driver\Zboard.exe
C:\WINDOWS\osk.exe
C:\Documents and Settings\eli\Application Data\snci.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\DOWNLO~1\WebEx\
319\raagtx
.exe
C:\Program Files\Nikon\NkView6\NkvMon
.exe
C:\windows\system32\calc.e
xe
C:\WINDOWS\system32\cidaem
on.exe
C:\WINDOWS\system32\cidaem
on.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\eli\Local Settings\Temp\HijackThis.e
xe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\SYSTEM32\j?vaw.
exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.dell4me.com/mywaybizR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.dell4me.com/mywaybizR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.dell4me.com/mywaybizR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = about:blank
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) = about:blank
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C
2D500688DA
2} - (no file)
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-0
8001100120
0} - C:\WINDOWS\dlmax.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-7
6E68DC4AB2
E} - C:\WINDOWS\systb.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIE
Helper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0
445EE16191
0} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FBF28874-6B99-3612-B1DE-1
A640CAB1B9
3} - C:\WINDOWS\system32\ydw.dl
l
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E
1B4C16F92E
B} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTo
ols\ADVCHK
.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bi
n\jusched.
exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS
\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS
\DVDAudio\
CTDVDDET.E
XE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [xLQErD533] C:\WINDOWS\asbcnak.exe
O4 - HKLM\..\Run: [PeZbyOA.exe] C:\documents and settings\eli\local settings\temp\PeZbyOA.exe
O4 - HKLM\..\Run: [TSL.exe] C:\documents and settings\eli\local settings\temp\TSL.exe
O4 - HKLM\..\Run: [dpuzRA.exe] C:\documents and settings\eli\local settings\temp\dpuzRA.exe
O4 - HKLM\..\Run: [ff117eb17dc9] C:\WINDOWS\system32\ati2ed
xx.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\QdgL.e
xe
O4 - HKLM\..\Run: [upddat'egon] Ad-Aware.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [fjljpu] c:\windows\system32\fjljpu
.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [sixtysix] C:\WINDOWS\sixtypopsix.exe
O4 - HKLM\..\RunServices: [upddat'egon] Ad-Aware.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\W
eather.EXE
1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [Clock] C:\WINDOWS\mshta.exe
O4 - HKCU\..\Run: [Tair] C:\Documents and Settings\eli\Application Data\snci.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Mkw] C:\WINDOWS\system32\l?gonu
i.exe
O4 - Global Startup: MyWebEx PC Agent.LNK = ?
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon
.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear
ch.htm
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZNO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - (no file)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F
0B44B4BD2A
C} - C:\WINDOWS\system32\maxspe
ed.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F
0B44B4BD2A
C} - C:\WINDOWS\system32\maxspe
ed.exe (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~4\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
7D41EF1CB5
2} - C:\PROGRA~1\AWS\WEATHE~1\W
eather.exe
(HKCU)
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-0
0104BD12D9
4} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CABO16 - DPF: {15AD4789-CDB4-47E1-A9DA-9
92EE8E6BAD
6} -
http://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge-c283.cabO16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
C0A30F9028
C} (MiniBugTransporterX Class) -
http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?O16 - DPF: {42F2C9BA-614F-47C0-B3E3-E
CFD34EED65
8} -
http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
060082AA75
C} (GpcContainer Class) -
https://pc.mywebexpc.com/client/v_mywebex-aa/ra/ieatgpc.cabO16 - DPF: {E0CE16CB-741C-4B24-8D04-A
817856E07F
4} -
http://cabs.media-motor.net/cabs/diamond.cabStart Free Trial