Alright... Here's what i've got... Every 5 minutes or so, i get an IE popup. The sites vary, but the most common ones are:
http://www.xzoomy.comhttp://69.20.56.3/yyy10.htmlhttp://69.20.62.53/yyy10.htmlhttp://www.ad-w-a-r-e.com/cgi-bin/PopupV2?ID={
BCA284CF-8
715-4592-B
B7D-456387
DAF378}
http://www.888.com (This one only comes up once, when i first start my computer, as a popup right after I open IE for the first time)
It happens more often when i'm at the computer than when i'm not, or so it seems. That could be me just noticing it more and getting pissed off.
My full (Yes, full) Hijack this log:
Logfile of HijackThis v1.98.2
Scan saved at 1:17:42 PM, on 9/21/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\rundll
32.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSP
Sv.exe
D:\D-Tools\daemon.exe
D:\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Exe Files\HijackThis.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\D-Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [AIM] D:\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
2.dll/cmtr
ans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - D:\AIM\aim.exe
O17 - HKLM\System\CCS\Services\T
cpip\..\{4
63189F6-44
A5-442F-86
A3-2EDCF77
57BA0}: NameServer = 128.115.25.3,130.203.1.4
I looked around and found that some people with the yyy10.html popups had something called VX2.betterinternet. I downloaded a fix for that (VX2Finder.exe), ran it and it found a key, but no files to delete. Here's the log from that.
Log for VX2.BetterInternet File Finder
Files Found---
Guardian Key--- is called:
User Agent String---
{BCA284CF-8715-4592-BB7D-4
56387DAF37
8}
That user agent string is the same ID that's in the URL for one of the popups, so i know they're linked somehow. VX2Finder gives me 2 options, Restore Policy and User Agent$, and neither of them do anything. I've run a virus scan locally, from housecall.trendmicro.com, run the latest Hijackthis, CWShredder, Spybot, and Adaware all in safe mode. Nothing seems to stick out. 500 points for this, as it's REALLY bothering me. Please help!
Start Free Trial