Check this:
Dealing with Unwanted Spyware and Parasites
http://mvps.org/winhelp200
Zee
Main Topics
Browse All TopicsHi,
My computer is full of spyware and adware stuff. So many popups keep coming up....I am so frustrated and annoyed...
I tried lavasoft, spyware doctor, installed Mcfee antiviurs ....nothing worked.
Can anyone tell me a comprehensive way of cleanign up the stuff and make my computer a nice one again????
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Check this:
Dealing with Unwanted Spyware and Parasites
http://mvps.org/winhelp200
Zee
Try the various scanners to verify that your system is clean -
Adaware - http://www.lavasoftusa.com
Spybot S&D - http://www.safer-networkin
Trend Antivirus Online Scanner - http://housecall.trendmicr
CoolWebShredder - http://www.spychecker.com/
ToolBar Cop - http://www.mvps.org/srames
Stinger - http://vil.nai.com/vil/sti
Also, You could also run a scan with HJT to create a log file -
HiJackThis - http://www.spywareinfo.com
Once the log file is created, post it to this site and save the log for analysis-
HJT LogAnalyzer - http://www.hijackthis.de/e
Here is the log file.
Logfile of HijackThis v1.99.1
Scan saved at 2:41:34 PM, on 6/14/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.ex
C:\WINNT\system32\winlogon
C:\WINNT\system32\services
C:\WINNT\system32\lsass.ex
C:\WINNT\system32\svchost.
C:\WINNT\system32\spoolsv.
C:\WINNT\System32\msdtc.ex
C:\WINNT\System32\svchost.
C:\WINNT\System32\llssrv.e
C:\Program Files\Network Associates\Common Framework\FrameworkService
C:\Program Files\Network Associates\VirusScan\Mcshi
C:\Program Files\Network Associates\VirusScan\VsTsk
C:\PROGRA~1\NETWOR~1\COMMO
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\MICROS~3\MSSQL
C:\Program Files\Symantec\Ghost\ngser
D:\Program Files\NMapWin\bin\nmapserv
C:\WINNT\Explorer.EXE
C:\WINNT\system32\regsvc.e
D:\SFU\common\rshsvc.exe
C:\WINNT\system32\MSTask.e
C:\WINNT\system32\atiptaxx
C:\Program Files\Network Associates\VirusScan\SHSTA
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\50\bin\OWSTIMER
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINNT\system32\stisvc.e
C:\Program Files\Nteysna\Vigsny.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\WBEM\Win
C:\PROGRA~1\HEWLET~1\HPSHA
C:\Program Files\Java\jre1.5.0\bin\ju
C:\Program Files\Java\jre1.5.0\bin\ju
C:\WINNT\System32\mspmspsv
C:\WINNT\system32\svchost.
C:\WINNT\system32\Dfssvc.e
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\system32\inetsrv\
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.
C:\Program Files\Common Files\System\MSSearch\Bin\
C:\WINNT\system32\alg.exe
C:\Program Files\GoogleAdBGone\Google
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\stho\cret.exe
C:\softwares\Spyware Doctor\swdoctor.exe
D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Symantec\Ghost\bin\d
C:\Program Files\Symantec\Ghost\bin\r
C:\WINNT\System32\svchost.
C:\WINNT\System32\svchost.
C:\Program Files\PicoZip\PicoZip.exe
C:\Program Files\PicoZip\PicoZip.exe
C:\Program Files\Common Files\Real\Update_OB\RealO
D:\Program Files\Yahoo!\Messenger\yms
C:\softwares\Microsoft AntiSpyware\gcasDtServ.exe
C:\softwares\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\reals
C:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\WINZIP\winzip3
C:\Documents and Settings\administrator.DCM
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {039A0683-EE66-92E9-1CCD-9
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroChec
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTA
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Script] C:\WINNT\system\Backdoor.e
O4 - HKLM\..\Run: [NGServer] C:\Program Files\Symantec\Ghost\ngser
O4 - HKLM\..\Run: [Yzhzmuar] C:\Program Files\Nteysna\Vigsny.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\ju
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.
O4 - HKLM\..\Run: [gcasServ] "C:\softwares\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareClean
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypa
O4 - HKCU\..\Run: [Jwpzw] C:\WINNT\system32\alg.exe
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\Google
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\softwares\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [PicoZip] C:\Program Files\PicoZip\PicoZipTray.
O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Mic
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8
O9 - Extra 'Tools' menuitem: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O16 - DPF: Microsoft WFC Forms Designer - file://I:\VJ98\wfcforms.ca
O16 - DPF: Visual Studio 6 Extensibility Libraries - file://I:\VJ98\vstudio6.ca
O16 - DPF: {74D05D43-3236-11D4-BDCD-0
O16 - DPF: {CAFEEFAC-0014-0000-0003-A
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CS1\Services\T
O17 - HKLM\System\CS1\Services\T
O17 - HKLM\System\CS2\Services\T
O17 - HKLM\System\CS2\Services\T
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.
O23 - Service: Macromedia JRun Admin Server (JRun Admin) - Macromedia Inc. - D:\JRun4\bin\jrunsvc.exe
O23 - Service: Macromedia JRun Default Server (JRun Default) - Macromedia Inc. - D:\JRun4\bin\jrunsvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshi
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTsk
O23 - Service: miniWebServer - Unknown owner - f:\miniWebServer.exe (file missing)
O23 - Service: Symantec Ghost Database Service (ngdbserv) - Symantec Corporation - C:\Program Files\Symantec\Ghost\bin\d
O23 - Service: Symantec Ghost Configuration Server (NGServer) - Symantec Corporation - C:\Program Files\Symantec\Ghost\ngser
O23 - Service: NMap - Unknown owner - D:\Program Files\NMapWin\bin\nmapserv
O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.ex
O23 - Service: Sun App Server 7 Admin Server (domain1:admin-server) (SunAppServer7.0.0_01-doma
O23 - Service: Sun App Server 7 (domain1:server1) (SunAppServer7.0.0_01-doma
Your saved analysis is here:
http://www.hijackthis.de/l
Read it carefully and fix as suggested.
Zee
HijackThis running in temp folder
HijackThis should be run from a permanent place on your hard drive. Please do this first: Go to C: and create a new permanent folder (call it hijackthis). Then put (or download - choose "save" not "run") the hijackthis.exe file in it (You must unzip it if it's zipped). You should now have C:\hijackthis\hijackthis.e
Malicious
These entries have been positively identified as malicious programs. In the HijackThis program, place a check mark next to the following entries.
R3 - Default URLSearchHook is missing
(Description: This will fix the search mechanism in IE.)
O2 - BHO: (no name) - {039A0683-EE66-92E9-1CCD-9
(Description: File of this BHO is missing -- probably a remnant of adware or spyware. OK to remove this entry.)
Suggestions
The following are not necessarily spyware/malware, but we suggest you place a check mark next to the following entries, as these programs may be taking up system resources.
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
(Description: This is the Microsoft MSN Queue Manager. There is disagreement over whether it is spying on you or not. Nevertheless, we suggest you check this entry and remove it. Removing this entry will free up some system resources. more information)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\ju
(Description: Sun Java update scheduler. Checks for updates. Not necessary. Removing this entry will free up a small amount of system resources.)
O4 - HKLM\..\Run: [TkBellExe] \"C:\Program Files\Common Files\Real\Update_OB\reals
(Description: RealPlayer scheduler. Completely unnecessary. Removing this entry will free up a small amount of system resources.)
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
(Description: Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it, and thus should remove this entry. )
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
(Description: WinZip system tray application. Not necessary. Removing this entry will free up a small amount of system resources.)
The above are only comments, please include your own fixes after reading the analysis.
Zee
And next time, please read:
Instructions regarding the handling of HIJACK THIS! logs
http://www.experts-exchang
Good luck,
Zee
Your HJT log isn't too bad - download and run SpyBot to clean up the rest of the mess...
http://www.safer-networkin
Things look pretty clean to me, but you do have all sorts of stuff installed on your system.
Visit housecall for a quick virus check:
http://housecall.trendmicr
If everything's clean, then we need more details as to your exact problems. How about installing XP SP2 and using the FW and pop-up blocker?
Defrag your hard drive too! Accessories > System Tools > Disk Defragmenter.
apart from those i tried
Adaware - http://www.lavasoftusa.com
Yep,
While browsing, all the unwanted windows are coming up, they are not pop-ups. I mean to say, they are coming up automatically even when the system is idle, even when I am not using interent.
And sometimes. the system slows down. When I see the processes, TBPS.exe file accupies whole system resources. I dont know what this is.
Download and install now:
Spyware Blaster
http://www.javacoolsoftwar
Prevents the installation of Active-X based spyware, malware, dialers, etc
Currently protects you against about 3600 nasties.
Advantage: no system resources used!!!
Just download, install and UPDATE.
Zee
I reccomend using Microsoft Anti spyware, its adaware and spybot in 1, works very well.
before installing i'd uninstall all other Anti-spyware software on your machine.
http://www.microsoft.com/a
update the program, enable all the secutiry agents and schedule/run scans regulary.
also your pop ups maybe form the Messenger Service.
follow the instructions on how to stop these pop ups
http://www.microsoft.com/w
also i would replace your hosts file as its porbably full of advert sites
http://www.mvps.org/winhel
downloaded the Hosts file to C:\WINDOWS\SYSTEM32\DRIVER
there should be instructions on the website.
also for a good anti-virus solution get AVG Free - update and scan on a regular basis
http://free.grisoft.com/do
good luck
gcasServ.exe
MS Antispyware Server Process
http://www.liutilities.com
Some users do report it as being a resource hog.
Maybe uninstall and reinstall corrects that for you.
Zee
the system may slow down depending on your system when a Scan is running. i have a top spec PC (1GB Ram etc) and when a spyware scan runs i have no problems, but on older PC's it does slow down considerably.
try disabling the active spyware 'agents' you have running, but ensure you do regular scans!
NB - If these utilities pick things up and remove them, but you find malware reappears after a reboot, disable System Restore, and re-run the tools in Safe Mode (hit f8 during bootup to bring up the menu).
All round tool
----------------
Look at www.ewido.com (download on trial basis) - seems to have worked wonders for a lot of people on this board..!
Make sure your system is patched and up to date
--------------------------
Get hold of Microsoft Security Baseline Analyzer
http://www.microsoft.com/d
To remove viruses
---------------------
Run Stinger on the machine -
http://vil.mcafeesecurity.
A free full AV, Security and Spyware scan is available from http://housecall.trendmicr
To remove spyware
-----------------------
Please use HijackThs for diagnosis:
www.hijackthis.de
Post the logfile to the same webpage for analysis.
Then try SpyBot to clean up the rest of the mess:
http://www.safer-networkin
To troubleshoot startup problems
--------------------------
Autoruns is also useful in working out whether or not something has latched on to your system that shouldn't have:
http://www.sysinternals.co
To disable System Restore Mode
--------------------------
Click the Start button.
Right-click My Computer, and then click Properties.
On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives
Can you provide any update? Did any suggestions help? If you need assistance in closing down the question, visit http://www.experts-exchang
Business Accounts
Answer for Membership
by: GreenandroidPosted on 2005-06-13 at 13:16:08ID: 14205847
There are lots of solutions to your problems, its just a case of trying each, and seeing what works for you.
-Aware-SE- Personal-E dition/300 0- 8022_4-1 0399602.ht ml?tag=lst -0-2
ast-Home-E dition/300 0-2239_4- 1 0375520.ht ml?tag=lst -0-1
Of course, the most obvious answer would be to reformat (and ultimately reinstall your operating system) your hard disk. This will produce the best results, but is the most 'drastic measure'.
First of all, if you have not tried it already, grab yourself a copy of Ad-Aware. This is free and should clean up any adware from your computer. You can get a copy here - http://www.download.com/Ad
The next step is to run a thourough virus scan. Although you have tried Mcfee, i would suggest you try Avast! (which is totally free for home users, and works nicely)! - You can get this here - http://www.download.com/Av
Avast should clean up any spyware/trojans/virus' and remaining spyware on your computor.
Now if you havent already, i would advise you to switch your default internet browser from Internet explorer to something a little more 'secure'. The reason why so much adware and spyware gets installed is because IE allows ActiveX controls to be enabled by default. Spyware and Adware exploits this to get itself installed on your system. Try a browser such as Firefox, which can be downloaded from www.mozilla.com
Before installing firefox, my computor became heavily congested with adware. Having installed it, i have not had a problem since. I hope this helps.
Kind Regards
James