i've been frantically going over the posts trying to find a solution to this.
im a college student running windows xp on a dell desktop. yesterday i installed dc++ to see what all the hype was about. then, today out of nowhere i come back to the computer and have about 16 pop up ads. im getting about 20 ads an hour on average just popping up on the desktop. i just got 3 as i typed thus far.
i ran adaware and spybot, found many troublesome things and deleted them, but without success. i noticed that you guys like to look at the HijackThis log file, so i downloaded it and heres mine....
Logfile of HijackThis v1.97.5
Scan saved at 1:09:07 AM, on 2/24/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCE
S.EXE
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\LEXMAR~1\ACMon
itor_X73.e
xe
C:\PROGRA~1\LEXMAR~1\AcBtn
Mgr_X73.ex
e
C:\Program Files\Common Files\Logitech\QCDriver3\L
VCOMS.EXE
C:\WINDOWS\System32\hkcmd.
exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Multimedia\main\ATISched.E
XE
C:\Documents and Settings\sean rainaldi\Application Data\nwai.exe
C:\WINDOWS\System32\wintsv
it.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEED
D~1\nopdb.
exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\sean rainaldi\Desktop\hijackthi
s\HijackTh
is.exe
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = 12.102.181.123:80
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
O2 - BHO: Zero Popup - {2EF37A01-884F-11d5-AC99-B
112050ECB4
F} - C:\PROGRA~1\ZEROPO~1\ZERO-
P~1.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
09B6AD74AC
C} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMon
itor_X73.e
xe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtn
Mgr_X73.ex
e
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\pri
ntray.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\L
VCOMS.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio
\ISStart.e
xe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio
\LogiTray.
exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~2\AdvTo
ols\ADVCHK
.EXE
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.E
XE
O4 - HKCU\..\Run: [Mabc] C:\Documents and Settings\sean rainaldi\Application Data\nwai.exe
O4 - HKCU\..\Run: [WCPI] C:\WINDOWS\System32\wintsv
it.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.e
xe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
LDMConf.ex
e
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: ATI TV (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: ConferenceRoom Java Client -
http://chat.privatefeeds.com:8000/java/cr.cabO16 - DPF: Yahoo! Checkers -
http://download.games.yahoo.com/games/clients/y/kt3_x.cabO16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/games/clients/y/ct0_x.cabO16 - DPF: Yahoo! Dominoes -
http://download.games.yahoo.com/games/clients/y/dot2_x.cabO16 - DPF: Yahoo! Dots -
http://download.games.yahoo.com/games/clients/y/dtt1_x.cabO16 - DPF: Yahoo! Fleet -
http://download.games.yahoo.com/games/clients/y/fltt0_x.cabO16 - DPF: Yahoo! Go -
http://download.games.yahoo.com/games/clients/y/gt1_x.cabO16 - DPF: Yahoo! Graffiti -
http://download.games.yahoo.com/games/clients/y/grt1_x.cabO16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/potb_x.cabO16 - DPF: Yahoo! Pyramids -
http://download.games.yahoo.com/games/clients/y/pyt0_x.cabO16 - DPF: Yahoo! Toki Toki Boom -
http://download.games.yahoo.com/games/clients/y/vtj_x.cabO16 - DPF: Yahoo! Trivia -
http://download.games.yahoo.com/games/clients/y/tvt0_x.cabO16 - DPF: Yahoo! Word Racer -
http://download.games.yahoo.com/games/clients/y/wt0_x.cabO16 - DPF: {01A88BB1-1174-41EC-ACCB-9
63509EAE56
B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CABO16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {11260943-421B-11D0-8EAC-0
000C07D88C
F} (iPIX ActiveX Control) -
http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://207.188.7.150/11b35e3707cb3a17d105/netzip/RdxIE6.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37862.5286458333O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
0105AA9B6A
E} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {CD17FAAA-17B4-4736-AAEF-4
36EDC304C8
C} (ContentAuditX Control) -
http://a840.g.akamai.net/7/840/5805/v1503/www.contentwatch.com/audit/includes/ContentAuditControl.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {E855A2D4-987E-4F3B-A51C-6
4D10A7E247
9} (EPSImageControl Class) -
http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cabthis is Greek to me, but you know what to look for. btw just got 4 more pop-ups
if you guys can help that would be awesome
Start Free Trial