Hi,
Recently my machine has been infiltrated with spyware pop-ups. I've ran SpyBot & Ad-aware which found a lot of entries. I've removed everthing they've found. However, still having a problem with a Pop-Up that says in the title bar is from a company called z1.adserver.com. Can't find anything about them on the net. I've ran HiJackThis and below are the contents of the log file.
Logfile of HijackThis v1.99.0
Scan saved at 5:54:56 PM, on 1/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
C:\WINDOWS\System32\hkcmd.
exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.10
01\en-us\m
snappau.ex
e
C:\WINDOWS\system32\d?dpla
y.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Brian\LOCALS~1
\Temp\Temp
orary Directory 1 for hijackthis[1].zip\HijackTh
is.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://news.bbc.co.uk/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-4
74BF36AF6E
4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en
-xu\stmain
.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en
-us\msntb.
dll
O2 - BHO: (no name) - {FAE2E03B-748E-7829-D13A-0
5C5387B40E
1} - C:\WINDOWS\System32\dps.dl
l
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en
-us\msntb.
dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCt
r\Binaries
\MSConfig.
exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
2.dll/cmtr
ans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: DigiChat Applet -
http://host7.digichat.com/DigiChat/DigiClasses/Client_IE.cabO16 - DPF: {0F9B4CA4-A30F-480A-841D-6
9B45C50A8F
8} (SekureL0gin.SekureKontrol
) -
http://secure2.comned.com/signuptemplates/AktiveSekurity.cabO16 - DPF: {205FF73B-CA67-11D5-99DD-4
4455354000
6} (CInstall Class) -
http://www.errorguard.com/installation/Install.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093123078437O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0
010DC2A624
3} (SecureLogin.SecureControl
) -
http://secure2.comned.com/signuptemplates/ActiveSecurity.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-5
95F0A5519F
F} (MsnMessengerSetupDownload
Control Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cabO23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Symantec AntiVirus Client - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
Any Help