I am receiving many pops up, even after running Ad-Aware and Spy-Bot. I downloaded and ran hijackthis. The log is below. If anyone can assist with the removal of spyware, it would be greatly appreciated and worth 200 points.
*NOTE - I removed IP and Domain related information at the bottom of the log. It has been replaced by XXX.
Logfile of HijackThis v1.97.7
Scan saved at 5:03:55 PM, on 6/1/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\system32\rundll
32.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\PROGRA~1\ThinkPad\UTILI
T~1\TP98TR
AY.EXE
C:\Program Files\ThinkPad\ConnectUtil
ities\QCWL
ICON.EXE
C:\Program Files\ThinkPad\Utilities\T
pKmapMn.ex
e
C:\PROGRA~1\ThinkPad\UTILI
T~1\NPDTra
y.exe
C:\PROGRA~1\ThinkPad\UTILI
T~1\EzEjMn
Ap.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Documents and Settings\dwinsey\Desktop\H
ijackThis.
exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAg
ent] rundll32.exe irprops.cpl,,BluetoothAuth
entication
Agent
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILI
T~1\TP98TR
AY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtil
ities\QCWL
ICON.EXE
O4 - HKLM\..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\T
pKmapMn.ex
e
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [NPDTray] C:\PROGRA~1\ThinkPad\UTILI
T~1\NPDTra
y.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILI
T~1\EzEjMn
Ap.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKLM\..\Run: [StorageGuard] "c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: startup.bat
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmtr
ans.html
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {02BCC737-B171-4746-94C9-0
D8A0B2C008
9} (Microsoft Office Template and Media Control) -
http://office.microsoft.com/templates/ieawsdc.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37972.4513425926O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = xxx.com
O17 - HKLM\Software\..\Telephony
: DomainName = xxx.com
O17 - HKLM\System\CCS\Services\T
cpip\..\{F
C2ECAD3-BE
3D-430C-8F
7C-110130A
5192C}: NameServer = x.x.x.x.x,x.x.x.x
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = XXX.com
Start Free Trial