Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Pop-Ups won't go away. Please Help! Log posted [RESOLVED]


  • This topic is locked This topic is locked

#1
kookypelli

kookypelli

    New Member

  • Member
  • Pip
  • 5 posts
Can someone please help? I have this pop-ups issue with searc-h.com, tagasaurus, etc. Lots of ads every 5 secs or so. Driving me crazy --I can't work online. I suspect there may be more than two culprits, here. I ran spybot, ad-aware and Avast to no avail. Here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 9:56:39 AM, on 9/20/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\HPSJVXD.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
E:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYS0266554577-6.EXE
C:\WINDOWS\SYSCHECKBOP32.EXE
C:\PROGRAM FILES\TAGASAURUS\TAGASAURUS.EXE
C:\PROGRAM FILES\COMMON FILES\TSA\TSL2.EXE
C:\WINDOWS\SYSCHECKBOP32.EXE
C:\SCANJET\PRECISIONSCAN\HPPPT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\WUCRTUPD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\HPZSTATX.EXE
F:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS13
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [HP CD-Writer] C:\Program Files\HP CD-Writer\Mmenu\hpcdtray.exe
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [HPSCANMonitor] c:\windows\SYSTEM\hpsjvxd.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [sys0266554577-6] C:\WINDOWS\sys0266554577-6.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SYSCHECKBOP32
O4 - HKLM\..\Run: [TagASaurus] C:\PROGRAM FILES\TAGASAURUS\TAGASAURUS
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\TSA\tsl2.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU\..\Run: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
O4 - HKCU\..\RunServices: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
O4 - Startup: HP Parallel Port Test.lnk = C:\SCANJET\PrecisionScan\hpppt.exe
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com...ior/Outside.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://remotemail.r...com/iNotes6.cab

Can someone please pull me out of this? Thanks in advance...
  • 0

Advertisements


#2
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Please print out these instructions or copy them into a text file on your Desktop for easy access.

During the fix, u will be asked to fix some entries, delete some files or uninstall some programs. If in case, you do not see those entries / files / programs, please make a note of it. Continue with the fix and in your next post please inform me of all deviations from the fix prescribed.

1. Download Programs

Please download these programs and save them in a new folder on your desktop -

CleanUp


2. Run Hijack This

Run Hijack This and click on scan. The following items need to be fixed -

O4 - HKLM\..\Run: [sys0266554577-6] C:\WINDOWS\sys0266554577-6.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SYSCHECKBOP32
O4 - HKLM\..\Run: [TagASaurus] C:\PROGRAM FILES\TAGASAURUS\TAGASAURUS
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\TSA\tsl2.exe
O4 - HKCU\..\Run: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
O4 - HKCU\..\RunServices: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe


Close all windows other than Hijack This. Check the boxes next to above items and click on Fix checked.

Restart the PC in Safe Mode (repeatedly tap the F8 key when the PC is starting up).

3. Delete Rogue files

Run CleanUp and delete all temp files including temporary internet files

Open Windows Explorer (right click on Start and then click on explore). Locate and delete the following folders and files -

Folders
C:\PROGRAM FILES\TAGASAURUS

Files
C:\WINDOWS\sys0266554577-6.exe
C:\WINDOWS\SYSCHECKBOP32
C:\WINDOWS\SysCheckBop32.exe
C:\WINDOWS\SysCheckBop32.exe
C:\PROGRA~1\COMMON~1\TSA\tsl2.exe


Reboot the PC in Normal Mode.

Please visit Panda and do an online scan. Save the scan report.

Run Hijack This and post a fresh HJT log along with Panda scan report.
  • 0

#3
kookypelli

kookypelli

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Ok...took me forever 'cause pop-us from searc-h.com STILL kept coming up among other things. Also, comehow think this is related to my computer internet hanging-up with the rundll32 command in the task box. Anyway, here is the Panda scan (yikes!)


Incident Status Location

Adware:adware/mssearch No disinfected C:\WINDOWS\SYSTEM\toolbar.exe
Adware:adware/gator No disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\HDPlugin1018.dll
Spyware:spyware/betterinet No disinfected C:\WINDOWS\INF\BIINI.INF
Adware:adware/searchaid No disinfected C:\WINDOWS\dict.dat
Adware:adware/tvmedia No disinfected C:\WINDOWS\cmuninstall.bat
Spyware:spyware/bargainbuddy No disinfected C:\WINDOWS\bbchk.exe
Adware:adware/adurl No disinfected C:\WINDOWS\icont.exe
Adware:adware/sahagent No disinfected C:\WINDOWS\unstall.exe
Adware:adware/xupiter No disinfected C:\PROGRAM FILES\COMMON FILES\OE
Adware:adware/delfinmedia No disinfected C:\WINDOWS\SYSTEM\nsvsvc
Adware:adware/savenow No disinfected C:\WINDOWS\ALL USERS\APPLICATION DATA\nsv
Adware:adware/cws No disinfected Windows Registry
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OTMREG.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SMMEDEA.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DTLAY.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SGCUR32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ANFSIPC.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DVWAVE.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SCNDMAIL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mHg_hook.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\HYSJINST.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AZFXRN32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\py.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WSSAPD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AODEVL16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UpdInst.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mxsr13n.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\GDPI32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\pep.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SMTUPAPI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\eyhsig.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MGNSSPC.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\madart32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\NMSWAN16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mefs13n.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\izl_gif.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MVRATELC.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OQGAPI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\pbcrt.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\lkgif11n.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\pwp.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MKWEBDVD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DKNDI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\HTAGENT.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MIPIU.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AYRESX32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ROCLTC6.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MCVIDC32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MMFS32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OUE32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IXHRCNV.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\PZPD32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\icl_libz.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WDCTHUNK.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RHANP.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mnssouri.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UADM16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\caral.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IPUSIC25.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AYRNDR32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CAJUI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MCTCP.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ABLFT332.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\NNNET32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CCJSETUP.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\FUE.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\VJ4EN16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\dnmasf.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\iqetcfg.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mzexcl40.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ldtif11n.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\izetres.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CCT32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DPIMAN32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MUSHRUI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ICSTRSA.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\llkrn70n.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MLPI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OSBCTL32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UJDM16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\zncomm.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RKVPSP.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RXASIG.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\in50_qc.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\iwetcfg.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AAUTIL32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\FA20ENU.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\LWEXPAND.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MHR2C.DLL
Adware:Adware/SearchTheWeb No disinfected C:\WINDOWS\SYSTEM\skytown.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CXDBControlRoxio.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\GgacView.dll
Adware:Adware/AlwaysupdatednewsNo disinfected C:\WINDOWS\FONTS\shopinst.exe
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\INF\banner.inf
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\HDPlugin1100.dll
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Downloaded Program Files\installer_PIVOTAL_5_DB.exe
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\banner.dll
Spyware:Spyware/Relevancy No disinfected C:\Program Files\HiJack This\backups\backup-20041228-231642-734.dll
Adware:Adware/MediaTickets No disinfected F:\HiJackThis\backups\backup-20050816-234902-873.dll
Adware:Adware/IST.YourSiteBar No disinfected F:\HiJackThis\backups\backup-20050816-234903-369.dll
Adware:Adware/IST.YourSiteBar No disinfected F:\HiJackThis\backups\backup-20050818-173527-225.dll
Adware:Adware/StartPage.AHW No disinfected


And, here is the new Hi-Jack This Log.
Logfile of HijackThis v1.99.1
Scan saved at 12:14:17 PM, on 9/20/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\HPSJVXD.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
E:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\SCANJET\PRECISIONSCAN\HPPPT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
F:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS13
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [HP CD-Writer] C:\Program Files\HP CD-Writer\Mmenu\hpcdtray.exe
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [HPSCANMonitor] c:\windows\SYSTEM\hpsjvxd.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - Startup: HP Parallel Port Test.lnk = C:\SCANJET\PrecisionScan\hpppt.exe
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com...ior/Outside.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://remotemail.r...com/iNotes6.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab

What's next to get rid of the pop-ups? Also, thanks for your help.
  • 0

#4
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Hi,

You have a bunch of infections on your PC. So need to tackle them in different stages. Here is the next stage.

Delete the following files -

C:\WINDOWS\dict.dat
C:\WINDOWS\cmuninstall.bat
C:\WINDOWS\bbchk.exe
C:\WINDOWS\icont.exe
C:\WINDOWS\unstall.exe
C:\WINDOWS\banner.dll

C:\WINDOWS\SYSTEM\toolbar.exe
C:\WINDOWS\SYSTEM\skytown.exe
C:\WINDOWS\INF\BIINI.INF
C:\WINDOWS\INF\banner.inf

C:\WINDOWS\FONTS\shopinst.exe

C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll
C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll
C:\WINDOWS\Downloaded Program Files\HDPlugin1100.dll
C:\WINDOWS\Downloaded Program Files\installer_PIVOTAL_5_DB.exe
C:\WINDOWS\DOWNLOADED PROGRAM FILES\HDPlugin1018.dll


Delete the following folders -

C:\PROGRAM FILES\COMMON FILES\OE
C:\WINDOWS\SYSTEM\nsvsvc
C:\WINDOWS\ALL USERS\APPLICATION DATA\nsv


Please download L2m9xfix here:
http://swandog46.gee...om/l2m9xfix.exe

Save it to the desktop and run it. Extract the files, and then open the l2m9xfix folder you just created and run RunThis.bat.

A window will open, and your desktop will disappear, then reappear. Please be patient until the batch says it is completed.

Then please restart your computer, and post a new HijackThis log as well as the entire text of the log.txt file which should be in the same folder as RunThis.bat.

Edited by tampabelle, 20 September 2005 - 02:40 PM.

  • 0

#5
kookypelli

kookypelli

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
OK - so did everything. Only the following that you mentioned, I could not find on my system at all:

C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll
C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll
C:\WINDOWS\Downloaded Program Files\HDPlugin1100.dll
C:\WINDOWS\Downloaded Program Files\installer_PIVOTAL_5_DB.exe
C:\WINDOWS\DOWNLOADED PROGRAM FILES\HDPlugin1018.dll

Also - through the process, I still had pop-ups so I'm guessing I'm not done, yet. Here's the log file from the 12m9xfix.exe:
Log of L2M9XFix v1.01a

************

Running from directory:
C:\WINDOWS\Desktop\l2m9xfix

************

Files found:

C:\WINDOWS\system\AAUTIL32.DLL
C:\WINDOWS\system\ABLFT332.DLL
C:\WINDOWS\system\ANFSIPC.DLL
C:\WINDOWS\system\AODEVL16.DLL
C:\WINDOWS\system\AYRESX32.DLL
C:\WINDOWS\system\AYRNDR32.DLL
C:\WINDOWS\system\AZFXRN32.DLL
C:\WINDOWS\system\CAJUI.DLL
C:\WINDOWS\system\caral.dll
C:\WINDOWS\system\CCJSETUP.DLL
C:\WINDOWS\system\CCT32.DLL
C:\WINDOWS\system\CXDBControlRoxio.dll
C:\WINDOWS\system\DKNDI.DLL
C:\WINDOWS\system\dnmasf.dll
C:\WINDOWS\system\DTLAY.DLL
C:\WINDOWS\system\DVWAVE.DLL
C:\WINDOWS\system\eyhsig.dll
C:\WINDOWS\system\FA20ENU.DLL
C:\WINDOWS\system\FUE.DLL
C:\WINDOWS\system\GDPI32.DLL
C:\WINDOWS\system\GgacView.dll
C:\WINDOWS\system\HTAGENT.DLL
C:\WINDOWS\system\HYSJINST.DLL
C:\WINDOWS\system\icl_libz.dll
C:\WINDOWS\system\ICSTRSA.DLL
C:\WINDOWS\system\in50_qc.dll
C:\WINDOWS\system\IPUSIC25.DLL
C:\WINDOWS\system\iqetcfg.dll
C:\WINDOWS\system\iwetcfg.dll
C:\WINDOWS\system\IXHRCNV.DLL
C:\WINDOWS\system\izetres.dll
C:\WINDOWS\system\izl_gif.dll
C:\WINDOWS\system\ldtif11n.dll
C:\WINDOWS\system\lkgif11n.dll
C:\WINDOWS\system\llkrn70n.dll
C:\WINDOWS\system\LWEXPAND.DLL
C:\WINDOWS\system\madart32.dll
C:\WINDOWS\system\MCTCP.DLL
C:\WINDOWS\system\MCVIDC32.DLL
C:\WINDOWS\system\mefs13n.dll
C:\WINDOWS\system\MGNSSPC.DLL
C:\WINDOWS\system\mHg_hook.dll
C:\WINDOWS\system\MHR2C.DLL
C:\WINDOWS\system\MIPIU.DLL
C:\WINDOWS\system\MKWEBDVD.DLL
C:\WINDOWS\system\MLPI.DLL
C:\WINDOWS\system\MMFS32.DLL
C:\WINDOWS\system\mnssouri.dll
C:\WINDOWS\system\MUSHRUI.DLL
C:\WINDOWS\system\MVRATELC.DLL
C:\WINDOWS\system\mxsr13n.dll
C:\WINDOWS\system\mzexcl40.dll
C:\WINDOWS\system\NMSWAN16.DLL
C:\WINDOWS\system\NNNET32.DLL
C:\WINDOWS\system\OQGAPI.DLL
C:\WINDOWS\system\OSBCTL32.DLL
C:\WINDOWS\system\OTMREG.DLL
C:\WINDOWS\system\OUE32.DLL
C:\WINDOWS\system\pbcrt.dll
C:\WINDOWS\system\pep.dll
C:\WINDOWS\system\prapi.dll
C:\WINDOWS\system\pwp.dll
C:\WINDOWS\system\py.dll
C:\WINDOWS\system\PZPD32.DLL
C:\WINDOWS\system\RHANP.DLL
C:\WINDOWS\system\RKASIG.DLL
C:\WINDOWS\system\RKVPSP.DLL
C:\WINDOWS\system\ROCLTC6.DLL
C:\WINDOWS\system\RUDL8B21.DLL
C:\WINDOWS\system\RXASIG.DLL
C:\WINDOWS\system\SCNDMAIL.DLL
C:\WINDOWS\system\SGCUR32.DLL
C:\WINDOWS\system\SMMEDEA.DLL
C:\WINDOWS\system\SMTUPAPI.DLL
C:\WINDOWS\system\UADM16.DLL
C:\WINDOWS\system\UJDM16.DLL
C:\WINDOWS\system\VJ4EN16.DLL
C:\WINDOWS\system\WDCTHUNK.DLL
C:\WINDOWS\system\WSSAPD.DLL
C:\WINDOWS\system\zncomm.dll

************

Registry entries found:

[HKEY_CLASSES_ROOT\CLSID\{D095DEC0-E372-11D9-816D-0010B50FC6CB}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\PZPD32.DLL"

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{CBB4D693-1186-EA53-B62A-A4991CA8F27A}"=""


************

Killing Explorer
Done!

Killing Rundll32
Done!

Removing malicious CLSID(s)
Done!

Restarting Explorer
Done!

Deleting malicious files
Done!


Finished!

And, here's the logfile from Hi-Jack This:

Logfile of HijackThis v1.99.1
Scan saved at 9:35:18 PM, on 9/20/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\HPSJVXD.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
E:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\SCANJET\PRECISIONSCAN\HPPPT.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\NOTEPAD.EXE
F:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS13
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [HP CD-Writer] C:\Program Files\HP CD-Writer\Mmenu\hpcdtray.exe
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [HPSCANMonitor] c:\windows\SYSTEM\hpsjvxd.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - Startup: HP Parallel Port Test.lnk = C:\SCANJET\PrecisionScan\hpppt.exe
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com...ior/Outside.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://remotemail.r...com/iNotes6.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab

So, next step?
  • 0

#6
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Your HJT log looks clean.

l2mfix got rid of a lot of the bad files.

Do you have any issues with your PC ??

If so, then please do another online scan at Panda here - http://www.pandasoft.../activescan.htm
  • 0

#7
kookypelli

kookypelli

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Looks good so far...no pop-ups not even when I'm not online! :tazz:

Any suggestions about keeping them at bay for the future? Software? I think they came from some song lyrics sites I visited. I have the free version of Zone Alarm and Avast but they're obviously not doing the trick and Spybot and Ad-Aware can't even find them on regular sweeps.
  • 0

#8
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Unfortunately that is the sad truth !!!

You can never do enough to protect yourself. Also no program can guarantee protection against such infections. You only need to take precautions to minimise the risk of infections. Apart from being careful about where you go on the net you can take a few other steps as well.

Avast, Spybot, Ad aware, Zone Alarm are all good programs. Keep them. In fact they are part of the programs I recommend all the time.


CONGRATULATIONS !!!!!!!!!!! Your PC is clean now :tazz:



I would recommend the following steps to keep your PC clean –

PREVENTIVE MEASURES FOR FUTURE

Operating System
1. Keep the Windows and Internet Explorer updated with the latest fixes. These fixes are available free from Microsoft. Click on Tools in the IE menu bar and then on Windows update. You can also use the following links

Windows security and critical updates
Internet Explorer security and critical updates

Also ensure that automatic updates are enabled for faster updation of the system.
(Right click on My Computer on your desktop, properties and Automatic Updates tab.


Anti-Virus Software
2. Keep your Anti-virus program updated with the latest definitions. Some of the common anti-virus programs in use are :

Norton Anti-Virus
McAfee Anti-Virus
AVG Anti-Virus --- freeware
Avast Home Edition --- freeware

Use only one anti-virus program as multiple such programs can create conflicts between themselves and severely hamper the performance of your PC.


Firewall
3. You should also have a good firewall. Here are 3 free ones available for personal use:
Sygate Personal Firewall, Kerio Personal Firewall, ZoneAlarm


Internet Browsers
4. Have robust explorer settings. It is preferable to use an internet browser other that IE as most of the malware is targetted at IE. In case you prefer to use IE, then download a list of innocent looking but harmful websites from IE-Spyad and install it on ur PC. IE-SPYAD puts over 5000 sites in your internet explorer's restricted zone, so you'll be protected when you visit innocent-looking sites that aren't really innocent at all.

Some alternate browsers I suggest are Firefox Mozilla Browser and Opera

Ensure that Security level, irrespective of whichever browser you use, is set at Medium or higher, restrict the usage of cookies and activeX components.


Spyware Protection
5. Have a wall of protection against spyware / adware by installing SpywareBlaster and SpywareGuard.

SpywareBlaster and SpywareGuard are by JavaCool and both are free programs.
SpywareBlaster will prevent spyware from being installed and consumes no system resources.
SpywareGuard offers realtime protection from spyware installation and browser hijack attempts. Both have free ongoing updates.


Spyware Removers
6. Install programs for scanning for malware and uninstalling them. Two of the best programs, both are freeware, are :

Spybot Search & Destroy - A powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.

AdAware SE Personal Edition - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.


Regular Maintenance of PC
7. Finally, invest some time for regular maintenance of your PC. Delete the temporary Internet files, temporary files, cookies etc. Click on Start button, Programs, Accessories, System Tools and run the program Disk Cleanup. Follow the instructions.

An alternate freeware software which can be used is CleanUp.

Keep your Registry clean. My favourite software is Registry First Aid. This is not a freeware but a trial version can be downloaded.


Go ahead and enjoy a clean PC !!!!!!!!!!!!!
  • 0

#9
kookypelli

kookypelli

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Many thanks again for your help! You are a timesaver and a PC saver and my own personal savior for getting me through this mess without tearing my hair out!

:tazz:
  • 0

#10
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP