This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Keep getting pop-ups

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, all… I'm a PC tech and I've got a puzzling case… I cleaned a whole bunch of toolbars and other malware off this user's computer and even rebooted into safe mode and ran SpyBot and Ad-Aware (both updated to the latest and greatest version / definitions.) After I left she logged back in and then called to say that she was getting pop-ups again…

I've run SpyBot and Ad-Aware again (in safe mode) and it's not finding anything. As my last-ditch effort to avoid re-formatting and re-imaging this user's PC (she's got a lot of stuff that would have to be reinstalled) I thought I'd post a Hijack-This! log and see if anyone here has any ideas…. Win98 SE with full rights on an NT4 domain, with Symantec Antivirus Corporate Edition 9.03 installed.

Here's the log file…

Logfile of HijackThis v1.99.1
Scan saved at 1:56:26 PM, on 6/27/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\TIGHTVNC\WINVNC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.8.1.2:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.COVISTA.NET;*.COVISTA.COM;*.KISSLD.COM;*.REALLD.COM;*.nwfld.com;*.DRSLD.COM;*.idsld.com;*.drvld.com;*.drild.com;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [hpjsiroute10.10.1.101] hpjsira.exe -i 10.10.1.101 -g 10.10.2.140
O4 - HKLM\..\Run: [hpjsiroute10.8.1.10] hpjsira.exe -i 10.8.1.10 -g 10.10.1.36
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\SYMANT~2\VPTRAY.EXE
O4 - HKLM\..\Run: [SpybotSnD] "C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [WinVNC] "C:\PROGRAM FILES\TIGHTVNC\WINVNC.EXE" -service
O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [defwatch] c:\PROGRA~1\SYMANT~2\DEFWATCH.EXE
O4 - HKLM\..\RunServices: [rtvscn95] c:\PROGRA~1\SYMANT~2\RTVSCN95.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - Startup: Microsoft Office.lnk.disabled
O4 - User Startup: Microsoft Office.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: agent.covista.net
O15 - Trusted Zone: www.agent.covista.net
O16 - DPF: {F91AB7B8-EE67-42AF-A5AA-8E232C396A04} (HTMLPRint Control) - https://www.creditcommander.com/cabs/htmlprint.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = covista.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = covista.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 10.10.1.2,10.20.1.2,10.10.1.248



Anyone see anything that would cause these pop-ups???
A couple quick things… First, we use VNC for remote support, so that's legit. Second, I used the ability of SpyBot S&D to prevent the start page from changing as a precaution. If anyone has some other tests I can run, I'll be glad to check 'em. A fellow PC tech friend (who's probably forgotten more than I'll ever know) suggested I try LSPFix, but since her PC is working fine except for random pop-ups on the desktop, I don't see the point. Thanks.
Hello and welcome to TomCoyote forum, Looks like the item causing the problem is Purity Scan: http://www.doxdesk.com/parasite/PurityScan.html

I will depend on you to make sure her domains are all correct, those are the 017 items in the log. The LSPfix is a tool used for a specific purpose, see this: http://www.cexx.org/lspfix.htm
It is really not suggested to use it for other reasons, read a little and you will see what I mean. Let's try this, and I am not running a lot of cleanup tools since it appears you have done that.

1) Put HJT in a permanent folder: C:\WINDOWS\TEMP\HIJACKTHIS.EXE Go to the Windows folder and make a new folder called HJT and move the HijackThis.exe into that folder. Logs and backups for safety will also store in the permanent folder. Thanks.

2) Purity has a uninstaller, lets try that first:
http://www.purityscan.com/uninstall.html

3) Search & Destroy\TeaTimer.exe will block HJT so please turn it off until you are finished:
http://russelltexas.com/malware/teatimer.htm

4) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
PurityScan/Clickspring adware >>
http://castlecops.com/startuplist-9165.html
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
above item can be remove if not needed
O15 - Trusted Zone: agent.covista.net
O15 - Trusted Zone: www.agent.covista.net
above two..do you really want those in the trusted zone? Your call
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
leftover from Windows AdTools winad

Close all programs but HJT and all browser windows, then click on "Fix Checked"

SHOW HIDDEN FILES: Follow the instructions in the link to enable hidden files for your operating system.
You may wish to reverse this process if you have any concern about anyone getting into these hidden system files.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

c:\windows\SYSTEM\wucrtupd.exe >>> file (may be gone if the uninstaller did it's job)

I suggest a good cleaning with: http://www.ccleaner.com/ just don't use the registry cleaner unless you back up the registry as prompted.

Post a new log for a last look and some great ideas for staying clean.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Thanks for the suggestions…. Here's the new HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 8:43:13 AM, on 7/8/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\TIGHTVNC\WINVNC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.8.1.2:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.COVISTA.NET;*.COVISTA.COM;*.KISSLD.COM;*.REALLD.COM;*.nwfld.com;*.DRSLD.COM;*.idsld.com;*.drvld.com;*.drild.com;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [hpjsiroute10.10.1.101] hpjsira.exe -i 10.10.1.101 -g 10.10.2.140
O4 - HKLM\..\Run: [hpjsiroute10.8.1.10] hpjsira.exe -i 10.8.1.10 -g 10.10.1.36
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\SYMANT~2\VPTRAY.EXE
O4 - HKLM\..\Run: [SpybotSnD] "C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [WinVNC] "C:\PROGRAM FILES\TIGHTVNC\WINVNC.EXE" -service
O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [defwatch] c:\PROGRA~1\SYMANT~2\DEFWATCH.EXE
O4 - HKLM\..\RunServices: [rtvscn95] c:\PROGRA~1\SYMANT~2\RTVSCN95.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - Startup: Microsoft Office.lnk.disabled
O4 - User Startup: Microsoft Office.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: agent.covista.net
O15 - Trusted Zone: www.agent.covista.net
O16 - DPF: {F91AB7B8-EE67-42AF-A5AA-8E232C396A04} (HTMLPRint Control) - https://www.creditcommander.com/cabs/htmlprint.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} -
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = covista.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = covista.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 10.10.1.2,10.20.1.2,10.10.1.248

The "trusted zone" domains are necessary. :-) Just as a precaution, I did not delete the wucrtupd.exe, but I did rename the extension. I downloaded and ran the uninstall, but it didn't appear to be doing anything. I think they REALLY don't want you to uninstall their crapware! :-)
OK, however you wish to do it. Concerning the uninstall, I always run it then follow up manually to be sure. There are a couple of partial DPF lines that should go:
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} -
FavoriteMan Websearch
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
Adware.Minibug

Sometimes it is hard to remove them because of TeaTimer, even turning it off sometimes does not work. I have uninstalled Spybot, removed the lines and reinstalled it to get them at times. You can also try it in safemode.

This item: O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU) looks like it can go also, I do not see the program. Make sure all AWS downloads are 6.0 or above as AWS stopped with the adware at that point.

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Safe surfing…Phil

Thanks…pskelley
TomCoyote forum
Slyware Warrior
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI