This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

FireFox Popups...

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey all,

I've managed to catch a bug on my system and I can't seem to shake it. Symptoms are the seemingly random opening of a FireFox (default web browser) window displaying an advertisement. This doesn't always happen when I otherwise have FireFox open. I've scanned with AdAware, SpyBot, MS Defender, and McAfee VirusScan, all to no avail. The buggers even come up booted in Safe Mode w/ Networking. System is fully patched, all scanners were updated with latest definitions before scanning in Safe Mode. HijackThis log (taken in Safe Mode) posted below. Any help in prying this thing out of my system would be greatly appreciated!

Thanks!

JW

ps - FYI, I've got a Creative sound card, NVidia video board, and Epson printer – software associated with these devices seems to account for a lot of the log entries below…

———————————————————————–
Logfile of HijackThis v1.99.1
Scan saved at 9:15:43 PM, on 8/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Windows Defender\MSASCui.exe
F:\Program Files\Gaim\gaim.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Documents and Settings\Jonathan\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…&ar=msnhome
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…ER}&ar=home
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.real.com/player/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ShStatEXE] "F:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "D:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [NVMixerTray] "D:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMS] D:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [Disc Detector] D:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CTStartup] F:\Program Files\Creative\SBAudigy\Program\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [Jet Detection] f:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Omnipage] F:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [zBrowser Launcher] f:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] f:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TaskTray] f:\Program Files\Creative\SBAudigy\Taskbar\CTLTray.exe
O4 - HKCU\..\Run: [Taskbar] f:\Program Files\Creative\SBAudigy\Taskbar\CTLTask.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] f:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = F:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = D:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: iM StartCenter.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1154401392640
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - f:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - F:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - F:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - F:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
Hello JW,

I know you have run several scans, but please do these and let's see the results.

STEP 1.
======
SpySweeper
Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

If you are taken to the internet page, just close the page.

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.


STEP 2.
======
The Ewido program’s detection rate is excellent. After the Trial has expired, the auto updates and real time protection stop but you can still update it manually and run scans anytime you want.

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan.
Empty Recycle Bin
Reboot

Please post the results from SpySweeper, ewido and a new hijackthis log.
Susan,

I took the steps that you suggested. Here are my Spy Sweeper and Ewido log files, followed by a fresh HijackThis log. Thanks for your help!

JW

ps - after these scans, the problem does not yet seem to be resolved… i got another popup just a moment ago

Spy Sweeper—————————————–
9:53 PM: Removal process completed. Elapsed time 00:00:01
9:53 PM: Quarantining All Traces: apropos
9:53 PM: Quarantining All Traces: nsis media extension
9:53 PM: Removal process initiated
9:37 PM: Traces Found: 4
9:37 PM: Full Sweep has completed. Elapsed time 00:20:08
9:37 PM: File Sweep Complete, Elapsed Time: 00:18:59
9:35 PM: Warning: Failed to access drive N:
9:35 PM: Warning: Failed to access drive M:
9:35 PM: Warning: Failed to access drive L:
9:35 PM: Warning: Failed to access drive K:
9:28 PM: a0008327.exe (ID = 50118)
9:28 PM: Found Adware: apropos
9:23 PM: uninst.exe (ID = 329369)
9:23 PM: a0008324.exe (ID = 329369)
9:18 PM: Starting File Sweep
9:18 PM: Warning: Failed to access drive A:
9:18 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
9:18 PM: Starting Cookie Sweep
9:18 PM: Registry Sweep Complete, Elapsed Time:00:00:11
9:18 PM: HKLM\software\nsis\media\ (ID = 1571094)
9:18 PM: Found Trojan Horse: nsis media extension
9:18 PM: Starting Registry Sweep
9:18 PM: Memory Sweep Complete, Elapsed Time: 00:00:54
9:17 PM: Starting Memory Sweep
9:17 PM: Sweep initiated using definitions version 740
9:17 PM: Spy Sweeper 5.0.5.1286 started
9:17 PM: | Start of Session, Tuesday, August 15, 2006 |
********
9:17 PM: | End of Session, Tuesday, August 15, 2006 |
9:17 PM: Program Version 5.0.5.1286 Using Spyware Definitions 740
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
8:57 PM: Shield States
8:57 PM: Spyware Definitions: 740
8:57 PM: Spy Sweeper 5.0.5.1286 started
6:03 PM: | End of Session, Tuesday, August 15, 2006 |
6:02 PM: Program Version 5.0.5.1286 Using Spyware Definitions 740
5:59 PM: Your spyware definitions have been updated.
Operation: File Access
Target:
Source: F:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\MCSHIELD.EXE
5:59 PM: Tamper Detection
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:57 PM: Shield States
5:57 PM: Spyware Definitions: 691
5:57 PM: Spy Sweeper 5.0.5.1286 started
5:57 PM: Spy Sweeper 5.0.5.1286 started
5:57 PM: | Start of Session, Tuesday, August 15, 2006 |
********
6:04 PM: | End of Session, Tuesday, August 15, 2006 |
6:03 PM: Traces Found: 0
6:03 PM: Memory Sweep Complete, Elapsed Time: 00:00:07
6:03 PM: Sweep Canceled
6:03 PM: Starting Memory Sweep
6:03 PM: Sweep initiated using definitions version 740
6:03 PM: Spy Sweeper 5.0.5.1286 started
6:03 PM: | Start of Session, Tuesday, August 15, 2006 |
********
6:57 PM: Removal process completed. Elapsed time 00:00:06
6:57 PM: Quarantining All Traces: apropos
6:57 PM: Quarantining All Traces: gain - common components
6:57 PM: Quarantining All Traces: 2o7.net cookie
6:57 PM: Quarantining All Traces: webtrends cookie
6:57 PM: Quarantining All Traces: nsis media extension
6:57 PM: Removal process initiated
6:27 PM: Traces Found: 9
6:27 PM: Full Sweep has completed. Elapsed time 00:23:42
6:27 PM: File Sweep Complete, Elapsed Time: 00:22:33
6:22 PM: Warning: Failed to access drive N:
6:22 PM: Warning: Failed to access drive M:
6:22 PM: Warning: Failed to access drive L:
6:22 PM: Warning: Failed to access drive K:
6:15 PM: gain website.url (ID = 61373)
6:15 PM: exec.exe (ID = 50118)
6:15 PM: Found Adware: apropos
6:15 PM: about gain.lnk (ID = 61269)
6:15 PM: gstartup.lnk (ID = 61450)
6:15 PM: Found Adware: gain - common components
6:09 PM: uninst.exe (ID = 329369)
6:05 PM: Starting File Sweep
6:05 PM: Warning: Failed to access drive A:
6:05 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
6:05 PM: jonathan@msnportal.112.2o7[1].txt (ID = 1958)
6:05 PM: jonathan@microsofteup.112.2o7[1].txt (ID = 1958)
6:05 PM: Found Spy Cookie: 2o7.net cookie
6:05 PM: [removed][2].txt (ID = 3669)
6:05 PM: Found Spy Cookie: webtrends cookie
6:05 PM: Starting Cookie Sweep
6:05 PM: Registry Sweep Complete, Elapsed Time:00:00:11
6:05 PM: HKLM\software\nsis\media\ (ID = 1571094)
6:05 PM: Found Trojan Horse: nsis media extension
6:05 PM: Starting Registry Sweep
6:05 PM: Memory Sweep Complete, Elapsed Time: 00:00:54
6:04 PM: Starting Memory Sweep
6:04 PM: Sweep initiated using definitions version 740
6:04 PM: Spy Sweeper 5.0.5.1286 started
6:04 PM: | Start of Session, Tuesday, August 15, 2006 |
********

Ewido—————————————-
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 10:25:26 PM 8/15/2006

+ Scan result:



:mozilla.46:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.47:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.48:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.49:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.11:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.57:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined).
:mozilla.13:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.38:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.34:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.35:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.36:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.37:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.10:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.6:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.7:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.8:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.9:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).


::Report end

HijackThis—————————————-
Logfile of HijackThis v1.99.1
Scan saved at 10:27:04 PM, on 8/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\WINDOWS\Explorer.EXE
F:\Program Files\ewido anti-spyware 4.0\ewido.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Documents and Settings\Jonathan\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…&ar;=msnhome
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…ER}&ar;=home
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.real.com/player/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ShStatEXE] "F:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "D:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [NVMixerTray] "D:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMS] "D:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE"
O4 - HKLM\..\Run: [Disc Detector] "D:\Program Files\Creative\ShareDLL\CtNotify.exe"
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CTStartup] "F:\Program Files\Creative\SBAudigy\Program\CTEaxSpl.EXE" /run
O4 - HKLM\..\Run: [Jet Detection] "f:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [Omnipage] "F:\Program Files\ScanSoft\OmniPageSE\opware32.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] "f:\Program Files\Logitech\iTouch\iTouch.exe"
O4 - HKLM\..\Run: [EM_EXEC] f:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpySweeper] "D:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!ewido] "F:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TaskTray] "f:\Program Files\Creative\SBAudigy\Taskbar\CTLTray.exe"
O4 - HKCU\..\Run: [Taskbar] "f:\Program Files\Creative\SBAudigy\Taskbar\CTLTask.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "f:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = F:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = D:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: iM StartCenter.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1154401392640
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - D:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - f:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - f:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - F:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - F:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - F:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - D:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Please do the following which will provide some reports for me to analyze.

STEP 1.
======
Look2Me
Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

You may receive pop-up asking if you will allow script to run when you perform the following instructions. Please allow the script to run.

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

If you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."…then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.
Susan, Thanks for your continued help! Here's the logfile from l2mfix: l2mfix——————————————————- L2MFIX find log 032106 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] "Logon"="WLEventLogon" "Logoff"="WLEventLogoff" "Startup"="WLEventStartup" "Shutdown"="WLEventShutdown" "StartScreenSaver"="WLEventStartScreenSaver" "StopScreenSaver"="WLEventStopScreenSaver" "Lock"="WLEventLock" "Unlock"="WLEventUnlock" "StartShell"="WLEventStartShell" "PostShell"="WLEventPostShell" "Disconnect"="WLEventDisconnect" "Reconnect"="WLEventReconnect" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000000 "SafeMode"=dword:00000001 "MaxWait"=dword:ffffffff "DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Event"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings] "Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\ 00,00,7b,0e,cf,fb,5e,b7,d2,4e,87,d8,83,08,c4,d7,59,2f,04,00,00,00,04,00,00,\ 00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,59,18,91,ba,37,02,4d,b7,\ 89,39,30,c1,47,5c,d1,d6,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,3a,\ 94,20,50,4e,8a,64,25,cf,0c,95,fc,a4,56,a8,ed,b0,01,00,00,57,8c,20,96,75,bd,\ 67,e0,9a,3f,21,ea,31,50,ad,fb,71,32,b5,3c,f8,53,1a,f3,e1,97,d8,7b,43,b8,22,\ 59,5e,7e,74,18,31,7b,b9,4f,e2,8a,31,3c,ae,40,7f,54,b8,82,1b,3f,18,71,2d,10,\ 7b,c9,a6,97,94,30,b1,af,7c,cb,ec,ab,a7,5f,66,dd,94,df,a6,90,b5,bc,c1,b8,5b,\ 9f,6e,a0,ec,08,c5,85,cd,57,33,64,b3,1c,16,ff,fa,8e,4c,e8,c6,6d,07,05,5e,fa,\ a2,dd,22,61,58,60,fe,e0,1f,35,54,e9,bc,d8,79,81,64,09,fe,23,cd,9d,e4,3d,42,\ 18,37,ab,1c,d4,f2,89,f4,77,44,cc,55,fd,a0,bb,43,c6,8f,36,e6,61,82,f8,a0,60,\ 88,45,23,6b,44,81,e9,6a,13,b8,11,c2,dc,80,a6,e3,9c,96,4b,58,f9,ff,5b,f3,a4,\ 61,a3,9a,43,f6,62,1b,3d,62,2e,45,5c,06,81,5c,d1,3f,42,59,30,1f,8f,b6,b8,e5,\ 05,0c,1c,1f,70,ab,58,02,1f,7e,bc,72,65,6f,b9,6c,9e,41,1e,2c,43,fb,ed,13,45,\ 48,67,de,ec,d1,eb,a6,21,18,d1,06,5f,99,e2,2d,98,ce,7e,1b,db,f9,df,47,6c,9a,\ dd,50,df,2e,33,b4,b5,0f,b9,a7,9a,d5,1f,35,eb,1f,0b,14,f4,5a,b1,0a,b4,f5,8d,\ ba,e6,f5,3d,81,45,11,04,20,20,52,6f,df,12,8a,51,c7,e8,f7,e1,e8,48,9a,95,9b,\ 7d,77,11,6c,05,28,e7,86,87,5d,57,cf,be,2d,c5,08,dd,a4,87,9b,31,c4,57,e4,09,\ 8e,4f,f6,78,fb,29,a2,be,f4,90,ed,ab,86,c5,84,5a,ee,11,31,de,30,a6,e9,a0,5d,\ ca,d3,77,a3,d0,47,79,3b,b1,7e,2a,1d,08,6e,74,53,18,a5,4c,6d,fb,2c,de,f0,70,\ 3b,c3,68,65,56,d8,48,50,bf,00,2f,f9,b5,df,e9,d6,0b,ce,87,df,70,e7,35,c3,a3,\ e1,b2,5c,9c,c8,38,07,7d,91,b6,e8,b2,55,1b,9f,a7,85,bc,7d,0c,47,69,e7,54,fe,\ 34,14,00,00,00,ef,1b,8a,b1,b2,a4,cf,16,97,dc,07,50,41,3a,36,5a,8e,63,a0,02 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier] "Asynchronous"=dword:00000000 "DllName"="WRLogonNTF.dll" "Impersonate"=dword:00000001 "Lock"="WRLock" "StartScreenSaver"="WRStartScreenSaver" "StartShell"="WRStartShell" "Startup"="WRStartup" "StopScreenSaver"="WRStopScreenSaver" "Unlock"="WRUnlock" "Shutdown"="WRShutdown" "Logoff"="WRLogoff" "Logon"="WRLogon" ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "SV1"="" ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet" "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension" "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management" "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras" "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…" "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band" "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar" "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service" "{FF393560-C2A7-11CF-BFF4-444553540000}"="History" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File" "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut" "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object" "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu" "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…" "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults" "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page" "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions" "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder" "{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class" "{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper" "{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer" "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu" "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu" "{cc3ebf80-1a70-11d3-bdf2-00902745d0a9}"="Mixman Shell Extention" "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band" "{40DAD1B9-DDCF-4A31-A5D3-A03BC8881370}"="IndexingServiceExtExt Extension" "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes" "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player" "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices" "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu" "{0561EC90-CE54-4f0c-9C55-E226110A740C}"="Haali Column Provider" "{E4D8441D-F89C-4b5c-90AC-A857E1768F1F}"="Haali Matroska Thumbnail Exctractor" "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"="Webroot Spy Sweeper Context Menu Integration" ********************************************************************************** HKEY ROOT CLASSIDS: ********************************************************************************** Files Found are not all bad files: D:\WINDOWS\SYSTEM32\ browseui.dll Fri Jun 23 2006 7:02:50a A…. 1,022,976 999.00 K cdfview.dll Fri Jun 23 2006 7:02:50a A…. 151,040 147.50 K danim.dll Fri Jun 23 2006 7:02:50a A…. 1,054,208 1.00 M dhcpcsvc.dll Fri May 19 2006 8:59:42a A…. 111,616 109.00 K dnsapi.dll Mon Jun 26 2006 1:37:10p A…. 148,480 145.00 K dxtmsft.dll Fri Jun 23 2006 7:02:50a A…. 357,888 349.50 K dxtrans.dll Fri Jun 23 2006 7:02:50a A…. 205,312 200.50 K extmgr.dll Fri Jun 23 2006 7:02:50a ….. 55,808 54.50 K hlink.dll Fri Jul 21 2006 4:24:44a A…. 72,704 71.00 K iepeers.dll Fri Jun 23 2006 7:02:50a A…. 251,392 245.50 K inetcomm.dll Thu Jul 27 2006 9:24:46a A…. 679,424 663.50 K inseng.dll Fri Jun 23 2006 7:02:50a A…. 96,256 94.00 K iphlpapi.dll Fri May 19 2006 8:59:42a A…. 94,720 92.50 K jgdw400.dll Thu Jun 1 2006 2:47:08p A…. 163,840 160.00 K jgpl400.dll Thu Jun 1 2006 2:47:08p A…. 27,648 27.00 K jsproxy.dll Fri Jun 23 2006 7:02:50a A…. 16,384 16.00 K kernel32.dll Wed Jul 5 2006 6:55:02a A…. 984,064 961.00 K legitc~1.dll Mon Jun 19 2006 4:19:42p A…. 571,184 557.80 K mshtml.dll Fri Jul 28 2006 7:28:54a A…. 3,054,080 2.91 M mshtmled.dll Fri Jun 23 2006 7:02:52a A…. 448,512 438.00 K msrating.dll Fri Jun 23 2006 7:02:52a A…. 146,432 143.00 K mstime.dll Fri Jun 23 2006 7:02:52a A…. 532,480 520.00 K netapi32.dll Fri Jul 14 2006 11:31:40a A…. 332,288 324.50 K nv4_disp.dll Thu Jun 1 2006 5:22:00p A…. 4,529,408 4.32 M nvapi.dll Thu Jun 1 2006 5:22:00p A…. 196,608 192.00 K nvcod.dll Thu Jun 1 2006 5:22:00p A…. 35,840 35.00 K nvcodins.dll Thu Jun 1 2006 5:22:00p A…. 35,840 35.00 K nvcpl.dll Thu Jun 1 2006 5:22:00p A…. 7,618,560 7.27 M nvcpluir.dll Thu Jun 1 2006 5:22:00p A…. 1,011,712 988.00 K nvdisps.dll Thu Jun 1 2006 5:22:00p A…. 5,652,480 5.39 M nvdispsr.dll Thu Jun 1 2006 5:22:00p A…. 5,246,976 5.00 M nvexpbar.dll Thu Jun 1 2006 5:22:00p A…. 311,296 304.00 K nvgames.dll Thu Jun 1 2006 5:22:00p A…. 3,100,672 2.96 M nvgamesr.dll Thu Jun 1 2006 5:22:00p A…. 2,916,352 2.78 M nvhwvid.dll Thu Jun 1 2006 5:22:00p A…. 581,632 568.00 K nview.dll Thu Jun 1 2006 5:22:00p A…. 1,466,368 1.40 M nvmccs.dll Thu Jun 1 2006 5:22:00p A…. 229,376 224.00 K nvmccsrs.dll Thu Jun 1 2006 5:22:00p A…. 45,056 44.00 K nvmccss.dll Thu Jun 1 2006 5:22:00p A…. 188,416 184.00 K nvmccssr.dll Thu Jun 1 2006 5:22:00p A…. 462,848 452.00 K nvmctray.dll Thu Jun 1 2006 5:22:00p A…. 86,016 84.00 K nvmobls.dll Thu Jun 1 2006 5:22:00p A…. 888,832 868.00 K nvmoblsr.dll Thu Jun 1 2006 5:22:00p A…. 2,859,008 2.73 M nvnt4cpl.dll Thu Jun 1 2006 5:22:00p A…. 286,720 280.00 K nvoglnt.dll Thu Jun 1 2006 5:22:00p A…. 5,632,000 5.37 M nvshell.dll Thu Jun 1 2006 5:22:00p A…. 466,944 456.00 K nvvitvs.dll Thu Jun 1 2006 5:22:00p A…. 2,924,544 2.79 M nvvitvsr.dll Thu Jun 1 2006 5:22:00p A…. 2,977,792 2.84 M nvwddi.dll Thu Jun 1 2006 5:22:00p A…. 81,920 80.00 K nvwdmcpl.dll Thu Jun 1 2006 5:22:00p A…. 1,662,976 1.59 M nvwimg.dll Thu Jun 1 2006 5:22:00p A…. 1,019,904 996.00 K nvwss.dll Thu Jun 1 2006 5:22:00p A…. 1,257,472 1.20 M nvwssr.dll Thu Jun 1 2006 5:22:00p A…. 1,740,800 1.66 M pncrt.dll Thu Aug 3 2006 6:13:18p A…. 278,528 272.00 K pndx5016.dll Thu Aug 3 2006 6:13:22p A…. 6,656 6.50 K pndx5032.dll Thu Aug 3 2006 6:13:22p A…. 5,632 5.50 K pngfilt.dll Fri Jun 23 2006 7:02:52a A…. 39,424 38.50 K rasadhlp.dll Mon Jun 26 2006 1:37:10p A…. 8,192 8.00 K rasmans.dll Thu Jun 22 2006 6:47:18a A…. 181,248 177.00 K rmoc3260.dll Thu Aug 3 2006 6:13:46p A…. 176,167 172.04 K shdocvw.dll Fri Jun 23 2006 7:02:52a A…. 1,494,016 1.42 M shell32.dll Thu Jul 13 2006 9:33:28a A…. 8,453,632 8.06 M shlwapi.dll Fri Jun 23 2006 7:02:52a A…. 474,112 463.00 K urlmon.dll Tue Jul 25 2006 4:33:40p A…. 613,888 599.50 K wgalogon.dll Mon Jun 19 2006 4:20:42p ….. 702,768 686.30 K wininet.dll Fri Jun 23 2006 7:02:52a A…. 658,944 643.50 K wrlogo~1.dll Fri Jul 7 2006 4:53:54p A…. 208,896 204.00 K wrlzma.dll Fri Jul 7 2006 4:53:50p A…. 20,992 20.50 K xpsp3res.dll Fri Jun 23 2006 4:34:36a A…. 24,576 24.00 K 69 items found: 69 files, 0 directories. Total of file sizes: 79,440,775 bytes 75.76 M Locate .tmp files: No matches found. ********************************************************************************** Directory Listing of system files: Volume in drive D is PrimaryBoot Volume Serial Number is 6C32-66AC Directory of D:\WINDOWS\System32 08/13/2006 10:08 PM dllcache 07/30/2006 09:09 PM Microsoft 0 File(s) 0 bytes 2 Dir(s) 24,678,793,216 bytes free
Alas, this does not seem to have fixed the problem, either. Really driving me batty. At least I only get about 1-2/hour. They come regardless of whether or not I have Firefox open already. I'm off on vacation for a week.. will have to pound at this some more when I return. Thanks again for all your help, and I'm open to any more suggestions you may have! JW
I don't know if you are back or not. Please do the following:

STEP 1.
======
Uninstall Manager
  • Open HijackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Uninstall Manager"
  • Click on the button "Save list"
  • Copy and past the List from notepad into your reply.
Are you still getting the pop-ups?
Susan, Been away longer than expected – things got busy w/ the start of a new semester @work and I haven't had time to deal with this. Just getting back to it now… So, I think I've noticed the pattern that the title bar of all of the popups includes "NSIS Media." I poked around, found in /Program Files/Common Files/ a folder named NSIS, in which there was actually an uninstaller. Keeping my fingers crossed that there will be no more popups… If I see another one, I'll post up those HijackThis logs from the Uninstall Manager. Thanks! JW

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI