This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help please! Unwanted popups!

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi There,

I hope someone is able to help me please. My pc has started throwing up pop ups 10 to the dozen. I have reviewed through spybot and removed all i could find, mainly just cookies. System startup shows something suspect. a file called corn tons hide.exe in C:\Documents and Settings\Emily\Application Data\internetmix that launches ever startup. i cant remove it!!

TIA
MikeA


Logfile of HijackThis v1.99.1
Scan saved at 18:07:23, on 30/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Wirelwss LAN Utility\tiwlnsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\U.S.R.TurboGWLAN\USRWLANG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Emily\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {E18C4431-D1CF-47E2-6DB7-B71288C13D3C} - C:\DOCUME~1\Emily\APPLIC~1\SOFTDE~1\Draw Team.exe
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk.disabled
O4 - Global Startup: AOL Companion.lnk.disabled
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: U.S. Robotics 802.11g Wireless Network Utility.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: TI Wlan Service (tiwlnsvc) - Unknown owner - C:\Program Files\Wirelwss LAN Utility\tiwlnsvc.exe
Hello Mike A and Welcome to TomCoyote,

Please do the following:

STEP 1.
======
SpySweeper
Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)
  • If you are taken to the internet page, just close the page.
  • You will be prompted to check for updated definitions, please do so.
    (This may take several minutes)
  • Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.
  • Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!
  • When the sweep has finished, click Remove. Click Select All and then Next
  • From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.
STEP 2.
======
The Ewido program’s detection rate is excellent. After the Trial has expired, the auto updates and real time protection stop but you can still update it manually and run scans anytime you want.

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan.
STEP 3.
======
File name reminds me of LOP so let's check.
FindLop

Download FindLop and unzip to one folder:
Inside the folder find findlop.bat
Doubleclick it and it will create the file C:\findlop.txt
Find that file and copy the content into your next post.

Please post the results from SpySweeper, ewido, C:\findlop.txt and a new hijackthis log.
thanks for your help. here is spysweeper log 22:07: Removal process completed. Elapsed time 00:00:31 22:07: Quarantining All Traces: questionmarket cookie 22:07: Quarantining All Traces: lopdotcom cookie 22:07: Quarantining All Traces: atlas dmt cookie 22:07: Quarantining All Traces: adtech cookie 22:07: Quarantining All Traces: lopdotcom 22:07: Removal process initiated 22:06: Traces Found: 13 22:06: Full Sweep has completed. Elapsed time 00:24:34 22:06: File Sweep Complete, Elapsed Time: 00:17:08 22:04: C:\Documents and Settings\All Users\Application Data\roam sect settings nurb\HOLEBLAH.exe (ID = 467) 22:03: C:\Documents and Settings\All Users\Application Data\roam sect settings nurb\Live Dent.exe (ID = 467) 22:02: C:\System Volume Information\_restore{52f314c1-285a-4009-909e-11f97d461dad}\RP29\A0033066.exe (ID = 467) 22:02: C:\System Volume Information\_restore{52f314c1-285a-4009-909e-11f97d461dad}\RP31\A0035169.exe (ID = 459) 22:02: C:\System Volume Information\_restore{52f314c1-285a-4009-909e-11f97d461dad}\RP29\A0033068.exe (ID = 467) 21:49: C:\Program Files\Adverts (ID = 2147496720) 21:49: Found Adware: lopdotcom 21:49: Starting File Sweep 21:49: Cookie Sweep Complete, Elapsed Time: 00:00:03 21:49: c:\documents and settings\emily\cookies\[removed]-look-up[1].txt (ID = 9191) 21:49: c:\documents and settings\emily\cookies\emily@questionmarket[2].txt (ID = 3217) 21:49: Found Spy Cookie: questionmarket cookie 21:49: c:\documents and settings\emily\cookies\[removed]-look-up[1].txt (ID = 9191) 21:49: c:\documents and settings\emily\cookies\[removed]-look-up[1].txt (ID = 9191) 21:49: c:\documents and settings\emily\cookies\[removed]-look-up[1].txt (ID = 9191) 21:49: Found Spy Cookie: lopdotcom cookie 21:49: c:\documents and settings\emily\cookies\emily@atdmt[2].txt (ID = 2253) 21:49: Found Spy Cookie: atlas dmt cookie 21:49: c:\documents and settings\emily\cookies\emily@adtech[2].txt (ID = 2155) 21:49: Found Spy Cookie: adtech cookie 21:49: Starting Cookie Sweep 21:49: Registry Sweep Complete, Elapsed Time:00:01:09 21:48: Starting Registry Sweep 21:48: Memory Sweep Complete, Elapsed Time: 00:05:57 21:47: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE 21:42: Starting Memory Sweep 21:42: Sweep initiated using definitions version 777 21:42: Spy Sweeper 5.0.5.1286 started 21:42: | Start of Session, 09 October 2006 | ******** 21:42: | End of Session, 09 October 2006 | Keylogger Shield: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites Shield: Off Hosts File Shield: On Spy Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 21:40: Shield States 21:40: Spyware Definitions: 777 21:39: Spy Sweeper 5.0.5.1286 started 21:28: Spy Sweeper 5.0.5.1286 started 21:21: Spy Sweeper 5.0.5.1286 started Operation: Terminate Target: C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPERUI.EXE Source: C:\WINDOWS\SYSTEM32\CSRSS.EXE 20:13: Tamper Detection Operation: Terminate Target: C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPERUI.EXE Source: C:\WINDOWS\SYSTEM32\CSRSS.EXE 20:13: Tamper Detection Keylogger Shield: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites Shield: Off Hosts File Shield: On Spy Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 20:09: Shield States 20:09: Spyware Definitions: 777 20:07: Spy Sweeper 5.0.5.1286 started 19:44: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE 19:40: Your spyware definitions have been updated. 19:39: Automated check for program update in progress. Keylogger Shield: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites Shield: Off Hosts File Shield: On Spy Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 19:36: Shield States 19:36: Spyware Definitions: 691 19:35: Spy Sweeper 5.0.5.1286 started 20:23: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE Keylogger Shield: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites Shield: Off Hosts File Shield: On Spy Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 20:16: Shield States 20:15: Spyware Definitions: 691 20:15: Spy Sweeper 5.0.5.1286 started Keylogger Shield: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites Shield: Off Hosts File Shield: On Spy Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 22:48: Shield States 22:48: Spyware Definitions: 691 22:47: Spy Sweeper 5.0.5.1286 started 22:07: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE Keylogger Shield: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites Shield: Off Hosts File Shield: On Spy Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 22:02: Shield States 22:01: Spyware Definitions: 691 22:01: Spy Sweeper 5.0.5.1286 started 21:08: | End of Session, 06 October 2006 | Keylogger Shield: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites Shield: Off Hosts File Shield: On Spy Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 21:04: Shield States 21:04: Spyware Definitions: 691 21:03: Spy Sweeper 5.0.5.1286 started 20:58: Spy Installation Shield: found: Adware: lopdotcom, version 1.0.0.0 Keylogger Shield: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites Shield: Off Hosts File Shield: On Spy Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 20:57: Shield States 20:57: Spyware Definitions: 691 20:57: Spy Sweeper 5.0.5.1286 started 20:57: Spy Sweeper 5.0.5.1286 started 20:57: | Start of Session, 06 October 2006 | ******** 21:56: Removal process completed. Elapsed time 00:20:22 21:56: Preparing to restart your computer. Please wait… 21:54: Quarantining All Traces: zedo cookie 21:54: Quarantining All Traces: xiti cookie 21:54: Quarantining All Traces: myaffiliateprogram.com cookie 21:54: Quarantining All Traces: weborama cookie 21:54: Quarantining All Traces: web-stat cookie 21:54: Quarantining All Traces: adbureau cookie 21:54: Quarantining All Traces: tribalfusion cookie 21:54: Quarantining All Traces: tradedoubler cookie 21:54: Quarantining All Traces: toplist cookie 21:54: Quarantining All Traces: webtrendslive cookie 21:54: Quarantining All Traces: reliablestats cookie 21:54: Quarantining All Traces: clicktracks cookie 21:54: Quarantining All Traces: statcounter cookie 21:54: Quarantining All Traces: serving-sys cookie 21:54: Quarantining All Traces: server.iad.liveperson cookie 21:54: Quarantining All Traces: revenue.net cookie 21:54: Quarantining All Traces: questionmarket cookie 21:54: Quarantining All Traces: qksrv cookie 21:54: Quarantining All Traces: partypoker cookie 21:54: Quarantining All Traces: overture cookie 21:54: Quarantining All Traces: offeroptimizer cookie 21:54: Quarantining All Traces: mysearchnow cookie 21:54: Quarantining All Traces: mediaplex cookie 21:54: Quarantining All Traces: webtrends cookie 21:54: Quarantining All Traces: lopdotcom cookie 21:54: Quarantining All Traces: cassava cookie 21:54: Quarantining All Traces: bravenet cookie 21:54: Quarantining All Traces: bluestreak cookie 21:54: Quarantining All Traces: a cookie 21:54: Quarantining All Traces: atwola cookie 21:54: Quarantining All Traces: atlas dmt cookie 21:54: Quarantining All Traces: falkag cookie 21:54: Quarantining All Traces: apmebf cookie 21:54: Quarantining All Traces: touchclarity cookie 21:54: Quarantining All Traces: anm.co.uk cookie 21:54: Quarantining All Traces: adtech cookie 21:54: Quarantining All Traces: pointroll cookie 21:54: Quarantining All Traces: adrevolver cookie 21:54: Quarantining All Traces: yieldmanager cookie 21:54: Quarantining All Traces: 888 cookie 21:54: Quarantining All Traces: 2o7.net cookie 21:53: potentially rootkit-masked files is in use. It will be removed on reboot. 21:36: Quarantining All Traces: potentially rootkit-masked files 21:36: Quarantining All Traces: lopdotcom 21:35: Removal process initiated 21:34: Traces Found: 258 21:34: Full Sweep has completed. Elapsed time 00:26:06 21:34: File Sweep Complete, Elapsed Time: 00:19:00 21:29: Found System Monitor: potentially rootkit-masked files 21:28: Warning: Failed to open file "c:\documents and settings\emily\local settings\application data\microsoft\messenger\[removed]\sharingmetadata\pending.dat". The operation completed successfully 21:28: Warning: Failed to open file "c:\documents and settings\emily\local settings\application data\microsoft\messenger\[removed]\sharingmetadata\working\database_4888_6ff8_886f_e344\$db_clean$". The operation completed successfully 21:28: C:\System Volume Information\_restore{52f314c1-285a-4009-909e-11f97d461dad}\RP31\A0035161.exe (ID = 304) 21:27: C:\System Volume Information\_restore{52f314c1-285a-4009-909e-11f97d461dad}\RP29\A0033065.exe (ID = 121) 21:27: C:\Documents and Settings\Emily\Local Settings\Temp\bis71.exe (ID = 304) 21:27: C:\Documents and Settings\Emily\Application Data\Soft Debug Bold\Draw Team.exe (ID = 91) 21:27: C:\Documents and Settings\Emily\Local Settings\Temp\bis57.exe (ID = 304) 21:15: C:\System Volume Information\_restore{52f314c1-285a-4009-909e-11f97d461dad}\RP29\A0033067.exe (ID = 90) 21:15: Starting File Sweep 21:15: Cookie Sweep Complete, Elapsed Time: 00:00:09 21:15: c:\documents and settings\emily\cookies\emily@zedo[2].txt (ID = 3762) 21:15: Found Spy Cookie: zedo cookie 21:15: c:\documents and settings\emily\cookies\emily@xiti[1].txt (ID = 3717) 21:15: Found Spy Cookie: xiti cookie 21:15: c:\documents and settings\emily\cookies\[removed][2].txt (ID = 3032) 21:15: Found Spy Cookie: myaffiliateprogram.com cookie 21:15: c:\documents and settings\emily\cookies\emily@weborama[2].txt (ID = 3658) 21:15: Found Spy Cookie: weborama cookie 21:15: c:\documents and settings\emily\cookies\emily@web-stat[1].txt (ID = 3648) 21:15: Found Spy Cookie: web-stat cookie 21:15: c:\documents and settings\emily\cookies\[removed][2].txt (ID = 2060) 21:15: Found Spy Cookie: adbureau cookie 21:15: c:\documents and settings\emily\cookies\emily@tribalfusion[1].txt (ID = 3589) 21:15: Found Spy Cookie: tribalfusion cookie 21:15: c:\documents and settings\emily\cookies\emily@tradedoubler[1].txt (ID = 3575) 21:15: Found Spy Cookie: tradedoubler cookie 21:15: c:\documents and settings\emily\cookies\emily@toplist[1].txt (ID = 3557) 21:15: Found Spy Cookie: toplist cookie 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 3667) 21:15: Found Spy Cookie: webtrendslive cookie 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 3254) 21:15: Found Spy Cookie: reliablestats cookie 21:15: c:\documents and settings\emily\cookies\[removed][2].txt (ID = 2407) 21:15: Found Spy Cookie: clicktracks cookie 21:15: c:\documents and settings\emily\cookies\emily@statcounter[1].txt (ID = 3447) 21:15: Found Spy Cookie: statcounter cookie 21:15: c:\documents and settings\emily\cookies\emily@serving-sys[2].txt (ID = 3343) 21:15: Found Spy Cookie: serving-sys cookie 21:15: c:\documents and settings\emily\cookies\[removed][2].txt (ID = 3341) 21:15: Found Spy Cookie: server.iad.liveperson cookie 21:15: c:\documents and settings\emily\cookies\emily@revenue[2].txt (ID = 3257) 21:15: Found Spy Cookie: revenue.net cookie 21:15: c:\documents and settings\emily\cookies\emily@questionmarket[1].txt (ID = 3217) 21:15: Found Spy Cookie: questionmarket cookie 21:15: c:\documents and settings\emily\cookies\emily@qksrv[2].txt (ID = 3213) 21:15: Found Spy Cookie: qksrv cookie 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 3106) 21:15: c:\documents and settings\emily\cookies\emily@partypoker[1].txt (ID = 3111) 21:15: Found Spy Cookie: partypoker cookie 21:15: c:\documents and settings\emily\cookies\emily@partygaming.122.2o7[1].txt (ID = 1958) 21:15: c:\documents and settings\emily\cookies\emily@overture[2].txt (ID = 3105) 21:15: Found Spy Cookie: overture cookie 21:15: c:\documents and settings\emily\cookies\emily@offeroptimizer[1].txt (ID = 3087) 21:15: Found Spy Cookie: offeroptimizer cookie 21:15: c:\documents and settings\emily\cookies\emily@mysearchnow[1].txt (ID = 3047) 21:15: Found Spy Cookie: mysearchnow cookie 21:15: c:\documents and settings\emily\cookies\emily@msnportal.112.2o7[1].txt (ID = 1958) 21:15: c:\documents and settings\emily\cookies\emily@microsofteup.112.2o7[1].txt (ID = 1958) 21:15: c:\documents and settings\emily\cookies\emily@mediaplex[2].txt (ID = 6442) 21:15: Found Spy Cookie: mediaplex cookie 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 2089) 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 3669) 21:15: Found Spy Cookie: webtrends cookie 21:15: c:\documents and settings\emily\cookies\emily@lop[1].txt (ID = 2936) 21:15: Found Spy Cookie: lopdotcom cookie 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 3566) 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 3566) 21:15: c:\documents and settings\emily\cookies\emily@cassava[1].txt (ID = 2362) 21:15: Found Spy Cookie: cassava cookie 21:15: c:\documents and settings\emily\cookies\emily@bravenet[1].txt (ID = 2322) 21:15: Found Spy Cookie: bravenet cookie 21:15: c:\documents and settings\emily\cookies\emily@bluestreak[1].txt (ID = 2314) 21:15: Found Spy Cookie: bluestreak cookie 21:15: c:\documents and settings\emily\cookies\emily@a[1].txt (ID = 2027) 21:15: Found Spy Cookie: a cookie 21:15: c:\documents and settings\emily\cookies\emily@atwola[1].txt (ID = 2255) 21:15: Found Spy Cookie: atwola cookie 21:15: c:\documents and settings\emily\cookies\emily@atoc.112.2o7[1].txt (ID = 1958) 21:15: c:\documents and settings\emily\cookies\emily@atdmt[2].txt (ID = 2253) 21:15: Found Spy Cookie: atlas dmt cookie 21:15: c:\documents and settings\emily\cookies\[removed][2].txt (ID = 2650) 21:15: Found Spy Cookie: falkag cookie 21:15: c:\documents and settings\emily\cookies\emily@apmebf[2].txt (ID = 2229) 21:15: Found Spy Cookie: apmebf cookie 21:15: c:\documents and settings\emily\cookies\emily@aoluk.122.2o7[1].txt (ID = 1958) 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 3566) 21:15: Found Spy Cookie: touchclarity cookie 21:15: c:\documents and settings\emily\cookies\[removed][1].txt (ID = 2223) 21:15: Found Spy Cookie: anm.co.uk cookie 21:15: c:\documents and settings\emily\cookies\emily@adtech[1].txt (ID = 2155) 21:15: Found Spy Cookie: adtech cookie 21:15: c:\documents and settings\emily\cookies\[removed][2].txt (ID = 3148) 21:15: Found Spy Cookie: pointroll cookie 21:15: c:\documents and settings\emily\cookies\emily@adrevolver[4].txt (ID = 2088) 21:15: c:\documents and settings\emily\cookies\emily@adrevolver[3].txt (ID = 2088) 21:15: c:\documents and settings\emily\cookies\emily@adrevolver[2].txt (ID = 2088) 21:15: Found Spy Cookie: adrevolver cookie 21:15: c:\documents and settings\emily\cookies\[removed][2].txt (ID = 3751) 21:15: Found Spy Cookie: yieldmanager cookie 21:15: c:\documents and settings\emily\cookies\emily@888[1].txt (ID = 2019) 21:15: Found Spy Cookie: 888 cookie 21:15: c:\documents and settings\emily\cookies\emily@2o7[1].txt (ID = 1957) 21:15: c:\documents and settings\emily\cookies\emily@122.2o7[1].txt (ID = 1958) 21:15: c:\documents and settings\emily\cookies\emily@112.2o7[2].txt (ID = 1958) 21:15: Found Spy Cookie: 2o7.net cookie 21:15: Starting Cookie Sweep 21:15: Registry Sweep Complete, Elapsed Time:00:00:45 21:14: Starting Registry Sweep 21:14: Memory Sweep Complete, Elapsed Time: 00:05:59 21:13: Detected running threat: C:\Documents and Settings\Emily\Application Data\Soft Debug Bold\Draw Team.exe (ID = 91) 21:08: Detected running threat: C:\Documents and Settings\Emily\Application Data\Soft Debug Bold\Draw Team.exe (ID = 91) 21:08: Found Adware: lopdotcom 21:08: Starting Memory Sweep 21:08: Sweep initiated using definitions version 691 21:08: Spy Sweeper 5.0.5.1286 started 21:08: | Start of Session, 06 October 2006 | ********
And here are the others:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 22:44:35 06/10/2006

+ Scan result:



HKLM\SOFTWARE\Classes\Softomate.IEToolbar -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Softomate.IEToolbar.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CLSID -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\Program Files\Adverts\uninst.exe -> Adware.Lop : Cleaned with backup (quarantined).
C:\Documents and Settings\Emily\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Emily\Cookies\[removed][2].txt -> TrackingCookie.Clubdicecasino : Cleaned.
C:\Documents and Settings\Emily\Cookies\emily@clubdicecasino[2].txt -> TrackingCookie.Clubdicecasino : Cleaned.
C:\Documents and Settings\Emily\Cookies\emily@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Emily\Cookies\emily@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Emily\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Emily\Cookies\[removed][2].txt -> TrackingCookie.Etracker : Cleaned.
C:\Documents and Settings\Emily\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned.


::Report end

FINDLOP

[TRACE] Enumerating jobs and queues
[TRACE] Activating job 'A2A0972C918B13B8.job'
[TRACE] Printing all job properties

ApplicationName: 'c:\docume~1\emily\applic~1\intern~1\32 comp base.exe'
Parameters: ''
WorkingDirectory: ''
Comment: ''
Creator: 'Emily'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 09/30/2006 17:00:00
NextRun: 10/06/2006 23:00:00
StartError: 0x80070002
ExitCode: 0
Status: SCHED_S_TASK_READY
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 0
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 1
SystemRequired = 0
Hidden = 1
TaskFlags: 0

1 Trigger

Trigger 0:
Type: Daily
DaysInterval: 1
StartDate: 10/03/1995
EndDate: 00/00/0000
StartTime: 00:00
MinutesDuration: 1440
MinutesInterval: 60
Flags:
HasEndDate = 0
KillAtDuration = 0
Disabled = 0


Logfile of HijackThis v1.99.1
Scan saved at 22:08:32, on 09/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Browser MOUSE\mouse32a.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\U.S.R.TurboGWLAN\USRWLANG.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Wirelwss LAN Utility\tiwlnsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Emily\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] "C:\Program Files\Browser MOUSE\mouse32a.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk.disabled
O4 - Global Startup: AOL Companion.lnk.disabled
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: U.S. Robotics 802.11g Wireless Network Utility.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: TI Wlan Service (tiwlnsvc) - Unknown owner - C:\Program Files\Wirelwss LAN Utility\tiwlnsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe



Thanks for your help
MikeA
Copy the part in bold below into a notepad and save its as remlop.bat
Set Filetype to "All files" and save it to the same folder as findlop.bat (This is very important)

@echo off
jt /sd A2A0972C918B13B8.job
if exist c:\tasks.txt del c:\tasks.txt
jt /se >>c:\tasks.txt


Double click on remlop.bat

Delete the following folder
C:\Documents and Settings\Emily\Application Data\internetmix<=folder

Reboot and run findlop.bat and post a fresh findlop log
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI