This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Internet Exploer pop ups while using firefox?

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 10:52:39 AM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Defender\Defender Pro 2005\kav.exe
C:\Program Files\Unlocker\UnlockerAssistant .exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Defender Pro Anti Spam\dpantispam.exe
C:\WINDOWS\System32\igfxpers .exe
C:\WINDOWS\System32\hkcmd .exe
C:\Program Files\Unlocker\UnlockerAssistant .exe
C:\Program Files\Windows Defender\MSASCui .exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\qsacc\x1exec.exe
C:\WINDOWS\system32\wvotmdbu.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…www.blingo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:7900
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.44.66;64.136.52.66;searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*
windowsupdate.com;*wustat.windows.com;*.pogo.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
ociates.com;*.dir.untd.com;cf.netzero.net;qs.netzero.net;*.prod.untd.com;
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NetZero\SearchEnh1.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\awtss.exe
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Defender\Defender Pro 2005\kav.exe /minimize
O4 - HKLM\..\Run: [DPAS] "C:\Program Files\DefenderPro AntiSpy\DPASNT.exe"
O4 - HKLM\..\Run: [DPASUpdate] "C:\Program Files\DefenderPro AntiSpy\DPASAutUpdate.exe"
O4 - HKLM\..\Run: [900e7f42] rundll32.exe "C:\WINDOWS\system32\kqcwtqep.dll",b
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant .exe" -H
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DefenderProAutoRun] "C:\Program Files\Defender Pro Anti Spam\dpantispam" -D "C:\Program Files\Defender Pro Anti Spam\conf"
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1191083576984
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{46013607-7023-44E7-A32F-50DF9F797BB3}: NameServer = 64.136.52.73 64.136.44.73
O23 - Service: DomainService - - C:\WINDOWS\system32\wvotmdbu.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Labs - C:\Program Files\Defender\Defender Pro 2005\kavsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



Hi, I been trying to remove any file that was unnecessary to my computer, and the pop ups still randomly appear which really becomes annoying. I don't want to accidentally delete the wrong thing so that's why I figured I ask an expert. Thank you for your help in advance
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.

After the above:

Go here scroll down and download the scanner using the 2nd link.

It will directly download the set-up icon on your desktop.
Double-click the set-up icon on your desktop and click Next.
Accept the agreement and click Next until the program installs.
Click Finish, at the end.
Make sure you update the scanner, and perform a full scan.

Click on the go to Main Menu and a Notepad will open.
Using Edit > Select all Copy/Paste the report back here.
Malwarebytes' Anti-Malware Version 0.87 Database version: 242 Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\| ) Objects scanned: 78738 Time elapsed: 1 hour(s), 10 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 8 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 6 Files Infected: 50 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\WebBuying (Adware.WebBuying) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\core (Rootkit) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DomainService (Trojan.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DomainService (Trojan.Agent) -> No action taken. HKEY_CURRENT_USER\Software\WinTouch (Adware.WinPop) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\System (Adware.Tagasaurus) -> No action taken. HKEY_CURRENT_USER\Software\System (Adware.Tagasaurus) -> No action taken. Registry Values Infected: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.starsdoor.com (Backdoor.Bot) -> No action taken. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\WINDOWS\system32\z1 (Trojan.Downloader) -> No action taken. C:\Program Files\web buying (Adware.WebBuying) -> No action taken. C:\Program Files\web buying\v1.8.6 (Adware.WebBuying) -> No action taken. C:\Program Files\InetGet2 (Trojan.Downloader) -> No action taken. C:\Documents and Settings\Administrator\Application Data\WinTouch (Adware.WinPop) -> No action taken. C:\Program Files\Common Files\??stem32 (Adware.PurityScan) -> No action taken. Files Infected: C:\Documents and Settings\Administrator\Local Settings\Temp\removalfile.bat (Malware.Trace) -> No action taken. C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NRFYN6CO\tk58[1].exe (Trojan.BHO) -> No action taken. C:\Program Files\Messenger\lavupah.dll (Trojan.BHO) -> No action taken. C:\Program Files\Messenger\lavupah237.dll (Trojan.BHO) -> No action taken. C:\Program Files\Messenger\lavupah468.dll (Trojan.BHO) -> No action taken. C:\Program Files\Messenger\lavupah977.dll (Trojan.BHO) -> No action taken. C:\Program Files\Messenger\lavupah98.dll (Trojan.BHO) -> No action taken. C:\Program Files\Web Buying\v1.8.6\wbuninst.exe (Adware.Webbuying) -> No action taken. C:\Program Files\Web Buying\v1.8.6\webbuying .exe (Trojan.DownLoader) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP332\A0047582.dll (Trojan.BHO) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP332\A0047586.exe (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP332\A0047587.exe (Trojan.BHO) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP332\A0047608.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333\A0047636.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333\A0047793.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333\A0047794.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333\A0048049.dll (Trojan.BHO) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333\A0048112.exe (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333\A0048113.exe (Trojan.BHO) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333\snapshot\MFEX-1.DAT (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP334\A0048117.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP334\snapshot\MFEX-1.DAT (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\A0048261.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\A0048262.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\A0048264.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\A0048525.exe (Trojan.BHO) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\A0048526.exe (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\A0050372.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\A0050373.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\snapshot\MFEX-1.DAT (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP336\A0050439.dll (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP336\A0050440.dll (Trojan.BHO) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP336\A0050442.exe (Trojan.BHO) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP336\A0050444.exe (Adware.TTC) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP338\A0051185.exe (Trojan.Downloader) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP338\A0053032.exe (Adware.Webbuying) -> No action taken. C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP338\A0053033.exe (Trojan.DownLoader) -> No action taken. C:\WINDOWS\b138.exe (Trojan.Agent) -> No action taken. C:\WINDOWS\df87173.exe (Trojan.TagASaurus) -> No action taken. C:\WINDOWS\hg173.exe (Trojan.Downloader) -> No action taken. C:\WINDOWS\system32\aj2\bumebrpl5.exe (Trojan.ZQuest) -> No action taken. C:\WINDOWS\system32\mr9\gyreo83122.exe (Adware.TTC) -> No action taken. C:\WINDOWS\system32\z1\aroblcidr31z.exe (Trojan.Downloader) -> No action taken. C:\Program Files\web buying\v1.8.6\webbuying.exe (Adware.WebBuying) -> No action taken. C:\Documents and Settings\Administrator\Application Data\WinTouch\wintouch.cfg (Adware.WinPop) -> No action taken. C:\Documents and Settings\Administrator\Application Data\WinTouch\WTUninstaller.exe (Adware.WinPop) -> No action taken. C:\WINDOWS\system32\drivers\core.cache.dsk (Malware.Trace) -> No action taken. C:\WINDOWS\b122.exe (Heuristics.Downloader) -> No action taken. C:\WINDOWS\casino.INI (Malware.Trace) -> No action taken. C:\WINDOWS\system32\drivers\core.sys (Rootkit.Agent) -> No action taken.
There are signs of some nasty infections including a Rootkit and Backdoor.

Lets run an F-Secure online scan it will scan for Viruses, Spyware and RootKits:
  • Click HERE
  • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post

Note: This scan will only work with Internet Explorer.
You must be logged on a administrator rights to run this scan.
The scan may take a few hours.

Also let me know how the computer is running now.
When I run the Full System scan, this is what happens in the middle of it. I tried several times and same message appears

[external image: Posted Image]
The infections you have can be really hard to kill.

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
awtss.exe;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.; hggdaya.dll;C:\WINDOWS\system32;Trojan.Virtumod.240;Deleted.; ardCo021099.exe;C:\WINDOWS\system32\ardCo02;Trojan.DownLoader.24715;Deleted.; aroblcidr31z.exe;C:\WINDOWS\system32\z1;Trojan.DownLoader.5013;Deleted.; gamadril20071203[1];C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\H2PSMT19;Trojan.EzulaAd;Deleted.; inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.3;Probably BACKDOOR.Trojan;Incurable.Moved.; MiniBugTransporter.dll;C:\Program Files\Common Files\Real\WeatherBug;Adware.Minibug;Incurable.Moved.; Admin.exe;C:\Program Files\Defender Pro Anti Spam;Probably BACKDOOR.Trojan;Incurable.Moved.; mbam.exe;C:\Program Files\Malwarebytes' Anti-Malware;Probably BACKDOOR.Trojan;Incurable.Moved.; A0047608.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP332;Adware.Ttc;Incurable.Moved.; A0047636.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333;Adware.Ttc;Incurable.Moved.; A0047793.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333;Adware.Ttc;Incurable.Moved.; A0047794.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333;Adware.Ttc;Incurable.Moved.; MFEX-1.DAT;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP333\snapshot;Adware.Ttc;Incurable.Moved.; A0048117.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP334;Adware.Ttc;Incurable.Moved.; MFEX-1.DAT;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP334\snapshot;Adware.Ttc;Incurable.Moved.; A0048261.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335;Adware.Ttc;Incurable.Moved.; A0048262.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335;Adware.Ttc;Incurable.Moved.; A0048264.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335;Adware.Ttc;Incurable.Moved.; A0049538.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335;Adware.Minibug;Incurable.Moved.; A0050372.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335;Adware.Ttc;Incurable.Moved.; A0050373.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335;Adware.Ttc;Incurable.Moved.; MFEX-1.DAT;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP335\snapshot;Adware.Ttc;Incurable.Moved.; A0050439.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP336;Adware.Ttc;Incurable.Moved.; A0050443.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP336;Adware.DSSAgent;Incurable.Moved.; A0051676.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP338;Probably BACKDOOR.Trojan;Incurable.Moved.; A0057071.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP338;Probably BACKDOOR.Trojan;Incurable.Moved.; A0058632.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP340;Probably BACKDOOR.Trojan;Incurable.Moved.; A0061847.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.MulDrop.9785;Deleted.; A0061849.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.DownLoader.38055;Deleted.; A0061850.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.MulDrop.9974;Deleted.; A0062884.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.EzulaAd;Deleted.; A0062897.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.MulDrop.10006;Deleted.; A0062976.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.EzulaAd;Deleted.; A0063898.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.MulDrop.10006;Deleted.; A0064295.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.MulDrop.10006;Deleted.; A0064302.dll;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.Virtumod.240;Deleted.; A0064303.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.MulDrop.10006;Deleted.; A0064313.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.DownLoader.24715;Deleted.; A0064318.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.DownLoader.5013;Deleted.; A0064323.exe;C:\System Volume Information\_restore{F83ABE97-3186-4E58-9E60-1F5E8861636E}\RP343;Trojan.MulDrop.10006;Deleted.; awtss.exe;C:\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.;
Computer seems be running fine now, no random pop ups have appeared within the time frame I logged onto the computer, and then internet. So all is well now.



Logfile of HijackThis v1.99.1
Scan saved at 9:03:33 AM, on 1/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Defender Pro Anti Spam\dpantispam.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\qsacc\x1exec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…age=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:7900
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.44.66;64.136.52.66;searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*
windowsupdate.com;*wustat.windows.com;*.pogo.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
ociates.com;*.dir.untd.com;cf.netzero.net;qs.netzero.net;*.prod.untd.com;
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NetZero\SearchEnh1.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {8176B729-43E7-45D6-9F98-FDB598AA6415} - C:\WINDOWS\system32\awtss.dll
O2 - BHO: {fba94a79-793d-de6a-21b4-cb994de2e529} - {925e2ed4-99bc-4b12-a6ed-d39797a49abf} - C:\WINDOWS\system32\kxrqkivo.dll
O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll
O2 - BHO: (no name) - {cb65e6d2-2576-456c-b7d8-79e207b333ee} - C:\WINDOWS\system32\jhdlxyu.dll (file missing)
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DPASUpdate] "C:\Program Files\DefenderPro AntiSpy\DPASAutUpdate.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant .exe" -H
O4 - HKCU\..\Run: [DefenderProAutoRun] "C:\Program Files\Defender Pro Anti Spam\dpantispam" -D "C:\Program Files\Defender Pro Anti Spam\conf"
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1191083576984
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{46013607-7023-44E7-A32F-50DF9F797BB3}: NameServer = 64.136.52.73 64.136.44.73
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Labs - C:\Program Files\Defender\Defender Pro 2005\kavsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
What are you using for a Anti-Virus program?

You might still have some infections.


Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Viewpoint <–All Viewpoint programs listed



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O2 - BHO: (no name) - {8176B729-43E7-45D6-9F98-FDB598AA6415} - C:\WINDOWS\system32\awtss.dll
O2 - BHO: {fba94a79-793d-de6a-21b4-cb994de2e529} - {925e2ed4-99bc-4b12-a6ed-d39797a49abf} - C:\WINDOWS\system32\kxrqkivo.dll
O2 - BHO: (no name) - {cb65e6d2-2576-456c-b7d8-79e207b333ee} - C:\WINDOWS\system32\jhdlxyu.dll (file missing)

Close ALL windows and browsers except HijackThis and click "Fix checked"

Delete these Files if listed:
C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\kxrqkivo.dll
C:\WINDOWS\system32\jhdlxyu.dll


Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 3:31:00 PM, on 1/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Defender Pro Anti Spam\dpantispam.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…age=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NetZero\SearchEnh1.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {9F272DB2-8E0D-4D67-8512-087659DBA6E8} - C:\WINDOWS\system32\awtss.dll
O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DPASUpdate] "C:\Program Files\DefenderPro AntiSpy\DPASAutUpdate.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant .exe" -H
O4 - HKCU\..\Run: [DefenderProAutoRun] "C:\Program Files\Defender Pro Anti Spam\dpantispam" -D "C:\Program Files\Defender Pro Anti Spam\conf"
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1191083576984
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Labs - C:\Program Files\Defender\Defender Pro 2005\kavsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

oh, and the pop ups have started again :(
Yep, I can see it.

  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI