This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE Popups/Apparent Malware Inection

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sheri W.,

No problem with your timing. You have been fine. :thumbup:

Let's take a little peek in your outlook folder.

Please download DirLook by jpshortstuff from one of the following mirrors:
Link 1
Link 2
Link 3
  • Double-click DirLook.exe to run it (Vista Users should right-click and select Run As Administrator…).
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the main textfield:

    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\DirLook.txt)
Note: Scanning may take longer for large folders.

Also, can you give me a description of the popups?
Tomk.

That was a quick scan for a change! Here is the log:


—FOLDERS—

(none found)

—FILES—

archive.pst (227558400 bytes - created on 03/07/2005 at 21:18, modified on 08/01/2009 at 10:35) –a—
archive1.pst (229590016 bytes - created on 02/05/2007 at 04:03, modified on 08/01/2009 at 10:35) –a—
extend.dat (952 bytes - created on 28/03/2007 at 11:59, modified on 10/12/2008 at 10:20) –a—
mailbox.pst (44712960 bytes - created on 13/01/2005 at 01:47, modified on 06/01/2009 at 10:59) –a—
Outlook.pst (276317184 bytes - created on 07/04/2007 at 15:59, modified on 06/01/2009 at 11:02) –a—
Outlook1.pst (402277376 bytes - created on 18/04/2007 at 23:03, modified on 08/01/2009 at 17:23) –a—

==================================
=EOF=

I've also attached a photo of the pop-ups on my desktop. When I took this screenshot, there was nothing at all that I personally had running on my system. Each time the pop-ups start, the blank window opens in the background, and then the pop-ups open. They are sometimes (but not always) multiple ones as you see here.

I also wanted to mention that my system clock has been displaying in military time since I last ran ComboFix. Do you know how I can correct this?

Thanks,
Sheri W.

Attachments:

Sheri W.,

Your clock should be reset once we are done and uninstall ComboFix. However, if it is bothering you, you can reset it as follows:

If you want your clock in 12 hr vs. 24 hour format:

  • Click on Start
  • Click on Control Panel
  • Click on Regional and language options
  • Click on customize
  • Click on Time tab
  • Click on arrow to the right of time format
  • Select h:mm:ss tt
  • OK your way out

I need to work on your problem a little here. I've also asked for input from some others. I'll post back as soon as I have something meaningful to post. :blush:
Sheri W.,

Rorschach112, another malware expert here, had a good idea to try.

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:[external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Hi Tomk, Below is my Dr. Web log. I don't know if I should have had it scan my Recovery Drive or not, and some screens also looked a bit different than what you mentioned. I think I followed the instructions correctly, but I was very freaked out during the scan when the pop-ups opened differently than they have been. The blank page that I've been getting first opened as normal, but then a browser window suddenly opened a web page instead of just an advertisement. It was the creepiest thing I've ever seen because it went to something I think was called TVBytes.com (which I've never been to before) and started playing a video about Patrick Swayze's pancreatic cancer. Seriously, I thought the machine was possessed. I really need this Trojan or whatever it is off of here! :( In any case, here is the log. A lot of what it found is stuff that I recognize as being part of various programs, some of which I've just downloaded in an effort to solve this problem: RegUBP2b-HP_Administrator.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.; 1196454044jtun_firstexpirationpif.x00\Program Files\Common Files\PIF_B8E1\pifCrawl.exe;C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\1196454044jtun_firstexpirationpif.x00;Trojan.Swizzor.based;; 1196454044jtun_firstexpirationpif.x00;C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads;Archive contains infected objects;Moved.; Process.exe;C:\Documents and Settings\HP_Administrator\Desktop\SmitfraudFix;Tool.Prockill;Moved.; restart.exe;C:\Documents and Settings\HP_Administrator\Desktop\SmitfraudFix;Trojan.Shutdown.134;Deleted.; data001\F0000014.DAT;C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\corkb100.exe\data001;Adware.ClearSearch;; data001;C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\corkb100.exe;Archive contains infected objects;; corkb100.exe;C:\Documents and Settings\HP_Administrator\My Documents\My Downloads;Archive contains infected objects;Moved.; SmitfraudFix.exe\SmitfraudFix\Process.exe;C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\SmitfraudFix.exe;Tool.Prockill;; SmitfraudFix.exe\SmitfraudFix\restart.exe;C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\SmitfraudFix.exe;Trojan.Shutdown.134;; SmitfraudFix.exe;C:\Documents and Settings\HP_Administrator\My Documents\My Downloads;Archive contains infected objects;Moved.; Process.exe;C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\SmitfraudFix;Tool.Prockill;Moved.; restart.exe;C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\SmitfraudFix;Trojan.Shutdown.134;Deleted.; KillWind.exe;C:\hp\bin;Tool.ProcessKill;Moved.; pifCrawl.exe;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08};Trojan.Swizzor.based;Deleted.; stream001\uninstll.exe;C:\Program Files\Online Services\EarthLink\EarthLink Setup.exe\\Windows\access\EarthLink Setup.msi\stream001;Probably STPAGE.Trojan;; stream001;C:\Program Files\Online Services\EarthLink\EarthLink Setup.exe\\Windows\access\EarthLink Setup.msi;Archive contains infected objects;; \Windows\access\EarthLink Setup.msi;C:\Program Files\Online Services\EarthLink\EarthLink Setup.exe\\Windows\access;Archive contains infected objects;; EarthLink Setup.exe;C:\Program Files\Online Services\EarthLink;Archive contains infected objects;Moved.; A0059695.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP581;Trojan.StartPage.1505;Deleted.; A0062365.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP583;Trojan.StartPage.1505;Deleted.; A0062458.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP583;Trojan.StartPage.1505;Deleted.; A0062559.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP583;Trojan.StartPage.1505;Deleted.; A0066304.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP588;Trojan.StartPage.1505;Deleted.; A0066770.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP602;Trojan.StartPage.1505;Deleted.; A0070029.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP650;Trojan.StartPage.1505;Deleted.; A0070113.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP650;Trojan.StartPage.1505;Deleted.; A0070600.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP660;Trojan.StartPage.1505;Deleted.; A0071238.reg;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668;Trojan.StartPage.1505;Deleted.; A0071239.exe;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668;Trojan.Shutdown.134;Deleted.; A0071240.exe;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668;Trojan.Swizzor.based;Deleted.; stream001\uninstll.exe;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668\A0071241.exe\\Windows\access\EarthLink Setup.;Probably STPAGE.Trojan;; stream001;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668\A0071241.exe\\Windows\access\EarthLink Setup.;Archive contains infected objects;; \Windows\access\EarthLink Setup.msi;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668\A0071241.exe\\Windows\access;Archive contains infected objects;; A0071241.exe;C:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668;Archive contains infected objects;Moved.; hp/tmp/src/SpyPreInstall.exe\ssengine.dll;D:\I386\Apps\APP14293\App14293.exe\hp/tmp/src/SpyPreInstall.exe;Probably MULDROP.Trojan;; hp/tmp/src/SpyPreInstall.exe;D:\I386\Apps\APP14293\App14293.exe;Archive contains infected objects;; App14293.exe;D:\I386\Apps\APP14293;Archive contains infected objects;Moved.; App00545.exe\hp/tmp/firstopt.js;D:\I386\Apps\APP00545\App00545.exe;Probably SCRIPT.Virus;; App00545.exe;D:\I386\Apps\APP00545;Archive contains infected objects;Moved.; App13056.exe\hp/tmp/getgames.js;D:\I386\Apps\APP13056\App13056.exe;Probably SCRIPT.Virus;; App13056.exe;D:\I386\Apps\APP13056;Archive contains infected objects;Moved.; hp/tmp/src/SpyPreInstall.exe\ssengine.dll;D:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668\A0071242.exe\hp/tmp/src/SpyPreInstall.exe;Probably MULDROP.Trojan;; hp/tmp/src/SpyPreInstall.exe;D:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668\A0071242.exe;Archive contains infected objects;; A0071242.exe;D:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668;Archive contains infected objects;Moved.; A0071243.exe\hp/tmp/firstopt.js;D:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668\A0071243.exe;Probably SCRIPT.Virus;; A0071243.exe;D:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668;Archive contains infected objects;Moved.; A0071244.exe\hp/tmp/getgames.js;D:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668\A0071244.exe;Probably SCRIPT.Virus;; A0071244.exe;D:\System Volume Information\_restore{55BCF168-B898-45C8-B42E-812AFE89FD32}\RP668;Archive contains infected objects;Moved.; Question – what did this change on my system? The second I re-booted, the pop-ups started again, so I know it hasn't fixed this particular issue. Maybe this was just to identify it? Thanks, Sheri Wl
Sheri W.,

The hope was that Dr.Web CureIt would in fact find and fix the cause of your pop-ups. Obviously, it didn't.

This scan won't fix anything, it just provides information.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Tomk, Could you please explain a little more about disabling script blocking protection? I'll probably need to wait for this scan until after work since I need to leave shortly, but just wanted to make sure I handle it correctly later. Thanks, Sheri W.
Sheri W., It's the "real-time" component of you Anti-Virus or Anti-Spyware. It's the same thing you did before running combofix. In your case it was disabling the real time component of Norton Internet Security.
Hi Tomk, Okay, here is my DDS log with the Attach.txt file attached. DDS (Ver_09-01-07.01) - NTFSx86 Run by [removed] at 18:29:16.75 on Fri 01/09/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.441 [GMT -5:00] AV: Norton Internet Security *On-access scanning disabled* (Updated) FW: Norton Internet Security *enabled* ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\CTSvcCDA.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\GFI\Network Server Monitor 7\NSMwebsrv.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\oracle\ora92\bin\omtsreco.exe C:\oracle\ora92\Apache\Apache\apache.exe C:\oracle\ora92\BIN\TNSLSNR.exe c:\oracle\ora92\bin\ORACLE.EXE c:\oracle\ora92\bin\ORACLE.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\MsPMSPSv.exe C:\oracle\ora92\Apache\Apache\apache.exe c:\oracle\ora92\bin\isqlplus C:\oracle\ora92\jdk\bin\java.exe C:\oracle\ora92\jdk\bin\java.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\hphmon06.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\ALCWZRD.EXE C:\WINDOWS\system32\CTHELPER.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\GIANT Company Software\Spam Inspector\siService.exe C:\Program Files\ATI Multimedia\main\ATIDtct.EXE C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\system32\WDBtnMgr.exe C:\Program Files\GIANT Company Software\Spam Inspector\siMailProxyServer.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\GIANT Company Software\Spam Inspector\siSpamFilterEngine.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Impact Software LLC\Notice\NoticeP.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft Money Plus\MNYCoreFiles\mnyinsit.exe C:\Program Files\Microsoft Money Plus\MNYCoreFiles\mnybbsvc.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Smileycons\smileycons.exe C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe C:\WINDOWS\system32\HPZipm12.exe C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\MI1933~1\OFFICE11\OUTLOOK.EXE C:\Program Files\GIANT Company Software\Spam Inspector\siMain.exe C:\Documents and Settings\HP_Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.0\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.0\CoIEPlg.dll uRun: [Acme.PCHButton] c:\progra~1\helpan~1\hpq\xpxwwpp5\plugin\bin\PCHButton.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [ATI Launchpad] "c:\program files\ati multimedia\main\launchpd.exe" uRun: [MoneyInsights] "c:\program files\microsoft money plus\mnycorefiles\mnyinsit.exe" uRun: [MoneyBackgoundBanking] "c:\program files\microsoft money plus\mnycorefiles\mnybbsvc.exe" uRun: [Smileycons] c:\program files\smileycons\smileycons.exe uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HPHUPD06] c:\program files\hp\{aac4fc36-8f89-4587-8dd3-ebc57c83374d}\hphupd06.exe mRun: [HPHmon06] c:\windows\system32\hphmon06.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [AlcWzrd] ALCWZRD.EXE mRun: [AlcxMonitor] ALCXMNTR.EXE mRun: [PS2] c:\windows\system32\ps2.exe mRun: [CTHelper] CTHELPER.EXE mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [CTDVDDET] c:\program files\creative\sbaudigy2zs\dvdaudio\CTDVDDet.EXE mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [siService.exe] "c:\program files\giant company software\spam inspector\siService.exe" mRun: [ATI DeviceDetect] c:\program files\ati multimedia\main\ATIDtct.EXE mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [WD Button Manager] WDBtnMgr.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [NoticeP.exe] c:\program files\impact software llc\notice\NoticeP.exe mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [DNS7reminder] "c:\program files\nuance\naturallyspeaking10\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\nuance\naturallyspeaking10\Ereg.ini dRunOnce: [SetDefaultMIDI] MIDIDEF.EXE dRunOnce: [StartMS] "c:\program files\creative\shared files\media sniffer\StartMS.EXE" /s dRunOnce: [CMSRegOW.exe] "c:\program files\installshield installation information\{56f3e1ff-54fe-4384-a153-6ccaba097814}\CMSRegOW.exe" /r StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\buffal~1.lnk - c:\program files\buffalo\linkstation\LsBackup.exe StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\apcups~1.lnk - c:\program files\apc\apc powerchute personal edition\Display.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\309731\program\Updates from HP.exe IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: Add To HP Organize… - c:\progra~1\hewlet~1\hporga~1\bin/module.main/favorites\ie_add_to.html IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - ============= SERVICES / DRIVERS =============== R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-12-22 8944] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-12-22 55024] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-9-9 99376] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090109.003\NAVENG.SYS [2009-1-9 89104] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090109.003\NAVEX15.SYS [2009-1-9 876112] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-22 7408] R3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2007-12-6 1251720] R4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352] R4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352] R4 GFI NSM 7 Attendant;GFI Network Server Monitor 7.0 attendant service;c:\program files\gfi\network server monitor 7\nsm_attendant.exe [2007-7-16 207944] R4 GFI NSM 7 Engine;GFI Network Server Monitor 7.0 engine;c:\program files\gfi\network server monitor 7\nsm_engine.exe [2007-8-2 595216] R4 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352] R4 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064] R4 OracleOraHome92HTTPServer;OracleOraHome92HTTPServer;c:\oracle\ora92\apache\apache\Apache.exe [2002-4-18 4096] R4 OracleServiceIU;OracleServiceIU;c:\oracle\ora92\bin\oracle.exe iu –> c:\oracle\ora92\bin\ORACLE.EXE IU [?] R4 OracleServiceN2;OracleServiceN2;c:\oracle\ora92\bin\oracle.exe n2 –> c:\oracle\ora92\bin\ORACLE.EXE N2 [?] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-5-29 23888] S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-9-19 33752] S3 OracleOraHome92SNMPPeerEncapsulator;OracleOraHome92SNMPPeerEncapsulator;c:\oracle\ora92\bin\encsvc.exe [2002-2-13 187392] S3 OracleOraHome92SNMPPeerMasterAgent;OracleOraHome92SNMPPeerMasterAgent;c:\oracle\ora92\bin\agntsvc.exe [2002-2-13 254464] S4 OracleOraHome92Agent;OracleOraHome92Agent;c:\oracle\ora92\bin\agntsrvc.exe [2002-4-26 28944] =============== Created Last 30 ================ 2009-01-08 20:35 –d—– c:\documents and settings\hp_administrator\DoctorWeb 2009-01-08 11:40 250 a——- c:\windows\gmer.ini 2009-01-06 11:14 –d—– c:\docume~1\hp_adm~1\applic~1\ieSpell 2009-01-05 20:04 –d—– c:\program files\ieSpell 2009-01-05 19:30 161,792 a——- c:\windows\SWREG.exe 2009-01-05 19:30 98,816 a——- c:\windows\sed.exe 2009-01-05 07:20 –d—– c:\docume~1\alluse~1\applic~1\DietPower4.4 2009-01-05 07:20 –d—– c:\program files\DietPower 4.4 2009-01-05 07:20 –d-h— c:\docume~1\alluse~1\applic~1\{B2C2A7FA-E16C-47D5-A3AA-FE006FCB3E39} 2009-01-03 09:20 –d—– c:\docume~1\hp_adm~1\applic~1\Malwarebytes 2009-01-03 09:20 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-01-03 09:20 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-03 09:20 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-01-03 09:20 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-01-03 09:13 –d—– c:\program files\Trend Micro 2009-01-01 20:49 –d—– c:\program files\RogueRemover FREE 2009-01-01 19:14 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-01-01 19:12 –d—– c:\program files\SUPERAntiSpyware 2009-01-01 19:12 –d—– c:\docume~1\hp_adm~1\applic~1\SUPERAntiSpyware.com 2008-12-26 20:05 750 a——- C:\unprogramDlls.tmp 2008-12-23 19:53 3,154 a——- c:\docume~1\hp_adm~1\applic~1\SAS7_000.DAT 2008-12-23 17:48 –d—– c:\docume~1\hp_adm~1\applic~1\Nuance 2008-12-23 17:29 –d—– c:\program files\common files\ScanSoft Shared 2008-12-23 17:28 –d—– c:\program files\common files\Nuance 2008-12-23 17:27 –d—– c:\program files\Nuance 2008-12-23 17:27 –d—– c:\docume~1\alluse~1\applic~1\Nuance 2008-12-23 17:27 –d—– c:\windows\speech 2008-12-21 20:09 410,984 a——- c:\windows\system32\deploytk.dll 2008-12-14 07:29 –d—– c:\program files\Impact Software LLC ==================== Find3M ==================== 2009-01-08 20:57 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-01-08 20:57 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2009-01-08 20:57 10,635 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-01-08 20:57 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2008-12-01 12:56 53,248 a——- c:\windows\system32\RT_Subclasser.dll 2008-12-01 12:56 36,864 a——- c:\windows\system32\DLLLDR.dll 2008-10-23 07:36 286,720 a——- c:\windows\system32\gdi32.dll 2008-10-21 09:59 155,995 a——- c:\windows\java\packages\DJ7BNN7D.ZIP 2008-10-21 09:59 2,232 a——- c:\windows\java\packages\data\VF9Z17LJ.DAT 2008-10-21 09:59 2,678 a——- c:\windows\java\packages\data\AJ1N5BTJ.DAT 2008-10-21 09:59 2,678 a——- c:\windows\java\packages\data\AB3FHJRF.DAT 2008-10-21 09:59 2,678 a——- c:\windows\java\packages\data\HRRLR3HV.DAT 2008-10-21 09:59 2,678 a——- c:\windows\java\packages\data\FJVXFLBR.DAT 2008-10-21 09:59 2,678 a——- c:\windows\java\packages\data\D33TV57J.DAT 2008-10-16 15:38 826,368 a——- c:\windows\system32\wininet.dll 2008-10-16 14:06 268,648 a——- c:\windows\system32\mucltui.dll 2008-10-16 14:06 208,744 a——- c:\windows\system32\muweb.dll 2008-02-21 13:39 32,768 a——- c:\documents and settings\hp_administrator\WebVpnRegKey6-66-193-208-2.dll 2005-05-19 18:13 23,440 ——– c:\docume~1\hp_adm~1\applic~1\wklnhst.dat 2005-03-29 23:36 0 a–sh— c:\windows\sminst\HPCD.SYS 2008-08-23 11:27 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082320080824\index.dat ============= FINISH: 18:30:06.73 =============== I had left my computer on today when I went to work and came home to find that the vrus or whatever it is had "visited" TVBytes.com again as it did yesterday. 'That IE window was open along with 3 of the pop-up advertisements. I hope this log will identify the problem! Thanks, Sheri W.

Attachments:

Sheri W.,

You have a bunch of old Java installs. This will remove them and just leave you with the most current. Old Java can be exploited and make you vulnerable to infections. I'm not convinced that this is the root of your problem but we need to get them off.

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.
Sheri W.,

I've got two more things I'd like you to do. Afterwords, try it for awhile and see how it goes.

First:
Start Internet Explorer
Click on Tools (it is probably in the upper right of your screen with an Icon that looks like a gear)
Click on Pop Up Blocker
Then click on Pop Up Blocker Settings
In the little box at the bottom, select Medium: Block most Automatic pop-ups
Click on Close button.

Then

Follow this link: MVPS Hosts file
Follow the directions to install a custom hosts file.

That's it for now. Let me know what happens.
Tomk.

I've followed all the instructions from your last 2 posts and something finally changed in the pop-ups after I installed the MVPS Hosts file. For the first time, I stopped getting the blank IE window opening in the background. Instead, the advertisement window opens by itself, but it obviously can't reach where it wants to go. The links within the ad are not opening. I've attached a screenshot.

Before I post my JavaRa log, there is something else very important I want to get your insight on. I always leave my computer on overnight to perform a backup and 2 or 3 of these pop-ups have typically opened on my desktop by the time I get up in the morning. Today, I tried to close them down as a group and it triggered an error regarding "Impact Software". As it so happens, some of the pop-up advertisements have mentioned Impact Software. I do indeed have a folder for Impact Software in my Program files, and it's related to a Bibliography Writer that I downloaded recently last semester for school when I was doing a research paper. As far as I'm concerned, I uninstalled it after the class, and it didn't give me any trouble until I accidentally sent myself the infected e-mail with the notes from my daughter's machine.

In addition, I looked at the processes running on my machine when the pop-ups are actually open on my desktop as opposed to when I've closed them down. There were 3 instances of In-Page.exe running on my system with the pop-ups open that terminated when I closed the ads. Lo and behold, there is an InPage.exe application file inside the Impact Software folder. I also found that rsmsink.exe was running only when the pop-ups were open, and I'm reading online that some malware disguises itself as rsmsink. Please see http://www.file.net/process/rsmsink.exe.html.

There are various programs online that will check rsmsink to make sure it's really Windows or is in disguise as malware, but I wanted your advice on which to run. Also, I definitely want to get rid of the entire folder for Impact Software, but don't want to just delete it my Program files.which may leave over registry keys or what have you. Please let me know how I should handle.

Here is my JavaRa log. I found I got an error from the nsm engine after I ran JavaRa, but the nsm engine was associated with a GFI Network Server Monitor that I had needed for school at one time. I don't need GFI anymore, so I just uninstalled it.

JavaRa 1.13 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Sat Jan 10 06:40:32 2009

Found and removed: C:\Program Files\Java\j2re1.4.2_03

Found and removed: C:\Program Files\Java\jre1.6.0_01

Found and removed: C:\Program Files\Java\jre1.6.0_02

Found and removed: C:\Program Files\Java\jre1.6.0_03

Found and removed: C:\Program Files\Java\jre1.6.0_05

Found and removed: C:\Program Files\Java\jre1.6.0_07

Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142030}

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\JavaPlugin.160_01

Found and removed: SOFTWARE\Classes\JavaPlugin.160_02

Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_02

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_02

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610002

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160010}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160020}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142030}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203

Found and removed: SOFTWARE\Classes\JavaPlugin.142_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_03

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\JavaPlugin.142_03

Found and removed: Software\Classes\JavaPlugin.160_01

Found and removed: Software\Classes\JavaPlugin.160_02

Found and removed: Software\Classes\JavaPlugin.160_03

Found and removed: Software\Classes\JavaPlugin.160_05

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

Found and removed: Software\JavaSoft\Java2D\1.6.0_01

Found and removed: Software\JavaSoft\Java2D\1.6.0_02

Found and removed: Software\JavaSoft\Java2D\1.6.0_03

Found and removed: Software\JavaSoft\Java2D\1.6.0_04

Found and removed: Software\JavaSoft\Java2D\1.6.0_05

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_02

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_01.b06\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_03.b05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_05.b13\

————————————

Finished reporting.

I'll wait to hear from you before doing any more, but it looks like this is finally getting somewhere. :yeah:

Thanks,
Sheri W.
Sheri W.,

That is great news. :woot:

The error in regards to Impact Software is everything I could hope for.

Filename: NoticeP.exe
Description: Related to iSync 2.1! Transfer and Sync your downloaded music to iTunes!
The TRIAL version displays advertisements. The ads disappear when the user purchases the software.


I have been trying to find more out about this application to see if:
1) It could be involved in what you are experiencing
2) What would happen to iSync if it was removed.

Still don't know answer to #2 but it appear that the answer to #1 is a resounding yes.

The attach.txt file you gave me after running DDS contains a list of installed programs. iSync doesn't appear on it. There is/was also nothing I can/could identify as Impact Software. I was not aware of the Bibliography Software from Impact but I don't see anything in your installed programs anyway. Based on your statement that you uninstalled it, I'm guessing that it just left you with a "little friend".

That all being said, I think we can nuke that folder without breaking anything. So:

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O4 - HKLM\..\Run: [NoticeP.exe] C:\Program Files\Impact Software LLC\Notice\NoticeP.exe
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.


Using Windows Explorer (Windows Key + E), locate the following folder, and DELETE it:
C:\Program Files\Impact Software LLC <–This folder

I don't think you should worry about rsmsink right now. It is your removable storage manager. It managers your USB devices. You provided a link to file.net that sounded like they were warning about this file. If you look around that site you will see that they provide a warning for every file that malware could disguise themselves as that name. While that is true, I believe it is unlikely.

Get rid of the Impact Software by following the instructions above, and then let me know how it goes. I think you are going to be pleased with the result. :popcorn:
Tomk, I followed your instructions, re-booted the machine, and then left the room for a while because I was afraid of speaking too soon. When I came back in - NO POP-UPS! This is the first time I've re-booted without the ads starting up within the first minute, so I actually think we did it! :woot: You've been so patient through this. THANKS SO MUCH! Please let me know if there is any other clean-up I should do, but I otherwise think my problem is solved. Sheri W.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI