PDA

View Full Version : cant stop popuppers.com from loading



bgsamevents
2006-11-16, 22:53
ok i cant get popuppers.com from loading on my computer. i just ran hijack this and here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 2:41:43 PM, on 11/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\system32\tgbstarter.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DeltTray.exe
C:\Program Files\NASDAK\OmniMouse Driver\4.06\MOUSE32A.EXE
C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Linksys\Linksys VPN Client\VPNClient.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINDOWS\next06.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SecCopy\SecCopy.exe
C:\Program Files\AboutTime\AboutTime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\slimgbxt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\mts\LOCALS~1\Temp\Temporary Directory 1 for

hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search

Bar =

http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*

http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search

Page =

http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*

http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

Page = http://webmail.commonwealthbroadcasting.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search

Bar = http://go.compaq.com/1Q00CDT/0409/bl8.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start

Page = http://go.compaq.com/1Q00CDT/0409/bl7.asp
R1 - HKCU\Software\Microsoft\Internet

Explorer\SearchURL,(Default) =

http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*

http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection

Wizard,ShellNext = http://go.compaq.com/1Q00CDT/0409/bl7.asp
R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) -

{A55581DC-2CDB-4089-8878-71A080B22342} - (no file)
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}

- C:\WINDOWS\system32\mxvfefyp.dll (file missing)
O2 - BHO: (no name) - {31B0FD56-C124-452C-B1D9-80F951BE8946}

- C:\WINDOWS\system32\pmkhi.dll (file missing)
O2 - BHO: RunBus Class -

{4865F155-CE00-4E93-A414-147844D7C81A} -

C:\WINDOWS\system32\tcblanas.dll
O2 - BHO: Yahoo! IE Services Button -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Banner Rotator -

{E954DB82-1533-4714-92F2-59C98D5C18CC} -

C:\WINDOWS\system32\brrotate.dll
O3 - Toolbar: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &VSToolBar -

{821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program

Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [M-Audio Delta Taskbar Icon]

C:\WINDOWS\System32\DeltTray.exe
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program

Files\NASDAK\OmniMouse Driver\4.06\MOUSE32A.EXE
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni

keyboard driver\5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [AVG7_CC]

C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC]

C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program

Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [VPN] C:\Program Files\Linksys\Linksys VPN

Client\VPNClient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmnext06] C:\WINDOWS\next06.exe
O4 - HKLM\..\Run: [adstart] "iexplore.exe"

"http://iesettingsupdate"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN

Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program

Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Second Copy 2000] "C:\Program

Files\SecCopy\SecCopy.exe"
O4 - HKCU\..\Run: [Second Copy] "C:\Program

Files\SecCopy\SecCopy.exe"
O4 - HKCU\..\Run: [Chckup] C:\WINDOWS\system32\Netverchk.exe
O4 - Global Startup: AboutTime.lnk = C:\Program

Files\AboutTime\AboutTime.exe
O8 - Extra context menu item: &Yahoo! Search -

file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary -

file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -

file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS -

file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Services -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}

(YInstStarter Class) - C:\Program

Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {400429E4-BED4-472E-93BF-F85AB8565DFF} -

http://www.terp17.com/ax/axo.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} -

http://cabs.elitemediagroup.net/cabs/eliteview.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}

(WUWebControl Class) -

http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/e

n/x86/client/wuweb_site.cab?1115686169406
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}

(GpcContainer Class) -

https://omt.webex.com/client/v_mywebex-t20/webex/ieatgpc.cab
O17 -

HKLM\System\CCS\Services\Tcpip\..\{0383DB38-9FF4-41CD-8497-9B

A9A1F0CA30}: NameServer = 192.168.2.1
O17 -

HKLM\System\CS1\Services\Tcpip\..\{0383DB38-9FF4-41CD-8497-9B

A9A1F0CA30}: NameServer = 192.168.2.1
O18 - Protocol: msnim -

{828030A1-22C1-4009-854F-8E305202313F} -

"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - igfxsrvc.dll (file missing)
O20 - Winlogon Notify: pmkhi - C:\WINDOWS\system32\pmkhi.dll

(file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) -

GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT,

s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International,

Inc. - C:\Program Files\Executive

Software\Diskeeper\DkService.exe
O23 - Service: TgbIke Starter (TgbIKE Starter) - Unknown

owner - C:\WINDOWS\system32\tgbstarter.exe
O23 - Service: VNC Server (winvnc) - Unknown owner -

C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)


thanks for any help you can provide.

tashi
2006-11-16, 23:02
Hello

Please follow the procedure here: "BEFORE you POST" -Preliminary Steps and scanning with SPYBOT-S&D (http://forums.spybot.info/showthread.php?t=288) Also take a look at the instructions for making a HJT log.

Then a helper will assist you as soon as available to do so. :)

LonnyRJones
2006-11-26, 00:54
Due to lack of responses this thread is closed
If you still need assistance a new log will be needed, send me or Tashi a PM (personal message) and we will re-open it.