bgsamevents
2006-11-16, 22:53
ok i cant get popuppers.com from loading on my computer. i just ran hijack this and here is the log:
Logfile of HijackThis v1.99.1
Scan saved at 2:41:43 PM, on 11/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\system32\tgbstarter.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DeltTray.exe
C:\Program Files\NASDAK\OmniMouse Driver\4.06\MOUSE32A.EXE
C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Linksys\Linksys VPN Client\VPNClient.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINDOWS\next06.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SecCopy\SecCopy.exe
C:\Program Files\AboutTime\AboutTime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\slimgbxt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\mts\LOCALS~1\Temp\Temporary Directory 1 for
hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Bar =
http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*
http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*
http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://webmail.commonwealthbroadcasting.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Bar = http://go.compaq.com/1Q00CDT/0409/bl8.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page = http://go.compaq.com/1Q00CDT/0409/bl7.asp
R1 - HKCU\Software\Microsoft\Internet
Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*
http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection
Wizard,ShellNext = http://go.compaq.com/1Q00CDT/0409/bl7.asp
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) -
{A55581DC-2CDB-4089-8878-71A080B22342} - (no file)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}
- C:\WINDOWS\system32\mxvfefyp.dll (file missing)
O2 - BHO: (no name) - {31B0FD56-C124-452C-B1D9-80F951BE8946}
- C:\WINDOWS\system32\pmkhi.dll (file missing)
O2 - BHO: RunBus Class -
{4865F155-CE00-4E93-A414-147844D7C81A} -
C:\WINDOWS\system32\tcblanas.dll
O2 - BHO: Yahoo! IE Services Button -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program
Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Banner Rotator -
{E954DB82-1533-4714-92F2-59C98D5C18CC} -
C:\WINDOWS\system32\brrotate.dll
O3 - Toolbar: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &VSToolBar -
{821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program
Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [M-Audio Delta Taskbar Icon]
C:\WINDOWS\System32\DeltTray.exe
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program
Files\NASDAK\OmniMouse Driver\4.06\MOUSE32A.EXE
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni
keyboard driver\5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program
Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [VPN] C:\Program Files\Linksys\Linksys VPN
Client\VPNClient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmnext06] C:\WINDOWS\next06.exe
O4 - HKLM\..\Run: [adstart] "iexplore.exe"
"http://iesettingsupdate"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN
Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program
Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Second Copy 2000] "C:\Program
Files\SecCopy\SecCopy.exe"
O4 - HKCU\..\Run: [Second Copy] "C:\Program
Files\SecCopy\SecCopy.exe"
O4 - HKCU\..\Run: [Chckup] C:\WINDOWS\system32\Netverchk.exe
O4 - Global Startup: AboutTime.lnk = C:\Program
Files\AboutTime\AboutTime.exe
O8 - Extra context menu item: &Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS -
file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Services -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program
Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
(YInstStarter Class) - C:\Program
Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {400429E4-BED4-472E-93BF-F85AB8565DFF} -
http://www.terp17.com/ax/axo.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} -
http://cabs.elitemediagroup.net/cabs/eliteview.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/e
n/x86/client/wuweb_site.cab?1115686169406
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
(GpcContainer Class) -
https://omt.webex.com/client/v_mywebex-t20/webex/ieatgpc.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{0383DB38-9FF4-41CD-8497-9B
A9A1F0CA30}: NameServer = 192.168.2.1
O17 -
HKLM\System\CS1\Services\Tcpip\..\{0383DB38-9FF4-41CD-8497-9B
A9A1F0CA30}: NameServer = 192.168.2.1
O18 - Protocol: msnim -
{828030A1-22C1-4009-854F-8E305202313F} -
"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - igfxsrvc.dll (file missing)
O20 - Winlogon Notify: pmkhi - C:\WINDOWS\system32\pmkhi.dll
(file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) -
GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT,
s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International,
Inc. - C:\Program Files\Executive
Software\Diskeeper\DkService.exe
O23 - Service: TgbIke Starter (TgbIKE Starter) - Unknown
owner - C:\WINDOWS\system32\tgbstarter.exe
O23 - Service: VNC Server (winvnc) - Unknown owner -
C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)
thanks for any help you can provide.
Logfile of HijackThis v1.99.1
Scan saved at 2:41:43 PM, on 11/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\system32\tgbstarter.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DeltTray.exe
C:\Program Files\NASDAK\OmniMouse Driver\4.06\MOUSE32A.EXE
C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Linksys\Linksys VPN Client\VPNClient.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINDOWS\next06.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SecCopy\SecCopy.exe
C:\Program Files\AboutTime\AboutTime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\slimgbxt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\mts\LOCALS~1\Temp\Temporary Directory 1 for
hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Bar =
http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*
http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*
http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://webmail.commonwealthbroadcasting.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Bar = http://go.compaq.com/1Q00CDT/0409/bl8.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page = http://go.compaq.com/1Q00CDT/0409/bl7.asp
R1 - HKCU\Software\Microsoft\Internet
Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*
http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection
Wizard,ShellNext = http://go.compaq.com/1Q00CDT/0409/bl7.asp
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) -
{A55581DC-2CDB-4089-8878-71A080B22342} - (no file)
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}
- C:\WINDOWS\system32\mxvfefyp.dll (file missing)
O2 - BHO: (no name) - {31B0FD56-C124-452C-B1D9-80F951BE8946}
- C:\WINDOWS\system32\pmkhi.dll (file missing)
O2 - BHO: RunBus Class -
{4865F155-CE00-4E93-A414-147844D7C81A} -
C:\WINDOWS\system32\tcblanas.dll
O2 - BHO: Yahoo! IE Services Button -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program
Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Banner Rotator -
{E954DB82-1533-4714-92F2-59C98D5C18CC} -
C:\WINDOWS\system32\brrotate.dll
O3 - Toolbar: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &VSToolBar -
{821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program
Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [M-Audio Delta Taskbar Icon]
C:\WINDOWS\System32\DeltTray.exe
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program
Files\NASDAK\OmniMouse Driver\4.06\MOUSE32A.EXE
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni
keyboard driver\5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program
Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [VPN] C:\Program Files\Linksys\Linksys VPN
Client\VPNClient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmnext06] C:\WINDOWS\next06.exe
O4 - HKLM\..\Run: [adstart] "iexplore.exe"
"http://iesettingsupdate"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN
Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program
Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Second Copy 2000] "C:\Program
Files\SecCopy\SecCopy.exe"
O4 - HKCU\..\Run: [Second Copy] "C:\Program
Files\SecCopy\SecCopy.exe"
O4 - HKCU\..\Run: [Chckup] C:\WINDOWS\system32\Netverchk.exe
O4 - Global Startup: AboutTime.lnk = C:\Program
Files\AboutTime\AboutTime.exe
O8 - Extra context menu item: &Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS -
file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Services -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program
Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
(YInstStarter Class) - C:\Program
Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {400429E4-BED4-472E-93BF-F85AB8565DFF} -
http://www.terp17.com/ax/axo.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} -
http://cabs.elitemediagroup.net/cabs/eliteview.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/e
n/x86/client/wuweb_site.cab?1115686169406
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
(GpcContainer Class) -
https://omt.webex.com/client/v_mywebex-t20/webex/ieatgpc.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{0383DB38-9FF4-41CD-8497-9B
A9A1F0CA30}: NameServer = 192.168.2.1
O17 -
HKLM\System\CS1\Services\Tcpip\..\{0383DB38-9FF4-41CD-8497-9B
A9A1F0CA30}: NameServer = 192.168.2.1
O18 - Protocol: msnim -
{828030A1-22C1-4009-854F-8E305202313F} -
"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - igfxsrvc.dll (file missing)
O20 - Winlogon Notify: pmkhi - C:\WINDOWS\system32\pmkhi.dll
(file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) -
GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT,
s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International,
Inc. - C:\Program Files\Executive
Software\Diskeeper\DkService.exe
O23 - Service: TgbIke Starter (TgbIKE Starter) - Unknown
owner - C:\WINDOWS\system32\tgbstarter.exe
O23 - Service: VNC Server (winvnc) - Unknown owner -
C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)
thanks for any help you can provide.