Results 1 to 3 of 3

Thread: cant stop popuppers.com from loading

  1. #1
    Junior Member
    Join Date
    Nov 2006
    Posts
    1

    Default cant stop popuppers.com from loading

    ok i cant get popuppers.com from loading on my computer. i just ran hijack this and here is the log:

    Logfile of HijackThis v1.99.1
    Scan saved at 2:41:43 PM, on 11/16/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Executive Software\Diskeeper\DkService.exe
    C:\WINDOWS\system32\tgbstarter.exe
    C:\Program Files\ORL\VNC\WinVNC.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\DeltTray.exe
    C:\Program Files\NASDAK\OmniMouse Driver\4.06\MOUSE32A.EXE
    C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\Linksys\Linksys VPN Client\VPNClient.exe
    C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
    C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
    C:\WINDOWS\next06.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\SecCopy\SecCopy.exe
    C:\Program Files\AboutTime\AboutTime.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\slimgbxt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\DOCUME~1\mts\LOCALS~1\Temp\Temporary Directory 1 for

    hijackthis.zip\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search

    Bar =

    http://red.clientapps.yahoo.com/cust.../defaults/sb/*

    http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search

    Page =

    http://red.clientapps.yahoo.com/cust.../defaults/sp/*

    http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

    Page = http://webmail.commonwealthbroadcasting.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search

    Bar = http://go.compaq.com/1Q00CDT/0409/bl8.asp
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start

    Page = http://go.compaq.com/1Q00CDT/0409/bl7.asp
    R1 - HKCU\Software\Microsoft\Internet

    Explorer\SearchURL,(Default) =

    http://red.clientapps.yahoo.com/cust.../defaults/su/*

    http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection

    Wizard,ShellNext = http://go.compaq.com/1Q00CDT/0409/bl7.asp
    R0 - HKCU\Software\Microsoft\Internet

    Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) -

    {A55581DC-2CDB-4089-8878-71A080B22342} - (no file)
    O2 - BHO: AcroIEHlprObj Class -

    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

    Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA}

    - C:\WINDOWS\system32\mxvfefyp.dll (file missing)
    O2 - BHO: (no name) - {31B0FD56-C124-452C-B1D9-80F951BE8946}

    - C:\WINDOWS\system32\pmkhi.dll (file missing)
    O2 - BHO: RunBus Class -

    {4865F155-CE00-4E93-A414-147844D7C81A} -

    C:\WINDOWS\system32\tcblanas.dll
    O2 - BHO: Yahoo! IE Services Button -

    {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

    Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: Banner Rotator -

    {E954DB82-1533-4714-92F2-59C98D5C18CC} -

    C:\WINDOWS\system32\brrotate.dll
    O3 - Toolbar: Yahoo! Toolbar -

    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

    Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &VSToolBar -

    {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program

    Files\VSToolbar\VSToolBar.dll
    O4 - HKLM\..\Run: [M-Audio Delta Taskbar Icon]

    C:\WINDOWS\System32\DeltTray.exe
    O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
    O4 - HKLM\..\Run: [LWBMOUSE] C:\Program

    Files\NASDAK\OmniMouse Driver\4.06\MOUSE32A.EXE
    O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni

    keyboard driver\5.0\KbdAp32A.exe
    O4 - HKLM\..\Run: [AVG7_CC]

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC]

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [WinVNC] "C:\Program

    Files\ORL\VNC\WinVNC.exe" -servicehelper
    O4 - HKLM\..\Run: [VPN] C:\Program Files\Linksys\Linksys VPN

    Client\VPNClient.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

    Files\Java\jre1.5.0_02\bin\jusched.exe
    O4 - HKLM\..\Run: [mmnext06] C:\WINDOWS\next06.exe
    O4 - HKLM\..\Run: [adstart] "iexplore.exe"

    "http://iesettingsupdate"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN

    Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program

    Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Second Copy 2000] "C:\Program

    Files\SecCopy\SecCopy.exe"
    O4 - HKCU\..\Run: [Second Copy] "C:\Program

    Files\SecCopy\SecCopy.exe"
    O4 - HKCU\..\Run: [Chckup] C:\WINDOWS\system32\Netverchk.exe
    O4 - Global Startup: AboutTime.lnk = C:\Program

    Files\AboutTime\AboutTime.exe
    O8 - Extra context menu item: &Yahoo! Search -

    file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! &Dictionary -

    file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps -

    file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS -

    file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

    Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

    Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Yahoo! Services -

    {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

    Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}

    (YInstStarter Class) - C:\Program

    Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {400429E4-BED4-472E-93BF-F85AB8565DFF} -

    http://www.terp17.com/ax/axo.cab
    O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} -

    http://cabs.elitemediagroup.net/cabs/eliteview.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}

    (WUWebControl Class) -

    http://v5.windowsupdate.microsoft.co...r/V5Controls/e

    n/x86/client/wuweb_site.cab?1115686169406
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}

    (GpcContainer Class) -

    https://omt.webex.com/client/v_myweb...ex/ieatgpc.cab
    O17 -

    HKLM\System\CCS\Services\Tcpip\..\{0383DB38-9FF4-41CD-8497-9B

    A9A1F0CA30}: NameServer = 192.168.2.1
    O17 -

    HKLM\System\CS1\Services\Tcpip\..\{0383DB38-9FF4-41CD-8497-9B

    A9A1F0CA30}: NameServer = 192.168.2.1
    O18 - Protocol: msnim -

    {828030A1-22C1-4009-854F-8E305202313F} -

    "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: igfxcui - igfxsrvc.dll (file missing)
    O20 - Winlogon Notify: pmkhi - C:\WINDOWS\system32\pmkhi.dll

    (file missing)
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) -

    GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT,

    s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Diskeeper - Executive Software International,

    Inc. - C:\Program Files\Executive

    Software\Diskeeper\DkService.exe
    O23 - Service: TgbIke Starter (TgbIKE Starter) - Unknown

    owner - C:\WINDOWS\system32\tgbstarter.exe
    O23 - Service: VNC Server (winvnc) - Unknown owner -

    C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)


    thanks for any help you can provide.

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Hello

    Please follow the procedure here: "BEFORE you POST" -Preliminary Steps and scanning with SPYBOT-S&D Also take a look at the instructions for making a HJT log.

    Then a helper will assist you as soon as available to do so.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #3
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Due to lack of responses this thread is closed
    If you still need assistance a new log will be needed, send me or Tashi a PM (personal message) and we will re-open it.
    ~~~~~~~~~~~~~~~~~~~~~~~
    Microsoft MVP Windows-Security 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •