Well, to get directly to the point, I'm infected with something that doesn't like me; a given, or else I wouldn't be here. A couple of days ago I began getting popups, two in general, and after a couple hours of scans have seem to have gotten rid of one of the pesty programs that caused said popups. Alternatively, I still seem unable to rid myself of the second program, which none of my scanners can remove.
Multiple McAfee Virus scans come up with this "Dialer-269," with no given information anywhere that I can find on it. It seems to be in correlation with the temp files that I mentioned in the title. There are two that show up in the running process list, as "winE79.tmp.exe" and "winE74.tmp.exe." Now, I've run Spybot, Adaware SE, McAfee, Bazooka, and a couple of smaller temp file cleaners such as Tuneup Utilities, and can't seem to get rid of the bugger. The popup states:
"Your current security settings prohibit running ActiveX controls on the page. As a result, the page may not display correctly."
It comes with the titlebar of "Microsoft IE," which I haven't used in ages. I've run updates on all the definition files, all the security and necessary updates for WinXP, and the such, but nothing seems to help. The popup seems to reoccur every 2-3 minutes or so, with the tmp.exe file staying in the process listing after I close the error window. I didn't know what to include besides the hjt log, so if you need any more information, I'll be glad to try something.
Thanks for any advice or help ahead of time.
[Log]
Logfile of HijackThis v1.99.1
Scan saved at 12:03:43 AM, on 2/25/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\wdfmgr.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\TEMP\winE74.tmp.exe
C:\WINDOWS\TEMP\winE79.tmp.exe
C:\WINDOWS\TEMP\winE74.tmp.exe
C:\WINDOWS\TEMP\winE79.tmp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\TEMP\winE74.tmp.exe
C:\Tools & Utilities\HijackThis.exe
R3 - URLSearchHook: (no name) - {6C6D115B-A39B-DB43-C805-DF98BF60F7BA} - (no file)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKCU\..\Run: [Ultimate Pop-up Blocker] C:\Program Files\Ultimate Pop-up Blocker\Ultimate Pop-up Blocker.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O16 - DPF: {0F4DACC9-A396-1C68-D371-5E6E657CE3E5} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {296D49D1-1122-5A88-E657-5F871F3B6BD5} - http://69.50.173.166/1/gdnUS1503.exe
O16 - DPF: {2DE9EC3B-7586-68FC-0915-48041BB64819} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {397E52BE-8FEF-0311-A105-30DA575A7F77} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {3C0F87B5-F082-4991-C472-27DE51ED65EB} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {3C91B533-CEE2-15B9-A62C-524B4E438A10} - http://69.50.173.166/1/gdnUS1503.exe
O16 - DPF: {43DB2CC0-6AAD-3D8F-E02B-6BC155F9BDD8} - http://69.50.173.166/1/gdnUS1503.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5060CBE0-5F9F-3AA1-4F66-6C11144D19C7} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {6211E70B-CE7D-51FA-5373-4D662D886961} - http://69.50.173.166/1/gdnUS1503.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140465396567
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {75E1CD18-3ECD-6825-A0EF-721A79F475A7} - http://69.50.173.166/1/rdgUS2405.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3894429A-964F-4399-8815-D944BABE82AD}: NameServer = 85.255.115.26,85.255.112.110
O20 - Winlogon Notify: winino32 - C:\WINDOWS\SYSTEM32\winino32.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\System32\oodag.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
Multiple McAfee Virus scans come up with this "Dialer-269," with no given information anywhere that I can find on it. It seems to be in correlation with the temp files that I mentioned in the title. There are two that show up in the running process list, as "winE79.tmp.exe" and "winE74.tmp.exe." Now, I've run Spybot, Adaware SE, McAfee, Bazooka, and a couple of smaller temp file cleaners such as Tuneup Utilities, and can't seem to get rid of the bugger. The popup states:
"Your current security settings prohibit running ActiveX controls on the page. As a result, the page may not display correctly."
It comes with the titlebar of "Microsoft IE," which I haven't used in ages. I've run updates on all the definition files, all the security and necessary updates for WinXP, and the such, but nothing seems to help. The popup seems to reoccur every 2-3 minutes or so, with the tmp.exe file staying in the process listing after I close the error window. I didn't know what to include besides the hjt log, so if you need any more information, I'll be glad to try something.
Thanks for any advice or help ahead of time.
[Log]
Logfile of HijackThis v1.99.1
Scan saved at 12:03:43 AM, on 2/25/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\wdfmgr.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\TEMP\winE74.tmp.exe
C:\WINDOWS\TEMP\winE79.tmp.exe
C:\WINDOWS\TEMP\winE74.tmp.exe
C:\WINDOWS\TEMP\winE79.tmp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\TEMP\winE74.tmp.exe
C:\Tools & Utilities\HijackThis.exe
R3 - URLSearchHook: (no name) - {6C6D115B-A39B-DB43-C805-DF98BF60F7BA} - (no file)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKCU\..\Run: [Ultimate Pop-up Blocker] C:\Program Files\Ultimate Pop-up Blocker\Ultimate Pop-up Blocker.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O16 - DPF: {0F4DACC9-A396-1C68-D371-5E6E657CE3E5} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {296D49D1-1122-5A88-E657-5F871F3B6BD5} - http://69.50.173.166/1/gdnUS1503.exe
O16 - DPF: {2DE9EC3B-7586-68FC-0915-48041BB64819} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {397E52BE-8FEF-0311-A105-30DA575A7F77} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {3C0F87B5-F082-4991-C472-27DE51ED65EB} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {3C91B533-CEE2-15B9-A62C-524B4E438A10} - http://69.50.173.166/1/gdnUS1503.exe
O16 - DPF: {43DB2CC0-6AAD-3D8F-E02B-6BC155F9BDD8} - http://69.50.173.166/1/gdnUS1503.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5060CBE0-5F9F-3AA1-4F66-6C11144D19C7} - http://69.50.173.166/1/rdgUS2405.exe
O16 - DPF: {6211E70B-CE7D-51FA-5373-4D662D886961} - http://69.50.173.166/1/gdnUS1503.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140465396567
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {75E1CD18-3ECD-6825-A0EF-721A79F475A7} - http://69.50.173.166/1/rdgUS2405.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3894429A-964F-4399-8815-D944BABE82AD}: NameServer = 85.255.115.26,85.255.112.110
O20 - Winlogon Notify: winino32 - C:\WINDOWS\SYSTEM32\winino32.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\System32\oodag.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe