pop up problem--help me with my Hijack This log file! **UPDATE**

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

nick1985

Lifer
Dec 29, 2002
27,153
6
81
i just deleted everything on those lists, scanned for viruses, and ran my 6 anti spyware tools, then restarted


then i get the same old pop up.....


im going to shoot someone pretty soon. i cant even fvcking use my comptuer!!
 

dighn

Lifer
Aug 12, 2001
22,820
4
81
Originally posted by: nick1985
i just deleted everything on those lists, scanned for viruses, and ran my 6 anti spyware tools, then restarted


then i get the same old pop up.....


im going to shoot someone pretty soon. i cant even fvcking use my comptuer!!

after it's all deleted, run hijack this again and post the new log
 

nick1985

Lifer
Dec 29, 2002
27,153
6
81
new log

Logfile of HijackThis v1.97.7
Scan saved at 6:14:15 PM, on 12/25/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\cmd32.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\Common Files\slmss\slmss.exe
C:\WINDOWS\mwsvm.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\United Devices\UD.EXE
C:\WINDOWS\System32\RUNDLL32.exe
C:\Program Files\United Devices\ud_1706422.exe
C:\Program Files\United Devices\ud_1706422_0.dir\ud_ligfit_Release.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\nick\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.anandtech.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.anandtech.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seekseek.com/quicksearch.asp?session=500CA143-0EC6-47E0-9A7B-E0BE09A3C5E1&version_id=18
R3 - URLSearchHook: (no name) - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - (no file)
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\System32\cmd32.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\cmd32.exe
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner\RivaTuner.exe" /S
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\RunServices: [CMD] cmd32.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Startup: UD Agent.lnk = C:\Program Files\United Devices\UD.EXE
O9 - Extra button: AIM (HKLM)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

 

dpm

Golden Member
Apr 24, 2002
1,513
0
0
Originally posted by: Sid59
i dont see how a firewall is gonna stop you from downloading content that will install. should always clean adaware, spybot. bhodemon .. last hi jack this. hihack is the most confusing and easy to botch other programs if you dont know what you are doing.

A firewall doesn't always stop you downloading stuff, but it will tell you what programs are trying to access the internet, and ask if you give them permission. This is a great help stopping this kind of stuff.

Anyway, there's no excuse nowadays for not running a firewall if you are connected to the internet.
 

nick1985

Lifer
Dec 29, 2002
27,153
6
81
thanks again for your help everyone.

i feel like gandalf fighting the balrog here....ive been battling since 2 central time.
 

dighn

Lifer
Aug 12, 2001
22,820
4
81
well at least most of the spyware are gone

i'd also get rid of O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

the popups maybe due to kazaa
 

nick1985

Lifer
Dec 29, 2002
27,153
6
81
UPDATE***

ive been attacked twice within the last 10 minutes. i hear my pop up stopper going crazy and there is clicking everywhere, although im not clicking my mouse:confused: the only thing is, the pop ups dont come up anymore! they are just trying. i will prolly eat my words, but i think its getting better.

 

dpm

Golden Member
Apr 24, 2002
1,513
0
0
ok, so in addition to the two cr4zymofo noticed, you still have mwsvm.exe and slmss.exe running.

Basically, just checking them in hijack this isn't going to be enough. I'm really surprised that adaware hasn't fixed them, though.

nick - what are the six anti spyware tools you are using? Y'know, there are a couple of spyware apps out there maskerading as anti-spyware aps... have to be careful.

Also, you really ought to be running a 24/7 software anti-virus program, and not relying on pc-pitstop. if you aren't running an anti-virus, or firewall prog, then I recommend the EZarmor suite, from CA, available for free here , as a good av/firewall package. Its just foolhardy to be on the internet without one.

Also, is that regular kazaa you are running, as opposed to kazaa lite, or klite+? That's well known as a ticket to adware hell.
 

CTho9305

Elite Member
Jul 26, 2000
9,214
1
81
Originally posted by: TheBoyBlunder
http://pics.bbzzdd.com - ok, I'm not sure what you have going on there...

And here I was, thinking bbzzdd was work safe. Guess not.
edit: removed the link. It was to a pic posted by "Infected" if whoever runs bbzzdd wants to remove it for TOS violation or whatever.
 

CTho9305

Elite Member
Jul 26, 2000
9,214
1
81
Originally posted by: TheBoyBlunder
Originally posted by: dighn
Originally posted by: CTho9305
Originally posted by: TheBoyBlunder
http://pics.bbzzdd.com - ok, I'm not sure what you have going on there...

And here I was, thinking bbzzdd was work safe. Guess not

better remove that link before a mod sees it

remove the link to pics.bbzzdd.com? what the hell for?
"Guess not." was originally a link. However, the pic linked to is still in the "last 25" gallery... making pics.bbzzdd.com unsafe. Maybe I should remove that link too ;).
edit: Thread here :p
 

dighn

Lifer
Aug 12, 2001
22,820
4
81
Originally posted by: TheBoyBlunder
Originally posted by: dighn
Originally posted by: CTho9305
Originally posted by: TheBoyBlunder
http://pics.bbzzdd.com - ok, I'm not sure what you have going on there...

And here I was, thinking bbzzdd was work safe. Guess not

better remove that link before a mod sees it

remove the link to pics.bbzzdd.com? what the hell for?

he removed the link i was talking about. nudity. i don't care but i can't say the same about the mods.
 

nick1985

Lifer
Dec 29, 2002
27,153
6
81
anything else i need to remove?


Logfile of HijackThis v1.97.7
Scan saved at 7:58:45 PM, on 12/25/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\cmd32.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\Common Files\slmss\slmss.exe
C:\WINDOWS\mwsvm.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\United Devices\UD.EXE
C:\WINDOWS\System32\RUNDLL32.exe
C:\Program Files\United Devices\ud_1706422.exe
C:\Program Files\United Devices\ud_1706422_0.dir\ud_ligfit_Release.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\svchost.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCD.exe
C:\Documents and Settings\nick\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.anandtech.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.anandtech.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: (no name) - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - (no file)
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\System32\cmd32.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\cmd32.exe
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner\RivaTuner.exe" /S
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\RunServices: [CMD] cmd32.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Startup: UD Agent.lnk = C:\Program Files\United Devices\UD.EXE
O9 - Extra button: AIM (HKLM)
O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

 

TheBoyBlunder

Diamond Member
Apr 25, 2003
5,742
1
0
Originally posted by: dighn
Originally posted by: TheBoyBlunder
Originally posted by: dighn
Originally posted by: CTho9305
Originally posted by: TheBoyBlunder
http://pics.bbzzdd.com - ok, I'm not sure what you have going on there...

And here I was, thinking bbzzdd was work safe. Guess not

better remove that link before a mod sees it

remove the link to pics.bbzzdd.com? what the hell for?

he removed the link i was talking about. nudity. i don't care but i can't say the same about the mods.

OH...ok.
 

nick1985

Lifer
Dec 29, 2002
27,153
6
81
i think i have the son of a b!tch in remission. no pop ups for the last 10 min....after 8 hours of battle.
 

Sid59

Lifer
Sep 2, 2002
11,879
3
81
Originally posted by: dpm
Originally posted by: Sid59
i dont see how a firewall is gonna stop you from downloading content that will install. should always clean adaware, spybot. bhodemon .. last hi jack this. hihack is the most confusing and easy to botch other programs if you dont know what you are doing.

A firewall doesn't always stop you downloading stuff, but it will tell you what programs are trying to access the internet, and ask if you give them permission. This is a great help stopping this kind of stuff.

Anyway, there's no excuse nowadays for not running a firewall if you are connected to the internet.

i don't run a software firewall on either computers i own. just the protection available from my router.

my 2nd rig is used only by my younger brother and both my parents. the only hting ever scanned on that computer for spyware are porn cookies.

my computer is clean and every computer i've ever own are clean.

every month i do a spyware sweep and nothing comes up.
i even take the time to install an AV to check out and nothing comes up.