1
   

Please help me rid the nasty pop ups

 
 
4ank
 
Reply Sun 11 Apr, 2004 07:28 pm
Hi all. Newb here.

I came home to find that my family was massacred with pop-ups and spyware. I downloaded and ran all of the following:

cwshredder
ad-aware
spybot S/D

I also installed Zone alarm (free version) as a firewall.

It helped a lot but there are still some pop ups. I was wondering if you could tell me what is wrong with this log:
Quote:

Logfile of HijackThis v1.97.7
Scan saved at 9:26:39 PM, on 4/11/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDLL32.EXE
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\DOCUME~1\ManHop\LOCALS~1\Temp\bs51.tmpbsx32\cg.exe
C:\Program Files\ClipGenie\WebInstall.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ManHop\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\Program Files\Lycos\IEagent\CSIE.DLL
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [WebInstall2] C:\Program Files\ClipGenie\WebInstall.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Support (HKCU)
O9 - Extra button: ComcastHSI (HKCU)
O9 - Extra button: Help (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38045.5911458333
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab



Thanks a lot
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 2,771 • Replies: 8
No top replies

 
Synonymph
 
  1  
Reply Mon 12 Apr, 2004 11:04 am
You might want to do a system restore and then reinstall those new programs.
0 Replies
 
Craven de Kere
 
  1  
Reply Mon 12 Apr, 2004 11:10 am
4ank,

Using system restore is a VERY bad idea. It'll just bring back the pests.
0 Replies
 
Synonymph
 
  1  
Reply Mon 12 Apr, 2004 11:20 am
It works if you can pinpoint when the trouble started. Then again, if 4ank's whole family uses the same computer, it could be impossible.
0 Replies
 
Synonymph
 
  1  
Reply Mon 26 Apr, 2004 10:24 am
Last night my computer was attacked by something called belgiandip. Sound like an imported biscuit? Apparently it's (a trojan?)from belgiandip.com, which managed to bypass Spybot. Panicware blocked all popups, but the browser slowed to a crawl. I did a system restore to the previous night. Problem solved: no more belgiandip, system back to normal. As a precaution I also added belgiandip.com to the computer's list of restricted sites.
0 Replies
 
BoGoWo
 
  1  
Reply Mon 26 Apr, 2004 10:33 am
two suggestions:


to Cinnny;
be careful to add a letter to the front or rear of dangerous Urls, such as xwww. belgiandip.come to disable them in a post so some poor soul who clicks on it without reading, or thinking, won't get caught.

and second, to 4ank;
I use Opera, configured to dissallow popup windows, unless requested, and they do not trouble me. But don't confuse this with spyware, wich still needs numerous precautions.
0 Replies
 
Synonymph
 
  1  
Reply Mon 26 Apr, 2004 10:40 am
Is the URL clickable without the http? On my screen it isn't.
0 Replies
 
BoGoWo
 
  1  
Reply Mon 26 Apr, 2004 10:43 am
Cinnesthesia wrote:
Is the URL clickable without the http? On my screen it isn't.


works on mine, though i resisted trying it (it if highlighted, and 'clickable').

maybe it's my Opera browser that accepts it without 'http'.

oops, i just looked back, and it no longer is; must be the little hamsters, busily at work protecting us;
my compliments to the little devils!
0 Replies
 
Craven de Kere
 
  1  
Reply Wed 28 Apr, 2004 08:32 pm
4ank,

Sorry for not getting back to this one, doing these logs takes from 10 to 30 minutes and I haven't been able to keep up.

These ones looks suspicious:

Code:C:\DOCUME~1\ManHop\LOCALS~1\Temp\bs51.tmpbsx32\cg.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN


These are baddies (to the best of my knowledge):

Code:C:\Program Files\ClipGenie\WebInstall.exe
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\Program Files\Lycos\IEagent\CSIE.DLL
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKLM\..\Run: [WebInstall2] C:\Program Files\ClipGenie\WebInstall.exe /R
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Please help me rid the nasty pop ups
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 05/05/2024 at 07:15:52