May 15, 200521 yr Ok my computer is going crazy. Im getting pop-ups all the time, even when im not on internet explorer. And my task manager is all messed up, SEE I think im going to get ad aware and spy bot right now..... When survival is in question, anything goes.
May 15, 200521 yr First..do as you said and download spybot and ad-aware.. As for the task-manager, double-click on the area outside the process list, it should be returned to normal.
May 15, 200521 yr Author Thanks its back to normal now. I ran spybot and ad aware, and restarted, but im still getting pop-ups like crazy. How do i get thoses away? When survival is in question, anything goes.
May 15, 200521 yr Post a HiJackThis Log (read the stickies to find out where to get this) and also make sure you are running adaware and spy bot with the newest definitions in safe mode, to get in safe mode restart your computer and repeatedly press F8 untill you get to the screen asking you how you would like to start. Choose Safe mode and then rescan ...
May 15, 200521 yr If spybot and ad-aware did nothing, it's possible you have messenger popups (not msn). Do the popups look like normal internet popups? Or do they look look like the kind of box you get when you have an error? A screenshot of one of the popups may be helpful..
May 15, 200521 yr Author Logfile of HijackThis v1.99.1 Scan saved at 4:16:45 PM, on 5/15/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss[Caution: ExecutableFile] C:\WINDOWS\system32\winlogon[Caution: ExecutableFile] C:\WINDOWS\system32\services[Caution: ExecutableFile] C:\WINDOWS\system32\lsass[Caution: ExecutableFile] C:\WINDOWS\system32\svchost[Caution: ExecutableFile] C:\WINDOWS\System32\svchost[Caution: ExecutableFile] C:\WINDOWS\system32\spoolsv[Caution: ExecutableFile] C:\WINDOWS\Explorer[Caution: ExecutableFile] C:\Program Files\AVPersonal\AVWUPSRV[Caution: ExecutableFile] C:\WINDOWS\System32\carpserv[Caution: ExecutableFile] C:\Program Files\Compaq\Easy Access Button Support\StartEAK[Caution: ExecutableFile] C:\Program Files\Analog Devices\SoundMAX\Smtray[Caution: ExecutableFile] C:\Program Files\Real\RealPlayer\RealPlay[Caution: ExecutableFile] C:\SMC\SMC[Caution: ExecutableFile] C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY[Caution: ExecutableFile] C:\Program Files\Zone Labs\ZoneAlarm\zlclient[Caution: ExecutableFile] C:\Program Files\Compaq\Easy Access Button Support\CPQEADM[Caution: ExecutableFile] C:\Program Files\Java\jre1.5.0_02\bin\jusched[Caution: ExecutableFile] C:\Compaq\EAKDRV\EAUSBKBD[Caution: ExecutableFile] C:\WINDOWS\System32\winupdt[Caution: ExecutableFile] C:\WINDOWS\system32\ZoneLabs\vsmon[Caution: ExecutableFile] C:\WINDOWS\System32\RUNDLL32[Caution: ExecutableFile] C:\PROGRA~1\Compaq\EASYAC~1\BttnServ[Caution: ExecutableFile] C:\DOCUME~1\JACKPA~1\LOCALS~1\Temp\ICD2.tmp\svcmm32[Caution: ExecutableFile] C:\WINDOWS\System32\wuauclt[Caution: ExecutableFile] C:\Documents and Settings\Jack Patterson\Desktop\runescape[Caution: ExecutableFile] C:\Program Files\Internet Explorer\iexplore[Caution: ExecutableFile] C:\Documents and Settings\Jack Patterson\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis[Caution: ExecutableFile] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_ ... ch/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_ ... .yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drf.com/ R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.tip.it/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [CARPService] carpserv[Caution: ExecutableFile] O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal[Caution: ExecutableFile]" O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK[Caution: ExecutableFile] O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean[Caution: ExecutableFile] O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray[Caution: ExecutableFile] O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay[Caution: ExecutableFile] SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [sMC] C:\SMC\SMC[Caution: ExecutableFile] O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient[Caution: ExecutableFile] O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched[Caution: ExecutableFile] O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT[Caution: ExecutableFile]" /min O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt[Caution: ExecutableFile] O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16 O4 - HKLM\..\Run: [uSB controller] "C:\DOCUME~1\JACKPA~1\LOCALS~1\Temp\ICD2.tmp\svcmm32[Caution: ExecutableFile]" /startup O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll" O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim[Caution: ExecutableFile] -cnetwait.odl O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll" O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl[Caution: ExecutableFile] O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim[Caution: ExecutableFile] O16 - DPF: {FDCC1518-6A63-11D9-AAC8-91EC5E497716} - http://www.ouchvideo.com/mmviewer_emg11.cab O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV[Caution: ExecutableFile] O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon[Caution: ExecutableFile] Theres the log file Heres a pic of ads When survival is in question, anything goes.
May 15, 200521 yr Maybe you got some spyware from your autotyper. Generally one doesn't want to post evidence that they cheat on tipit... On a side note, you should probably upgrade to sp2.
May 16, 200521 yr Maybe you got some spyware from your autotyper. Generally one doesn't want to post evidence that they cheat on tipit... On a side note, you should probably upgrade to sp2. why the hell did you delete my post im right and you know it just face it
May 16, 200521 yr Do you get those just randomly or while you are surfing the net? If its while you are on line you might want to download firefox. http://www.getfirefox.com
May 16, 200521 yr PLEASE DONT DELETE THIS this saves the world lol what he got is normal it happens when you double click on the spot like the pict below http://img17.echo.cx/img17/5001/noob25bj.png to get it back just double click on the spot like the pict below http://img141.echo.cx/img141/9397/dumbnoob3xn.png if you say that spyware did it then your 100% false
May 16, 200521 yr PLEASE DONT DELETE THIS this saves the world lol what he got is normal it happens when you double click on the spot like the pict below http://img17.echo.cx/img17/5001/noob25bj.png to get it back just double click on the spot like the pict below http://img141.echo.cx/img141/9397/dumbnoob3xn.png if you say that spyware did it then your 100% false Wow kid... we solved that mystery LONG ago, infact the 1st post: As for the task-manager, double-click on the area outside the process list, it should be returned to normal. We are now talking about his SPYWARE problem, hence why we are talking about SPYWARE And why are you yelling at battletrax... if you havn't noticed he isn't an admin or mod, so I am fairly sure he isn't deleteing your oh-so-smart posts... ...
May 16, 200521 yr Author I just get the pop-ups at random, i could just turn my comp on then leave and come back and it would be flooded with them. I hate the internet.... When survival is in question, anything goes.
May 16, 200521 yr get a popup blocker? That won't get rid his problem, just more or less cover it up... Get service pack 2 by going to the windows update site, that is NOT an option, you should ALWAYS keep your version of windows up to date. They release the patchs to fix security flaws... obviously it is something you are going to want ...
May 16, 200521 yr Author Thanks zonda, your uber smart. I wish i knew stuff about computers.... When survival is in question, anything goes.
May 16, 200521 yr Firstly, can_t_ecape is 100% a pleb Secondly, Its no wonder you have so much popups and crap. You dont even have ServicePack1 let alone Service Pack 2. Your PC is open to a massive amount of malware and viruses. Your PC may even be used in a botnet to spread viruses and spam to thousands of people. You are literally YEARS out of date. http://www.windowsupdate.com is a MUST. You need to download and patch your PC immediatly before going on any other websites/msn/runescape etc. Thirdly, Move HJT to a perminant location. C:\Documents and Settings\Jack Patterson\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis[Caution: ExecutableFile] will not create backups. Copy the exe to C:\HijackThiszHijackThis[Caution: ExecutableFile] or something like that. Ok now to try and fix some of this mess *sigh* Press Ctrl+alt+del and end the following processes C:\WINDOWS\System32\winupdt[Caution: ExecutableFile] - Downloader virus. Runs in the background as a back door to install yet more malware. C:\DOCUME~1\JACKPA~1\LOCALS~1\Temp\ICD2.tmp\svcmm32[Caution: ExecutableFile] - Any exe running from the temporary folder is most likely to me malicious. In this case its part of the n-lite spyware. then "fix" the following O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg.dll O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt[Caution: ExecutableFile] O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16 O4 - HKLM\..\Run: [uSB controller] "C:\DOCUME~1\JACKPA~1\LOCALS~1\Temp\ICD2.tmp\svcmm32[Caution: ExecutableFile]" /startup O16 - DPF: {FDCC1518-6A63-11D9-AAC8-91EC5E497716} - http://www.ouchvideo.com/mmviewer_emg11.cab Remove all that crap. Check you are clean with spybot and Adaware then install Service pack 2. It will probably take you hours even on a fast connection because you have neglected to secure your pc. When you have got SP2 post a fresh log. I have a feelings theres a few more nasties on your pc but are hidden away using the old XP exploits. Mercifull <3 Suzi "We don't want players to be able to buy their way to success in RuneScape. If we let players start doing this, it devalues RuneScape for others. We feel your status in real-life shouldn't affect your ability to be successful in RuneScape" Jagex 01/04/01 - 02/03/12
May 17, 200521 yr Author Logfile of HijackThis v1.99.1 Scan saved at 12:31:18 AM, on 5/17/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss[Caution: ExecutableFile] C:\WINDOWS\system32\winlogon[Caution: ExecutableFile] C:\WINDOWS\system32\services[Caution: ExecutableFile] C:\WINDOWS\system32\lsass[Caution: ExecutableFile] C:\WINDOWS\system32\svchost[Caution: ExecutableFile] C:\WINDOWS\System32\svchost[Caution: ExecutableFile] C:\WINDOWS\system32\spoolsv[Caution: ExecutableFile] C:\WINDOWS\Explorer[Caution: ExecutableFile] C:\WINDOWS\System32\carpserv[Caution: ExecutableFile] C:\Program Files\Compaq\Easy Access Button Support\StartEAK[Caution: ExecutableFile] C:\WINDOWS\system32\ZoneLabs\vsmon[Caution: ExecutableFile] C:\Program Files\Analog Devices\SoundMAX\Smtray[Caution: ExecutableFile] C:\Program Files\Real\RealPlayer\RealPlay[Caution: ExecutableFile] C:\SMC\SMC[Caution: ExecutableFile] C:\Program Files\Zone Labs\ZoneAlarm\zlclient[Caution: ExecutableFile] C:\Program Files\Java\jre1.5.0_02\bin\jusched[Caution: ExecutableFile] C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY[Caution: ExecutableFile] C:\Program Files\Compaq\Easy Access Button Support\CPQEADM[Caution: ExecutableFile] C:\Program Files\AIM\aim[Caution: ExecutableFile] C:\Compaq\EAKDRV\EAUSBKBD[Caution: ExecutableFile] C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl[Caution: ExecutableFile] C:\PROGRA~1\Compaq\SETREF~1\SetRefresh[Caution: ExecutableFile] C:\PROGRA~1\Compaq\EASYAC~1\BttnServ[Caution: ExecutableFile] C:\Documents and Settings\Jack Patterson\My Documents\hijackthis\HijackThis[Caution: ExecutableFile] C:\WINDOWS\System32\wuauclt[Caution: ExecutableFile] C:\WINDOWS\system32\rundll32[Caution: ExecutableFile] C:\WINDOWS\System32\drwtsn32[Caution: ExecutableFile] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_ ... ch/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_ ... .yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drf.com/ R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.tip.it/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [CARPService] carpserv[Caution: ExecutableFile] O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal[Caution: ExecutableFile]" O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK[Caution: ExecutableFile] O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean[Caution: ExecutableFile] O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray[Caution: ExecutableFile] O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay[Caution: ExecutableFile] SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [sMC] C:\SMC\SMC[Caution: ExecutableFile] O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient[Caution: ExecutableFile] O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched[Caution: ExecutableFile] O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll" O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim[Caution: ExecutableFile] -cnetwait.odl O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll" O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl[Caution: ExecutableFile] O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim[Caution: ExecutableFile] O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 6303958811 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon[Caution: ExecutableFile] I downloaded all thoses windows updates, ran spy-bot and ad-aware and re-booted. When survival is in question, anything goes.
May 18, 200521 yr Look punk, a volunteer will get to you when s/he is ready, not when you're ready. If you wan't tech support immediately, well go pay for it :roll: Ahem. Where the bloody hell are you?
May 18, 200521 yr Look punk, a volunteer will get to you when s/he is ready, not when you're ready. If you wan't tech support immediately, well go pay for it :roll: Ahem. Ouch, you just made one of the very few people that takes time to go over HJT logs angry... Guess now you get to wait for merc or grin :lol: ...
May 18, 200521 yr Author actually i just wanted to bump it, cause i though Merc forgot about it cause he told me to get a new log. Well sorry if i came of as rude but my comp is freaking out. When survival is in question, anything goes.
May 18, 200521 yr Are you sure you got all of the updates? From the looks of your log it seems you don't have SP1/2 yet, nor is your Internet Explorer up to date..
May 18, 200521 yr Author How can i find out if i got them? BTW my pop-ups have been gone for awhile, maybe its fixed? When survival is in question, anything goes.
May 18, 200521 yr I havn't replied because... a) I have been very busy irl, i dont sit at my computer desk all day helping people out and B) You havn't done as i asked and updated and security patched windows http://www.windowsupdate.com Mercifull <3 Suzi "We don't want players to be able to buy their way to success in RuneScape. If we let players start doing this, it devalues RuneScape for others. We feel your status in real-life shouldn't affect your ability to be successful in RuneScape" Jagex 01/04/01 - 02/03/12
May 18, 200521 yr Author I went there, and it said it was downloading, and i did that before i ran the log. Should i try again? When survival is in question, anything goes.
Create an account or sign in to comment