Help Please!

Discussion in 'Gaming' started by ViperAFK, Oct 22, 2005.

  1. ViperAFK

    ViperAFK Well-Known Member

    Age:
    34
    Posts:
    1,561
    Likes Received:
    0
    Joined:
    Sep 10, 2005
    Location:
    Vermont
    Whenever I use the intenet randomly and very often a new tab comes up in my firefox and takes me to some retarded site, like free things web shpping ect.. and then a pop up ad comes up and they NEVER come up normally in my firefox, and that new tab comes up like every 30 seconds, i can't take it anymore! I've scanned for spyware using ad-aware, spybot s&d, and microsoft antispyware beta and removed alot but my problem is not fixed can anyone please help me with this?
     
  2. DiabloDj1

    DiabloDj1 Well-Known Member

    Age:
    33
    Posts:
    5,610
    Likes Received:
    0
    Joined:
    Jan 27, 2005
    Location:
    USA/RI
    Hmm..
    Well as a safety precaution against spyware you should get SpywareBlaster:
    http://www.javacoolsoftware.com/spywareblaster.html

    For your problem, did you check for any weird programs running in your Task Manager?

    Did you empty temp int. files folder?

    Can you get the name of the site next time it opens?

    Also, you can try getting a HijackThis log and posting it here...
    http://www.tomcoyote.org/hjt/
    theres a button saying HiJackThis! right on the left, click it to download.

    I cant think at the moment but I'll try to keep thinkin what to do.
     
  3. ViperAFK

    ViperAFK Well-Known Member

    Age:
    34
    Posts:
    1,561
    Likes Received:
    0
    Joined:
    Sep 10, 2005
    Location:
    Vermont
  4. ViperAFK

    ViperAFK Well-Known Member

    Age:
    34
    Posts:
    1,561
    Likes Received:
    0
    Joined:
    Sep 10, 2005
    Location:
    Vermont
    heres the complete list of all the pop up urls, and I'm dling hijack this right now.
     
  5. ViperAFK

    ViperAFK Well-Known Member

    Age:
    34
    Posts:
    1,561
    Likes Received:
    0
    Joined:
    Sep 10, 2005
    Location:
    Vermont
    Hijackthis scan results
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\Google Talk\googletalk.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\CursorXP\CursorXP.exe
    C:\WINDOWS\SYSTEM32\rundll32.exe
    C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Brandon\Desktop\hijackthis(2)\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
    O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
    O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
    O4 - HKCU\..\Run: [DesktopX] C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
    O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...96/mcinsctl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1119918799812
    O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} - http://install.wildtangent.com/bgn/partner...lim/install.cab
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocx
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1125609204031
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {94837F90-A2CA-4A8A-9DA0-B5438EC563EA} (WildTangent Active Launcher) - http://install.wildtangent.com/cda/islandr...uncherSetup.cab
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1441/ftp...23/cpbrkpie.cab
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partner...ler/install.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg...,16/mcgdmgr.cab
    O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) - http://gameadvisor.futuremark.com/global/msc37.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
    O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\l88mlil118q.dll
    O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Intel NCS NetService (NetSvc) - IntelĀ® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
     
  6. DiabloDj1

    DiabloDj1 Well-Known Member

    Age:
    33
    Posts:
    5,610
    Likes Received:
    0
    Joined:
    Jan 27, 2005
    Location:
    USA/RI
    I would say remove O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -

    unless you know of it as a program you use I'm pretty sure its just spyware.
     
  7. ViperAFK

    ViperAFK Well-Known Member

    Age:
    34
    Posts:
    1,561
    Likes Received:
    0
    Joined:
    Sep 10, 2005
    Location:
    Vermont
    I've tried everything, I've mangaged to stop the pop up ads, but it still randomly opens new tabs in my firefox, search-h.com alot and alot that have yyy/53 in the urls
     
  8. .eclipse

    .eclipse Senior Member

    Posts:
    317
    Likes Received:
    0
    Joined:
    Sep 10, 2005
    Im not sure what the problem is, and i dont know very much about computers. But, maybe you check your Mozilla folder in your Program Files folder. There might be a virus or something in there.
     
  9. Otaku23

    Otaku23 Well-Known Member

    Posts:
    1,115
    Likes Received:
    0
    Joined:
    Jul 3, 2005
    Location:
    canada
    Virus Scan...

    Try that...
     
  10. DiabloDj1

    DiabloDj1 Well-Known Member

    Age:
    33
    Posts:
    5,610
    Likes Received:
    0
    Joined:
    Jan 27, 2005
    Location:
    USA/RI
    Run Avast! and/or AVG Anti virus

    I'd reccomend SpywareBlaster if you don't allready have it.

    Run Ad-Aaware SE Personal and Spybot Search & Destroy.

    Go to Run<msconfig<start up. Remove anything that shouldn't be there.

    Download Ccleaner.

    Clear:
    C:\Documents and Settings\User\Local Settings\Temp
    C:\Documents and Settings\User\Local Settings\Temporary Internet Files
    Remember to change User or just go to whatever folder when you go through the folders for it.

    Get a firewall if you don't allready have one.
    I would reccomend ZoneAlarm.

    Make sure to run updates on everything, including Windows Update.

    God I should save this or something..I hate having to type it over and over.
     
  11. toymachine2009

    toymachine2009 Well-Known Member

    Posts:
    176
    Likes Received:
    0
    Joined:
    Oct 23, 2005
    get the microsoft antispyware who knows there computers better than themselves
     
  12. .DeFuZioN

    .DeFuZioN Well-Known Member

    Age:
    34
    Posts:
    2,260
    Likes Received:
    0
    Joined:
    Oct 7, 2005
    Location:
    Australia
    PopCap loader is the loader for games at www.popcap.com
     
  13. ViperAFK

    ViperAFK Well-Known Member

    Age:
    34
    Posts:
    1,561
    Likes Received:
    0
    Joined:
    Sep 10, 2005
    Location:
    Vermont
    Ok i scanned alot more and scanned for viruses and reinstalled firefox and it seems to have stop, thx for the help everyone.
     

Share This Page