Annoyances.org
Home » Windows Me Discussion Forum » Message 1080610500 Search | Help | Home
  
Tip: Run a free scan for common Windows errors ad

re: Spyware? Random pop-ups when starting IE.
Monday, March 29, 2004 at 5:35 pm
Windows Me Annoyances Discussion Forum
Posted by Jen (6 messages posted)


Hmmm. You know what... After everything seemed a-okay, I'm getting more problems. 
A few pop-ups remain, such as one from z1.adserver.com. and something from adtomi 
(which might be related to the yahoo stock ticker that I'll mention below..) I ran 
spybot and adaware, I now have SpywareGuard installed, as you suggested, but these 
don't seem to go away... Should I do the whole process over? Also,  is Pest Patrol 
a valid spyware remover? It detected z1.adserver, the Yahoo thing, WildTanget, igentnet.clearsearch, 
and a bunch of other stuff that I had before such as the Lycos Searchbar that automatically 
installed itself.... PestPatrol says that adtomi and igetnet are "in registry" - 
?

------Yahoo stock ticker/Adtomi thing.------
At the bottom right on my taskbar thing where the shortcuts are (?), there's this 
other thing that appears to be a stock ticker for Yahoo, but I never installed such 
a thing and it's been there for about 3 days. It's bugging me... This site, http://www.kephyr.com/spywarescanner/library/adtomi/index.phtml, 
has some info on manually deleting "adtomi" and mentions deleting "YahooStock". Along 
with that, it mentions an anti-spyware thing called Bazooka, but again, I want to 
be sure everything is valid. Should I try the program? Follow the instructions?

(sorry for the many questions)

Another thing, in my Add/Remove Programs List, I noticed something called "Search 
Assistant - My Search". And I can't get rid of it... It says "error loading c:\program~1\myway\srchasst\1/bin\mysrchas.dll" 
Blah!

AND..... About the error messages with Morze.lnk (which is another issue I have) 
and tons of other "missing shortcuts" messages that appear wjhen starting my computer, 
I found these directions below on another site while searching on Google, should 
I follow them?  (AGAIN, to be sure. I don't want to simply do whatever I find with 
Google, I might screw up my computer even more):
**********
Name: ToX666
Date: March 29, 2004 at 14:30:55 Pacific
Subject: Help with error messages
 
Reply: 
Ok guys here it is....
1st: Spybot Full Updates/Full Scan and Fix!

2nd: Remove all shortcuts to the files in c:\windows\start menu\programs\start up

3rd: Remove all shortcuts to the files in c:\windows\all users\startup menu\programs\start 
up

4th: Enter Msconfig>startup and remove all links to the files there.

5th: Reboot

6th: Run a full updated virus scan (Norton AV 2004) on your drives just to be safe.

7th: Thx ToX666 for saving the day yet again ;)

If anyone had to do anything else besides what i posted here please reply. 

http://www.computing.net/windowsme/wwwboard/forum/42076.html
**************

*SIGH* Oh my gosh.... Maybe I should toss this computer out the window and get a 
new one. Hah... Hmm. Anywho, here's my new log (I really appreciate the help):


Logfile of HijackThis v1.97.7
Scan saved at 5:43:48 PM, on 3/29/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\ALOGSERV.EXE
C:\PROGRAM FILES\SUPPORT.COM\CLIENT\BIN\TGCMD.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\PESTPATROL\PPCONTROL.EXE
C:\PROGRAM FILES\PESTPATROL\PPMEMCHECK.EXE
C:\PROGRAM FILES\PESTPATROL\COOKIEPATROL.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\5CUZLK37.EXE
C:\PROGRAM FILES\SONY\VAIO ACTION SETUP\VASERV.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MY DOCUMENTS\HIJACKTHIS1977\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded 
program files\conflict.1\googletoolbar_en_1.1.66-deleon.dll
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\PROGRAM 
FILES\MYWAY\SRCHASTT\1.BIN\MYSRCHAS.DLL (file missing)
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRAM FILES\LYCOS\IEAGENT\CSIE.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} 
- C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O2 - BHO: (no name) - {B549456D-F5D0-4641-BCED-8648A0C13D83} - C:\WINDOWS\BrowserHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} 
- C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [OmgStartup] C:\Program Files\Common Files\Sony Shared\OpenMG\OmgStartup.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [Prodigy DSL] C:\PROGRA~1\PRODINET\PRODIG~1\APP\EnterNetDUN.Exe
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\Client\bin\tgcmd.exe" /server 
/nosystray
O4 - HKLM\..\Run: [ZTgServerSwitch] C:\Program Files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" 
-osboot
O4 - HKLM\..\Run: [bpcpost.exe] C:\WINDOWS\SYSTEM\bpcpost.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [5CUZLK37.EXE] C:\WINDOWS\5CUZLK37.EXE /dk
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program Files\McAfee\McAfee 
VirusScan\Avsynmgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [VidSvr] \vidsvr.exe /Automation
O4 - HKLM\..\RunServices: [Announcements] \annclist.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [5CUZLK37.EXE] C:\WINDOWS\5CUZLK37.EXE /dk
O4 - Startup: VAIO Action Setup (Server).lnk = C:\Program Files\Sony\VAIO Action 
Setup\VAServ.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft 
Shared\Works Shared\wkcalrem.exe
O4 - Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Startup: MORZE5.lnk = C:\WINDOWS\morze5.exe
O4 - Startup: 1DC0O6UJ.lnk = C:\WINDOWS\1dc0o6uj.exe
O4 - Startup: 6A5LK4XU.lnk = C:\WINDOWS\6a5lk4xu.exe
O4 - Startup: 1T0JQ9OG.lnk = C:\WINDOWS\1t0jq9og.exe
O4 - Startup: MORZE1.lnk = C:\WINDOWS\morze1.exe
O4 - Startup: 7IX8MKNM.lnk = C:\WINDOWS\7ix8mknm.exe
O4 - Startup: F8P15LV5.lnk = C:\WINDOWS\f8p15lv5.exe
O4 - Startup: QHT0RLIG.lnk = C:\WINDOWS\qht0rlig.exe
O4 - Startup: 3R8GO8L2.lnk = C:\WINDOWS\3r8go8l2.exe
O4 - Startup: NTPJTOVW.lnk = C:\WINDOWS\ntpjtovw.exe
O4 - Startup: 0DI7AMGK.lnk = C:\WINDOWS\0di7amgk.exe
O4 - Startup: 4AAZ18HX.lnk = C:\WINDOWS\4aaz18hx.exe
O4 - Startup: D6AV3CLX.lnk = C:\WINDOWS\d6av3clx.exe
O4 - Startup: VQ1OZN9M.lnk = C:\WINDOWS\vq1ozn9m.exe
O4 - Startup: V2Y35KR3.lnk = C:\WINDOWS\v2y35kr3.exe
O4 - Startup: F38J4ZZQ.lnk = C:\WINDOWS\f38j4zzq.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: A63Y8WZW.lnk = C:\WINDOWS\a63y8wzw.exe
O4 - Startup: Z74W0FN0.lnk = C:\WINDOWS\z74w0fn0.exe
O4 - Startup: 4ZQBLL6H.lnk = C:\WINDOWS\4zqbll6h.exe
O4 - Startup: B2LRHL1R.lnk = C:\WINDOWS\b2lrhl1r.exe
O4 - Startup: 5CUZLK37.lnk = C:\WINDOWS\5cuzlk37.exe
O4 - Global Startup: MORZE5.lnk = C:\WINDOWS\morze5.exe
O4 - Global Startup: 1DC0O6UJ.lnk = C:\WINDOWS\1dc0o6uj.exe
O4 - Global Startup: 6A5LK4XU.lnk = C:\WINDOWS\6a5lk4xu.exe
O4 - Global Startup: 1T0JQ9OG.lnk = C:\WINDOWS\1t0jq9og.exe
O4 - Global Startup: MORZE1.lnk = C:\WINDOWS\morze1.exe
O4 - Global Startup: 7IX8MKNM.lnk = C:\WINDOWS\7ix8mknm.exe
O4 - Global Startup: F8P15LV5.lnk = C:\WINDOWS\f8p15lv5.exe
O4 - Global Startup: QHT0RLIG.lnk = C:\WINDOWS\qht0rlig.exe
O4 - Global Startup: 3R8GO8L2.lnk = C:\WINDOWS\3r8go8l2.exe
O4 - Global Startup: 0DI7AMGK.lnk = C:\WINDOWS\0di7amgk.exe
O4 - Global Startup: NTPJTOVW.lnk = C:\WINDOWS\ntpjtovw.exe
O4 - Global Startup: 4AAZ18HX.lnk = C:\WINDOWS\4aaz18hx.exe
O4 - Global Startup: D6AV3CLX.lnk = C:\WINDOWS\d6av3clx.exe
O4 - Global Startup: VQ1OZN9M.lnk = C:\WINDOWS\vq1ozn9m.exe
O4 - Global Startup: F38J4ZZQ.lnk = C:\WINDOWS\f38j4zzq.exe
O4 - Global Startup: V2Y35KR3.lnk = C:\WINDOWS\v2y35kr3.exe
O4 - Global Startup: A63Y8WZW.lnk = C:\WINDOWS\a63y8wzw.exe
O4 - Global Startup: Z74W0FN0.lnk = C:\WINDOWS\z74w0fn0.exe
O4 - Global Startup: 4ZQBLL6H.lnk = C:\WINDOWS\4zqbll6h.exe
O4 - Global Startup: B2LRHL1R.lnk = C:\WINDOWS\b2lrhl1r.exe
O4 - Global Startup: 5CUZLK37.lnk = C:\WINDOWS\5cuzlk37.exe
O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\DOWNLOADED PROGRAM 
FILES\CONFLICT.1\GOOGLETOOLBAR_EN_1.1.66-DELEON.DLL/cmtrans.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: AIM (HKLM)
O12 - Plugin for .MTD: C:\Program Files\Netscape\Communicator\Program\Plugins\npmusicn.dll
O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\NPSWF32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DBB2DE32-61F1-4F7F-BEB8-A37F5BC24EE2} (MozillaPluginHostCtrl Class) - 
http://www.musicnotes.com/download/adaptor.cab
O16 - DPF: {E87A6788-1D0F-4444-8898-1D25829B6755} (MSN Chat Control 4.0) - http://fdl.msn.com/public/chat/msnchat4.cab
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/v1000/www.contentwatch.com/audit/includes/ContentAuditControl.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/Z4/heartbeat.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnview95.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/154ae491a01ac6c06f01/netzip/RdxIE601.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37987.7979050926











On Sunday, March 28, 2004 at 10:18 pm, Carol wrote:
>


>
>Jen, you're welcome.It might be a good idea to post a new Hijack This log, since you had so many problems
>showing. I should have asked you to before.
>

>
>

Carol




Written in response to:
re: Spyware? Random pop-ups when starting IE. (Ms. Eagle: Sunday, March 28, 2004 at 10:18 pm)

Responses to this message:
*re: Spyware? Random pop-ups when starting IE. (David: Monday, March 29, 2004 at 7:45 pm)
*! (Ms. Eagle: Monday, March 29, 2004 at 10:52 pm)

All messages in this thread [show all]
-Spyware? Random pop-ups when starting IE. (Jen: Sat, Mar 27, 2004, 8:30 pm)
*re: Spyware? Random pop-ups when starting IE. (Ms. Eagle: Sat, Mar 27, 2004, 11:18 pm)
-re: Spyware? Random pop-ups when starting IE. (Ms. Eagle: Sat, Mar 27, 2004, 11:48 pm)
-re: Spyware? Random pop-ups when starting IE. (Jen: Sun, Mar 28, 2004, 6:05 pm)
-re: Spyware? Random pop-ups when starting IE. (Ms. Eagle: Sun, Mar 28, 2004, 10:18 pm)
-re: Spyware? Random pop-ups when starting IE. (Charles: Mon, Mar 29, 2004, 6:28 am)
*re: Spyware? Random pop-ups when starting IE. (Ms. Eagle: Mon, Mar 29, 2004, 11:44 am)
-re: Spyware? Random pop-ups when starting IE. (Brian: Mon, Mar 29, 2004, 7:04 am)
*re: Spyware? Random pop-ups when starting IE. (Ms. Eagle: Mon, Mar 29, 2004, 11:53 am)
-re: Spyware? Random pop-ups when starting IE. (Jen: Mon, Mar 29, 2004, 5:35 pm)
*re: Spyware? Random pop-ups when starting IE. (David: Mon, Mar 29, 2004, 7:45 pm)
*! (Ms. Eagle: Mon, Mar 29, 2004, 10:52 pm)
-re: Spyware? Random pop-ups when starting IE. (Rody: Mon, Mar 29, 2004, 8:44 am)
*re: Spyware? Random pop-ups when starting IE. (Ms. Eagle: Mon, Mar 29, 2004, 11:50 am)
*re: Spyware? Random pop-ups when starting IE. (Tim: Mon, Mar 29, 2004, 10:53 am)
Return to the Windows Me Discussion Forum


All content at Annoyances.org is Copyright ©1995-2012 Creative Elementtm All rights reserved.
Please do not plagiarize; redistributing these pages without permission is strictly prohibited.