|
|
|
Pop ups help me remove them
|
Original Message
|
Name: Gen
Date: March 16, 2004 at 09:13:59 Pacific
Subject: Pop ups help me remove themOS: -CPU/Ram: - |
Comment: PLEASE!!! HELP ME REMOVE A PROGRAM WHICH IS CAUSING POP UPS ON MY COMPUTER I HAVE AD-AWARE IT DOESNT REMOVE IT I DISABLED WINDOWS MESSENGER IVE DONE EVERYTHING POSSIBLE IT DOESNT HELP PLEASE HELP ME!! Everyones entitled to be stupid but your abusing the privledge
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: doofus
Date: March 16, 2004 at 09:39:25 Pacific
|
Reply: (edit)First, ya gotta sit down and take a deep breath...chill. Now then, 1...d/l Spybot and run it 2..make sure you have the updates for adaware installed. 3. d/l CWShredder and run it in safe mode. 4. Run whatever anti virus program you're using. Then...come back and let us know what's happening.
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
Name: leli
Date: March 16, 2004 at 10:28:16 Pacific
|
Reply: (edit)you might also want to try, deleting your internet cookies, temp internet files and clearing out your browswer cache. Usually that will take care of most or all the issues that programs such as spybot miss. Hope this helps!
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: dagowv
Date: March 16, 2004 at 14:53:45 Pacific
|
Reply: (edit)I too am having pop up problems. I have ran every spyware program out there. Adaware, Spyhunter, Spybot. You name it i've tried it. I continue to have these certain pop ups that try to mimic themselves like they are coming from the internet when in fact they are lodged somewhere on my hard drive that I can not find. I found in another post on this forum a program called Hijack This. Your supposed to run it and then look at what it found running on your computer. Problem is I dont know what is on there that needs deleted. Can someone look at this and let me know? Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\LEXBCES.EXE C:\WINNT\system32\spoolsv.exe C:\WINNT\system32\LEXPPS.EXE C:\WINNT\system32\Ati2evxx.exe C:\Program Files\Network Associates\VirusScan\avsynmgr.exe C:\WINNT\System32\drivers\CDAC11BA.EXE C:\WINNT\System32\DRIVERS\CDANTSRV.EXE C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\Program Files\Network Associates\VirusScan\VsStat.exe C:\WINNT\Explorer.EXE C:\Program Files\Network Associates\VirusScan\Vshwin32.exe C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe C:\WINNT\system32\lxamsp32.exe C:\WINNT\system32\atiptaxx.exe C:\Program Files\DIGStream\digstream.exe C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe C:\Program Files\Active SMART\ActiveSMART.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Yahoo!\Messenger\YPager.exe C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe C:\PROGRA~1\Yahoo!\MESSEN~1\YServer.exe C:\unzipped\hijackthis1977\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eversonfinancial.com/ R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file) O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINNT\mxTarget.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [PrinTray] C:\WINNT\system32\spool\DRIVERS\W32X86\3\printray.exe O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe O4 - HKLM\..\Run: [rwlevel] c:\rwlevel2k O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NODEDIAG] c:\apps\sacomm\colonial O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe O4 - HKLM\..\Run: [Belt] C:\WINNT\Belt.exe O4 - HKLM\..\Run: [SpyBlocker] C:\Program Files\SpyBlocker Software\spyblocker.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet O4 - Startup: Active SMART.lnk = C:\Program Files\Active SMART\ActiveSMART.exe O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Notify.lnk = C:\SA\SA10_0\NOTIFY.EXE O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: AIM (HKLM) O9 - Extra button: Open this PDF with PDFtypewriter (HKLM) O9 - Extra button: Yahoo! Messenger (HKLM) O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50047/QDow.cab O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://12.144.132.56/webline/applets/msie40x.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} (Seagate SeaTools English Online) - http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_5_0.cab
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: OtheHill
Date: March 16, 2004 at 15:34:07 Pacific
|
Reply: (edit)Have you done a update on Adaware or Spybot recently? I used adaware yesterday, did an update and sound 1 more file. These folks that want to take over our screens are hard at work.
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: dagowv
Date: March 16, 2004 at 17:27:59 Pacific
|
Reply: (edit)I've done updates on all the programs and nothing has worked. This one is one mean sucker!
Report Offensive Follow Up For Removal
|
|
Response Number 8
|
Name: Gen
Date: March 18, 2004 at 09:01:32 Pacific
|
Reply: (edit)ok i used all the programs u said apart from google toolbar (adware) spybot didnt work it frozen and caused pop ups while checking a file got anymore cw shredder didnt help much either :( Everyones entitled to be stupid but your abusing the privledge
Report Offensive Follow Up For Removal
|
Use following form to reply to current message:
|
|

|