ok i just ran adaware, spybot search and destroy, and spysweeper. I get redirected to www.ads234.com and then to the page i want then a pop up.
I get pop ups when my pc is just sitting there and my PC seems to be using up my bandwidth. I also keep having to delete some "people on page" thing and "belgiandip" thing when i run spyware programs. why do they keep coming back?
I also have way to many processes running when the pc is doing nothing.
here is my hijack this log file
StartupList report, 8/4/2004, 2:53:56 PM
StartupList version: 1.52
Started from : C:\Documents and Settings\Brian\My Documents\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\program files\support.com\client\bin\tgcmd.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPMon32.exe
C:\documents and settings\brian\local settings\temp\ZVg.exe
C:\documents and settings\brian\local settings\temp\J.exe
C:\documents and settings\brian\local settings\temp\83DAPDG.exe
C:\documents and settings\brian\local settings\temp\xdfb0P7.exe
C:\WINDOWS\System32\jspwdm32.exe
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\System32\console.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\erfd009p.exe
C:\WINDOWS\System32\abinetc.exe
C:\WINDOWS\System32\mloaderd.exe
C:\WINDOWS\System32\PceK.exe
C:\WINDOWS\System32\UbgrXIn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Brian\My Documents\HijackThis.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
VAIO Action Setup (Server).lnk = ?
Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NvCplDaemon = RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
ZTgServerSwitch = c:\program files\support.com\client\bin\tgcmd.exe /server
LVCOMS = C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
NAV Agent = C:\PROGRA~1\NORTON~1\navapw32.exe
QAGENT = C:\Program Files\QUICKENW\QAGENT.EXE
TkBellExe = C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
Motive SmartBridge = C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
IPInSightLAN 01 = "C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe" -l
IPInSightMonitor 01 = "C:\Program Files\Verizon Online\Visual IP InSight\IPMon32.exe"
ppn = C:\WINDOWS\System32\ppn.exe
ZVg = C:\documents and settings\brian\local settings\temp\ZVg.exe
4X@95ME57C5BM8 = C:\WINDOWS\System32\Uit9.exe
nbjmonc = C:\WINDOWS\System32\nbjmonc.exe
BnetlibD = C:\WINDOWS\System32\BnetlibD.exe
J = C:\documents and settings\brian\local settings\temp\J.exe
83DAPDG = C:\documents and settings\brian\local settings\temp\83DAPDG.exe
xdfb0P7 = C:\documents and settings\brian\local settings\temp\xdfb0P7.exe
o73V3tW = jspwdm32.exe
erfd009p = C:\WINDOWS\System32\erfd009p.exe
mloaderd = C:\WINDOWS\System32\mloaderd.exe
abinetc = C:\WINDOWS\System32\abinetc.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SpyKiller =
Zws9Rja3Q = kd1sp.exe
console = C:\WINDOWS\System32\console.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\sstext3d.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - (no file) - SOFTWARE
myBar BHO - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing) - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC}
(no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - (no file) - {2CF0B992-5EEB-4143-99C0-5297EF71F443}
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
WinPage Affiliate - C:\Documents and Settings\Brian\Local Settings\Temp\aWU.dll - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Registration reminder 1.job
Registration reminder 2.job
Registration reminder 3.job
Symantec NetDetect.job
Norton AntiVirus - Scan my computer.job
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa...director/sw.cab
[{1D0D9077-3798-49BB-9058-393499174D5D}]
CODEBASE = file://C:\counter.cab
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yinsthelper.dll
CODEBASE = http://download.yahoo.com/dl/installs/yinst0401.cab
[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a1540.g.akamai.net/7/1540/52/200207...meInstaller.exe
[PWMediaSendControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PWActiveXImgCtl.dll
CODEBASE = http://216.249.24.142/code/PWActiveXImgCtl.CAB
[Yahoo! Webcam Upload Wrapper]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yuplapp.dll
CODEBASE = http://chat.yahoo.com/cab/yuplapp.cab
[Update Class]
InProcServer32 = C:\WINDOWS\System32\iuctl.dll
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/...7861.7980902778
[YAddBook Class]
InProcServer32 = C:\PROGRA~1\YAHOO!\Common\yaddbook.dll
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab
[PreQualifier Class]
InProcServer32 = C:\Program Files\Common Files\Verizon Online\SFP\MotivePrequal.dll
CODEBASE = http://www.verizon.net/getdsl/system_check/MotivePreQual.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab
[EPSImageControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\EPScontrol.dll
CODEBASE = http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
[MSN Chat Control 4.5]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MSNChat45.ocx
CODEBASE = http://fdl.msn.com/public/chat/msnchat45.cab
[sonyctl.sonycm]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\sonyctl.dll
CODEBASE = http://supportcentral.sel.sony.com/sdccomm...oad/sonyctl.CAB
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 8,699 bytes
Report generated in 0.078 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only