I'm getting a never-ending sequance of pop-ups normally starting with this one:
http://red.as-us.falkag.net/red?cmd=url&fl...com/11/LMO1_002
then this
http://www.advnt01.com/new_sys/click_no/index.asp?id=33134
here's a selection of the addresses which are appearing:
http://www.advnt01.com/new_sys/click_no/index.asp?id=33134
http://www.advnt01.com/new_sys/send_campai...sp?pub_id=33134
http://www.advnt01.com/new_sys/send_ocx_sof.asp?pub_id=33134
http://advnt03.com/popsend.asp?id=33134
http://www.amazon.co.uk/exec/obidos/tg/sto...3795534-8933468
http://www.amazon.co.uk/exec/obidos/tg/sto...6362223-2658214
http://www.amazon.co.uk/exec/obidos/tg/sto...6892581-6806256
http://www.bladesunlimited.co.uk
http://www.buycheapadvertising.com/advert....co.uk/top40bct4
http://www.888.com/?l=35&SR=691872&flag=1001
http://www.888.com/default.htm?lang=en&SR=694726&flag=1101
http://www.4her2shop.co.uk/Templates/bdy4h...FTOKEN=42653454
http://ads.clicksor.com/serving/cpalinks.p...-seeking.com%2F
http://ads.clicksor.com/serving/cpalinks.p...-seeking.com%2F
http://ads.realcastmedia.com/pc/53/1526/&d...t+out%21%21&p=1
http://ads.realcastmedia.com/pc/53/1942/&d...t+Out%21%21&p=1
http://www.winfixer.com/pages/scanner/inde...d2&ex=1&p=&ax=1
http://www.winfixer.com/pages/scanner/inde...d2&ex=1&p=&ax=1
http://www.webtrafficstats.net/traffic.php?CatID=92
http://uk.global-acces.com/7adpower
http://uk.global-acces.com/seed
http://www.twiceasnice.co.uk
http://www.paypopup.com/?ref=clicksorcpa
http://www.partypoker.com/index20100_np4.htm?wm=2647917
http://www.jamster.co.uk/jcw/go/rmc?partne...25&affId=172609
http://www.freespywareremoval.info
I've disabled all spyware/adware programs, i'm showing all system32 files and i've run a scan using Hijackthis.
Here's the Log:
Logfile of HijackThis v1.99.1
Scan saved at 22:40:43, on 07/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\D\WINDOWS\System32\smss.exe
D:\D\WINDOWS\system32\winlogon.exe
D:\D\WINDOWS\system32\services.exe
D:\D\WINDOWS\system32\lsass.exe
D:\D\WINDOWS\system32\svchost.exe
D:\D\WINDOWS\System32\svchost.exe
D:\D\WINDOWS\Explorer.EXE
D:\D\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\D\WINDOWS\System32\Fmctrl.EXE
D:\D\WINDOWS\SOUNDMAN.EXE
D:\Program Files\D-Link\AirPlus Xtreme G\AirPlusCFG.exe
D:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Java\jre1.5.0\bin\jusched.exe
D:\Program Files\Picasa2\PicasaMediaDetector.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\D\WINDOWS\System32\RUNDLL32.EXE
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Setup.exe
D:\D\WINDOWS\System32\ctfmon.exe
D:\D\WINDOWS\FSScrCtl.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\D\WINDOWS\System32\nvsvc32.exe
D:\D\WINDOWS\System32\svchost.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://thesearchmall.com/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\D\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] D:\D\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] D:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [D-Link AirPlus Xtreme G] D:\Program Files\D-Link\AirPlus Xtreme G\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCSService] D:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [STOPzilla] "D:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [LifeScape Media Detector] D:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] D:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [winupdate] D:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\Run: [gah95on6] D:\D\WINDOWS\System32\gah95on6.exe
O4 - HKLM\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\D\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\D\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "D:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PCguard] "D:\Program Files\blueyonder\PCguard\RPS.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MyVBApp] C:\Setup.exe
O4 - HKLM\..\Run: [Media Gateway] D:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\D\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [seticlient] D:\Program Files\SETI@home\SETI@home.exe -min
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\D\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Screen Saver Control.lnk = D:\D\WINDOWS\FSScrCtl.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - D:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc...e/bridge-c9.cab
O16 - DPF: {41D13E9A-BB94-402A-8502-AFA78526B63D} (iiittt Class) - http://www.thesearchmall.com/toolbar/winsrm32.cab
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\D\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hope you can help.....
Thanx in advance...