1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Windows 98 Machine: Excessive Pop Ups

Discussion in 'Malware and Virus Removal Archive' started by rtstanley, 2004/12/23.

Thread Status:
Not open for further replies.
  1. 2004/12/23
    rtstanley

    rtstanley Inactive Thread Starter

    Joined:
    2002/04/20
    Messages:
    50
    Likes Received:
    0
    I'm sure this has been discussed, but I'm looking for some quick recommendations.

    I have a relative I'm going to see tomorrow. She said about 2 months ago, her PC started having horrible problems with excessive pop-ups. She has installed spybot and adaware. She runs these, deletes everything found. However, she can go onto the internet, and almost immediately, the pop-up problem resumes.

    Can you guys recommend other stuff to try. Here is what I was going to do.

    Install Norton AV 2005 (she has an older AV software)
    Clear IE cache
    Make sure she has the latest spybot and adaware
    Scandisk
    Defrag
    Disk Clean-up

    Any other recommendations?

    As usual, thank you for any ideas or suggestions.
     
  2. 2004/12/23
    BearNunya

    BearNunya Inactive

    Joined:
    2004/10/20
    Messages:
    39
    Likes Received:
    0
    Google Toolbar

    Give the Google Toolbar a try, it's free and includes an excellent popup stopper. :)
     

  3. to hide this advert.

  4. 2004/12/23
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    My best idea would be for your relative to post a HijackThis log, for any leftovers. While Spybot and Ad-Aware both do a fine job, HJT is used as a good cleanup. However, it is only a tool and doesn't label anything found as bad or good. Getting advice on what to remove is a good idea.
     
  5. 2004/12/23
    rtstanley

    rtstanley Inactive Thread Starter

    Joined:
    2002/04/20
    Messages:
    50
    Likes Received:
    0
    Will post a hijackThis log as soon as I can. Thank you for the reply.
     
  6. 2004/12/25
    rtstanley

    rtstanley Inactive Thread Starter

    Joined:
    2002/04/20
    Messages:
    50
    Likes Received:
    0
    Ok. Here is the hijacklog. However, note that I got the latest spybot, adaware, and NAV 2005. There were about 18 viruses detected by NAV and probably 150 items between spybot and adaware.

    In any event, here is the hijack log. Let me know what you think.

    Logfile of HijackThis v1.99.0
    Scan saved at 4:43:59 PM, on 12/25/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.50 (5.50.4134.0600)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
    C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\HPZTSB05.EXE
    C:\WINDOWS\SYSTEM\HPHMON04.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SVRRUN.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
    C:\PROGRAM FILES\INTERNET\ICC\ICC32.EXE
    C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
    C:\WINDOWS\SYSTEM\HPHIPM11.EXE
    C:\WINDOWS\DESKTOP\FOR PAM\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/sidesearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.rev.net/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe
    O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\SYSTEM\HPHMON04.EXE
    O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe "
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [svrrun] C:\WINDOWS\svrrun.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe "
    O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe "
    O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    O4 - Startup: Rev.Net.LNK = C:\Program Files\Internet\icc\icc32.exe
    O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/18fcb95f6f8d1bfc8d14/netzip/RdxIE601.cab
     
  7. 2004/12/25
    rtstanley

    rtstanley Inactive Thread Starter

    Joined:
    2002/04/20
    Messages:
    50
    Likes Received:
    0
    OK, we have been on the internet for maybe all of 60 seconds and the pop-up problem is still there! PLEASE HELP !!!!

    Here are some of the pop-ups that occur a lot....

    pop-ups from something titled targetnet.com
    pop-up from something called tickle.com
     
  8. 2004/12/25
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Im Moving your post to our security area, Mark or another forum member will be glad to help, Hang in there.
     
  9. 2004/12/26
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    Remove these items with HJT.

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/sidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
    O4 - HKLM\..\Run: [svrrun] C:\WINDOWS\svrrun.exe

    Reboot, find the file "svrrun.exe" and delete it. It may be marked as 'Hidden" or 'System" to hide it.

    As a general cleanup for 98SE, especially since Spybot and Ad-Aware found so much, you should Restart in Dos Mode and do these commands, reboot when done, and these folders will be rebuilt clean. The first command will appear to do nothing, it speeds things up.
    smartdrv
    deltree c:\windows\cookies
    deltree c:\windows\history
    deltree c:\windows\temp
    deltree c:\windows\tempor~1

    Type a Y that you want to delete, check for typos as this time.

    Please post a new log after surfing a bit, to see if anything else show up.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.