Start a Conversation

Unsolved

This post is more than 5 years old

B

1636

May 15th, 2004 00:00

Slow Start-Up Problems, Constant Pop Up's too!! HijackThis log included.. help!

Hi there, i've had my Dell 2400 Dimension computer since September of last year, recently i've had a few problems with the start up of the computer, although its 2.6, 1024mb ram and only about 10gb of the 80gb hard drive are full, the computer wont run properly until everything is started up and this takes atleast a minute. If i click on applications before this, the computer will just freeze until they start. Usually i wont be able to get control over the computer until MSN Messenger starts. The computer does run quite slow at times although this isnt a major problem.

I'm also gettin really frustrated with pop up's. I use my AOL browser and every 10 minutes or so, i'll get a pop up on my internet explorer browser which opens itself from a website called "www.popuppers.com", it can vary from this to search results on lycos about "doubleclick", i used adaware and spybot but neither have stopped them, does anyone have any ideas how i could get rid of them? i very much appreciate anyones help... thank you very much :)

My HijackThis Logfile, thanks again...

Logfile of HijackThis v1.97.7
Scan saved at 01:46:34, on 15/05/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\ipbczwqeo.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\aoltpspd.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Kazaa Lite K++\KazaaLite.kpp
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Bobby\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {5747BA72-3648-4DF7-BA04-91CA09F20209} - C:\WINDOWS\vkgcpksq.dll
O2 - BHO: (no name) - {581F8C6F-D6B7-48A5-A223-500F60274CD1} - C:\WINDOWS\tsix.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CD2AB879-C52D-4FB9-A45B-3AD9F4293A16} - C:\WINDOWS\xylirx.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\en-gb\msntb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [bdtipjyl] C:\WINDOWS\zdlzacos.exe
O4 - HKLM\..\Run: [opprdusp] C:\WINDOWS\ipbczwqeo.exe
O4 - HKLM\..\Run: [Wast] C:\WINDOWS\Wast
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot4_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt2_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518} (ell Class) - http://www.easports.com/downloads/games/common/ieell.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/roing.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D90223F-4228-4679-8339-4CFE86BD8158}: NameServer = 195.93.49.134

3.4K Posts

May 15th, 2004 03:00

Please relocate your hijackthis.exe file to C:\HJT

FAQ's 2,3,4  http://www.russelltexas.com/spywareinfo/faqhijackthis.htm

In new folder HJT in C: root level run hijackthis and scan. Check the box to the left of each of these entries:

C:\WINDOWS\ipbczwqeo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {5747BA72-3648-4DF7-BA04-91CA09F20209} - C:\WINDOWS\vkgcpksq.dll
O2 - BHO: (no name) - {581F8C6F-D6B7-48A5-A223-500F60274CD1} - C:\WINDOWS\tsix.dll
O2 - BHO: (no name) - {CD2AB879-C52D-4FB9-A45B-3AD9F4293A16} - C:\WINDOWS\xylirx.dll
O4 - HKLM\..\Run: [bdtipjyl] C:\WINDOWS\zdlzacos.exe
O4 - HKLM\..\Run: [opprdusp] C:\WINDOWS\ipbczwqeo.exe
O4 - HKLM\..\Run: [Wast] C:\WINDOWS\Wast
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/roing.cab

With no other windows open except for Hijackthis, click on fix checked button.

Reboot in Safe Mode and enable Hidden Files option:

FAQ 8 and 9   http://www.russelltexas.com/spywareinfo/faqhijackthis.htm

Open Windows Explorer (type explorer at Start/Run).

Delete the following files and or folders.

C:\WINDOWS\ipbczwqeo.exe   file
C:\WINDOWS\vkgcpksq.dll       file
C:\WINDOWS\tsix.dll                  file
C:\WINDOWS\xylirx.dll               file
C:\WINDOWS\zdlzacos.exe      file
C:\WINDOWS\ipbczwqeo.exe   file

C:\WINDOWS\Wast     folder

Reboot in Normal Mode. Update Norton AV and run a full scan. It may find and remove this adware for popuppers.com
http://symantec.com/avcenter/venc/data/adware.roimoi.html

If not you can look for and delete the value roimoi in the Registry mentioned in section 4 on that page.

Run Disk Cleanup (type cleanmgr at Start/Run). Scan all hard drives, check all categories at end and click OK.

Browse a bit and then run Hijackthis and scan a new log. Post it here with any comments.

HTH,

Texruss

No Events found!

Top