It's Cyber Monday - fantastic 70% discount

Buy Now

Limited time offer:

03

Days

/

00

Hrs

/

04

Min

/

04

Sec

Please Help! Pop-ups and unwanted sites with underlined links?!?! Do I have a virus or ad/spyware?

Posted 3/26/2005 4:15 PM
#11703
User avatar

Dan1 Valued member

Date Joined Nov 2016
Total Posts: 27
Hi there seems to be sometyhing wrong with my computer. On every web page I open there are numerous underlined words linking to random search sites and other unwanted pop-ups and sites. There are constant "video poker" and "search" pop-ups as well as download boxes for file registry. Do I have ad or spy ware or a virus? My hijack this log is at the bottom of this. Please Help! <br/> <br/> <br/> * * * * * * * * * * * * <br/> <br/> <br/> <br/>Logfile of HijackThis v1.99.1 <br/>Scan saved at 11:13:47 AM, on 3/26/2005 <br/>Platform: Windows XP (WinNT 5.01.2600) <br/>MSIE: Internet Explorer v6.00 (6.00.2600.0000) <br/> <br/>Running processes: <br/>C:\WINDOWS\System32\smss.exe <br/>C:\WINDOWS\system32\winlogon.exe <br/>C:\WINDOWS\system32\services.exe <br/>C:\WINDOWS\system32\lsass.exe <br/>C:\WINDOWS\System32\ibmpmsvc.exe <br/>C:\WINDOWS\system32\svchost.exe <br/>C:\WINDOWS\System32\svchost.exe <br/>C:\WINDOWS\system32\spoolsv.exe <br/>C:\WINDOWS\System32\QCONSVC.EXE <br/>C:\WINDOWS\System32\svchost.exe <br/>C:\WINDOWS\Explorer.EXE <br/>C:\WINDOWS\System32\igfxtray.exe <br/>C:\WINDOWS\System32\hkcmd.exe <br/>C:\WINDOWS\LTSMMSG.exe <br/>C:\WINDOWS\System32\tp4serv.exe <br/>C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe <br/>C:\WINDOWS\System32\AEIWLSTA.EXE <br/>C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe <br/>C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe <br/>C:\WINDOWS\System32\hphmon04.exe <br/>C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe <br/>C:\Program Files\HP\hpcoretech\hpcmpmgr.exe <br/>C:\Program Files\QuickTime\qttask.exe <br/>C:\Program Files\iTunes\iTunesHelper.exe <br/>C:\WINDOWS\System32\winupdt.exe <br/>C:\WINDOWS\System32\RUNDLL32.exe <br/>C:\WINDOWS\viahpaqd.exe <br/>C:\Program Files\iPod\bin\iPodService.exe <br/>C:\Program Files\keobllpe\keobllpe.exe <br/>C:\windows\system32\eibzini.exe <br/>C:\WINDOWS\System32\lfaator.exe <br/>C:\Program Files\AutoUpdate\AutoUpdate.exe <br/>C:\WINDOWS\System32\ikznip.exe <br/>C:\WINDOWS\SysCheckBop32.exe <br/>C:\Program Files\Messenger\msmsgs.exe <br/>C:\WINDOWS\System32\kbdmgr.exe <br/>C:\windows\system32\packager.exe <br/>C:\Program Files\keobllpe\65825120.exe <br/>C:\WINDOWS\System32\rundll32.exe <br/>C:\WINDOWS\System32\rundll32.exe <br/>C:\WINDOWS\System32\wuauclt.exe <br/>C:\Program Files\Internet Explorer\IEXPLORE.EXE <br/>C:\Documents and Settings\Pathfinder Day Camp\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe <br/> <br/>R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php <br/>R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com <br/>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com <br/>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com <br/>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.passport.net/uilogin.srf?id=6528 <br/>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br/>O2 - BHO: SearchToolbarBHOObject - {12EE7A5E-0674-42f9-A76A-000000004D00} - C:\WINDOWS\System32\stlb2.dll <br/>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) <br/>O3 - Toolbar: Search - {12EE7A5E-0674-42f9-A76B-000000004D00} - C:\WINDOWS\System32\stlb2.dll <br/>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe <br/>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe <br/>O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe <br/>O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe <br/>O4 - HKLM\..\Run: [TP4EX] tp4ex.exe <br/>O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe <br/>O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE <br/>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe <br/>O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe <br/>O4 - HKLM\..\Run: [windows auto update] msblast.exe <br/>O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe <br/>O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" <br/>O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" <br/>O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" <br/>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime <br/>O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe <br/>O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe <br/>O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16 <br/>O4 - HKLM\..\Run: [dajxtmrgticpm] C:\WINDOWS\viahpaqd.exe <br/>O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe <br/>O4 - HKLM\..\Run: [keobllpe] C:\Program Files\keobllpe\keobllpe.exe <br/>O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe <br/>O4 - HKLM\..\Run: [eibzini] c:\windows\system32\eibzini.exe <br/>O4 - HKLM\..\Run: [5sti36h] lfaator.exe <br/>O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" <br/>O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\ikznip.exe <br/>O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitemav32.exe <br/>O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe" <br/>O4 - HKLM\..\Run: [salm] c:\temp\salm.exe <br/>O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32 <br/>O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain <br/>O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C <br/>O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1 <br/>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background <br/>O4 - HKCU\..\Run: [KB2sRWN6P] kbdmgr.exe <br/>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe <br/>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 <br/>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL <br/>O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm <br/>O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm <br/>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll <br/>O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe <br/>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe <br/>O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe <br/>O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
Posted 3/26/2005 5:37 PM
#11707
User avatar

Lee_UK Valued member

Date Joined Nov 2016
Total Posts: 14
Get K9 from; <br/>http://windowsx.pwp.blueyonder.co.uk/K9_Setup_Latest.exe <br/> <br/>I made a small k9 script that should remove it from here, to use it right click and click "Save target as"/"Save link as " then save it on the desktop then open it. <br/>http://lee.rafc.co.uk/Dan1.k9s
Posted 3/27/2005 3:44 PM
#11736
User avatar

Dan1 Valued member

Date Joined Nov 2016
Total Posts: 27
[4]Thank you so much. Here is my Hijack This log. I also had another question: what is BMan and BMan1? Usually when I shut down my computer it says closing BMan or BMan 1, and it is listed on the running processes of my computer. Any help you can give I would greatly appreciate. Thank you again.[/4] <br/> <br/>************************************* <br/> <br/>Logfile of HijackThis v1.99.1 <br/>Scan saved at 10:44:55 AM, on 3/27/2005 <br/>Platform: Windows XP (WinNT 5.01.2600) <br/>MSIE: Internet Explorer v6.00 (6.00.2600.0000) <br/> <br/>Running processes: <br/>C:\WINDOWS\System32\smss.exe <br/>C:\WINDOWS\system32\winlogon.exe <br/>C:\WINDOWS\system32\services.exe <br/>C:\WINDOWS\system32\lsass.exe <br/>C:\WINDOWS\System32\ibmpmsvc.exe <br/>C:\WINDOWS\system32\svchost.exe <br/>C:\WINDOWS\System32\svchost.exe <br/>C:\WINDOWS\system32\spoolsv.exe <br/>C:\WINDOWS\System32\QCONSVC.EXE <br/>C:\WINDOWS\System32\svchost.exe <br/>C:\WINDOWS\System32\igfxtray.exe <br/>C:\WINDOWS\System32\hkcmd.exe <br/>C:\WINDOWS\LTSMMSG.exe <br/>C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe <br/>C:\WINDOWS\System32\AEIWLSTA.EXE <br/>C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe <br/>C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe <br/>C:\WINDOWS\System32\hphmon04.exe <br/>C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe <br/>C:\Program Files\HP\hpcoretech\hpcmpmgr.exe <br/>C:\Program Files\QuickTime\qttask.exe <br/>C:\Program Files\iTunes\iTunesHelper.exe <br/>C:\WINDOWS\viahpaqd.exe <br/>C:\Program Files\iPod\bin\iPodService.exe <br/>C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe <br/>C:\Program Files\Messenger\msmsgs.exe <br/>C:\WINDOWS\System32\kbdmgr.exe <br/>C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe <br/>C:\WINDOWS\System32\wuauclt.exe <br/>C:\WINDOWS\explorer.exe <br/>C:\Program Files\Internet Explorer\IEXPLORE.EXE <br/>C:\Documents and Settings\Pathfinder Day Camp\Local Settings\Temp\Temporary Directory 1 for hijackthis[2].zip\HijackThis.exe <br/>C:\WINDOWS\System32\ikznip.exe <br/> <br/>R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php <br/>R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com <br/>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com <br/>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com <br/>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.passport.net/uilogin.srf?id=6528 <br/>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br/>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe <br/>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe <br/>O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe <br/>O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe <br/>O4 - HKLM\..\Run: [TP4EX] tp4ex.exe <br/>O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe <br/>O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE <br/>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe <br/>O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe <br/>O4 - HKLM\..\Run: [windows auto update] msblast.exe <br/>O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe <br/>O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" <br/>O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" <br/>O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" <br/>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime <br/>O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe <br/>O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe <br/>O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16 <br/>O4 - HKLM\..\Run: [dajxtmrgticpm] C:\WINDOWS\viahpaqd.exe <br/>O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe <br/>O4 - HKLM\..\Run: [keobllpe] C:\Program Files\keobllpe\keobllpe.exe <br/>O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe <br/>O4 - HKLM\..\Run: [eibzini] c:\windows\system32\eibzini.exe <br/>O4 - HKLM\..\Run: [5sti36h] lfaator.exe <br/>O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" <br/>O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\ikznip.exe <br/>O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitemav32.exe <br/>O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe" <br/>O4 - HKLM\..\Run: [salm] c:\temp\salm.exe <br/>O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32 <br/>O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain <br/>O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C <br/>O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1 <br/>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background <br/>O4 - HKCU\..\Run: [KB2sRWN6P] kbdmgr.exe <br/>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe <br/>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 <br/>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL <br/>O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm <br/>O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm <br/>O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll <br/>O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe <br/>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe <br/>O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe <br/>O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE <br/> <br/><br /><br />
Posted 3/27/2005 5:23 PM
#11740
User avatar

Dan1 Valued member

Date Joined Nov 2016
Total Posts: 27
[3]After I dowloaded and did what you had told me to, I am continuing to get pop-ups and there random words that are underlined as links in every web page. Please help as soon as possible. I am becoming tired of this ongoing problem. Please help, and thank you for your patience.[/3]
Posted 3/27/2005 5:32 PM
#11741
User avatar

Lee_UK Valued member

Date Joined Nov 2016
Total Posts: 14
It looks like that silly ceres thing; igfxsrvc.dll. Grap the latest k9 release(just incase a new version has been released). BMan... seems to be CWS [CoolWebSearch] related or something else that Windows doesnt really need. <br/> <br/>Then, lets try this, save the following (copy and paste) as a .k9s script file on the desktop then open it. Eg in notepad, file, save as, and then on the desktop, Go.k9s <br/> <br/>MsgBox "Script Starting" <br/> <br/>'Kill all IE <br/>While ProcessExistByEXE("IEXPLORE.EXE") = True <br/> KillProcessByEXE "IEXPLORE.EXE" <br/>Wend <br/> <br/>'Kill all Rundll32 <br/>While ProcessExistByEXE("RUNDLL32.EXE") = True <br/> KillProcessByEXE "RUNDLL32.EXE" <br/>Wend <br/>'Kill That Ceres =) <br/>MoveOnReboot "C:\WINDOWS\SYSTEM32\igfxsrvc.dll","C:\deleteme.bak" <br/> <br/>KillProcessByEXE "BMan.exe" <br/>KillProcessByEXE "BMan1.exe" <br/>KillProcessByEXE "viahpaqd.exe" <br/>KillProcessByEXE "AEIWLSTA.EXE" <br/> <br/>strRun = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\" <br/>RegDelKey strRun & "AutoUpdater" <br/>RegDelKey strRun & "windows auto update" <br/>RegDelKey strRun & "winupdtl" <br/>RegDelKey strRun & "farmmext" <br/>RegDelKey strRun & "Internet Optimizer" <br/>RegDelKey strRun & "salm" <br/>RegDelKey strRun & "KB2sRWN6P" <br/> <br/>if ProcessExistByEXE("BMan.exe") then <br/> Msgbox "BMan was not terminated" <br/>else <br/> Msgbox "Bman was terminated" <br/> <br/> if ProcessExistByEXE("BMan1.exe") then <br/> Msgbox "BMan1 was not terminated" <br/> else <br/> Msgbox "Bman1 was terminated" <br/> end if <br/>end if <br/> <br/>MsgBox "Script Ended, Repost HJT please :)"
  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Sunday, December 4, 2016, 11:28 PM (GMT +1)
There are a total of 61,160 posts in 13,449 threads.
In the last 3 days there were 3 new threads and 4 reply posts.

Who's online

This forum has 37,968 registered members. Please welcome our newest member, Old shape.
There are currently no users on-line.