<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Popups in Security</title>
<link>http://www.dslreports.com/forum/r9115397</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 12:03:17 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 12:03:17 EDT</lastBuildDate>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9118827</link>
<description><![CDATA[<A HREF="/useremail/u/304287"><b>pream</b></A> : I have to leave now.  Thanks all for your help.  It looks like the first job got rid of the two files from starting.  I am posting the latest hijackthis.  If there is any more I can do, I might be able to guide my son through it over the phone.<br><br>Logfile of HijackThis v1.97.7<br>Scan saved at 7:30:24 PM, on 1/18/2004<br>Platform: Windows ME (Win9x 4.90.3000)<br>MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)<br><br>Running processes:<br>C:\WINDOWS\SYSTEM\KERNEL32.DLL<br>C:\WINDOWS\SYSTEM\MSGSRV32.EXE<br>C:\WINDOWS\SYSTEM\mmtask.tsk<br>C:\WINDOWS\SYSTEM\MPREXE.EXE<br>C:\WINDOWS\SYSTEM\MSTASK.EXE<br>C:\WINDOWS\EXPLORER.EXE<br>C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE<br>C:\WINDOWS\SYSTEM\SYSTRAY.EXE<br>C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE<br>C:\PROGRAM FILES\IPOD\BIN\IPODMANAGER.EXE<br>C:\WINDOWS\SYSTEM\WMIEXE.EXE<br>C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE<br>C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE<br>C:\PROGRAM FILES\IPOD\BIN\IPODSERVICE.EXE<br>C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE<br>C:\WINDOWS\SYSTEM\DDHELP.EXE<br>C:\WINDOWS\SYSTEM\STIMON.EXE<br>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE<br>C:\PROGRAM FILES\BROADBAND\HIJACKTHIS.EXE<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T WorldNet Service<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = &raquo;<A HREF="http://hometab.bellsouth.net/" >hometab.bellsouth.net/</A><br>O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar_en_2.0.95-deleon.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL<br>O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar_en_2.0.95-deleon.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE<br>O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme<br>O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe<br>O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe<br>O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager.exe<br>O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe<br>O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg<br>O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme<br>O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe<br>O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe<br>O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM<br>O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM<br>O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmsearch.html<br>O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmcache.html<br>O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmsimilar.html<br>O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmbacklinks.html<br>O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmtrans.html<br>O9 - Extra button: Related (HKLM)<br>O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)<br>O9 - Extra button: Encarta Encyclopedia (HKLM)<br>O9 - Extra 'Tools' menuitem: Encarta Encyclopedia (HKLM)<br>O9 - Extra button: Define (HKLM)<br>O9 - Extra 'Tools' menuitem: Define (HKLM)<br>O9 - Extra button: Real.com (HKLM)<br>O9 - Extra button: AIM (HKLM)<br>O9 - Extra 'Tools' menuitem: Turbo Download (HKLM)<br>O9 - Extra button: Dell Home (HKCU)<br>O12 - Plugin for .mfg: C:\PROGRA~1\INTERN~1\PLUGINS\npmirage.dll<br>O14 - IERESET.INF: START_PAGE_URL=http://www.worldnet.att.net<br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;lash.cab</A><br>O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - &raquo;<A HREF="http://www.installengine.com/engine/isetup.cab" >www.installengine.com/engine/isetup.cab</A><br>O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! WebCam Viewer Wrapper) - &raquo;<A HREF="http://chat.yahoo.com/cab/yvwrctl.cab" >chat.yahoo.com/cab/yvwrctl.cab</A><br>O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &raquo;<A HREF="http://download.yahoo.com/dl/installs/yinst.cab" >download.yahoo.com/dl/installs/yinst.cab</A><br>O16 - DPF: {E87A6788-1D0F-4444-8898-1D25829B6755} (MSN Chat Control 4.0) - &raquo;<A HREF="http://fdl.msn.com/public/chat/msnchat4.cab" >fdl.msn.com/public/chat/msnchat4.cab</A><br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://www.apple.com/qtactivex/qtplugin.cab" >www.apple.com/qtactivex/qtplugin.cab</A><br>O16 - DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} (XMirage Control) - &raquo;<A HREF="http://www.myfamily.com/plugins/ue/Install_UE.exe" >www.myfamily.com/plugins/ue/Install_UE.exe</A><br>O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;r/sw.cab</A><br>O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &raquo;<A HREF="http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37926.7612268519" >v4.windowsupdate.microsoft.com/C&middot;&middot;&middot;12268519</A><br>O16 - DPF: {01118D00-3E00-11D2-8470-0060089874ED} (SupportSoft Password Reset Class) - &raquo;<A HREF="http://www.fastaccesstools.com/sdccommon/download/tgctlpw.cab" >www.fastaccesstools.com/sdccommo&middot;&middot;&middot;tlpw.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &raquo;<A HREF="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab" >us.chat1.yimg.com/us.yimg.com/i/&middot;&middot;&middot;scom.cab</A><br>O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - &raquo;<A HREF="http://lg.home.microsoft.com/search/lobby/searchsettings.cab" >lg.home.microsoft.com/search/lob&middot;&middot;&middot;ings.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe" >a1408.g.akamai.net/7/1408/9955/2&middot;&middot;&middot;etup.exe</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9118827</guid>
<pubDate>Sun, 18 Jan 2004 19:33:31 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9118397</link>
<description><![CDATA[<A HREF="/useremail/u/304287"><b>pream</b></A> : Yes the first file ran fine.  I tried running "Find backup and Delete Peper files.vbs" from safe mode, but got the same result.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9118397</guid>
<pubDate>Sun, 18 Jan 2004 18:43:57 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9117895</link>
<description><![CDATA[<A HREF="/useremail/u/525050"><b>Zupe</b></A> : So the first file ran without a problem?  You may want to try booting to safe mode and running "Find backup and Delete Peper files.vbs" from there.<br><br>You might also want to check in NAV's options under Script Blocking and verify that it's set to "Ask Me What to Do", as the other option would prevent this from running without a prompt and could probably cause an error like that.<br><SMALL>--<br><I>Brain:</I> Pinky, are you pondering what I'm pondering?<BR><I>Pinky:</I> I think so, Brain, but "Snowball for Windows"?</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9117895</guid>
<pubDate>Sun, 18 Jan 2004 17:47:35 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9117311</link>
<description><![CDATA[<A HREF="/useremail/u/304287"><b>pream</b></A> : Also I deleted all from startup with the same result.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9117311</guid>
<pubDate>Sun, 18 Jan 2004 16:29:17 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9117163</link>
<description><![CDATA[<A HREF="/useremail/u/304287"><b>pream</b></A> : I have downloaded the two files and run them.  When I run Find backup and delete oeoer files.vbs, it prompts for the file.  When I enter Rcn0.exe, it appears to run for about 2 minutes and then I get an "out of memory" message.<br><br>Any ideas?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9117163</guid>
<pubDate>Sun, 18 Jan 2004 16:09:21 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9116541</link>
<description><![CDATA[<A HREF="/useremail/u/525050"><b>Zupe</b></A> :  <BLOCKQUOTE><SMALL>said by  John2g <A HREF="/useremail/u/448758"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>I cannot find anything on theses 2 exes and they seem to be suspicious.<br><br>C:\WINDOWS\SYSTEM\ZMZ4.EXE<br>C:\WINDOWS\SYSTEM\RSAQS5.EXE<br><br>Someone thinks that RSAQS5.EXE is a trojan, but I cannot confirm that.<br> <HR></BLOCKQUOTE>Those both look to be part of the Peper trojan I mentioned above.  They'll be removed if you use the uninstall procedure I listed.<br><SMALL>--<br><I>Brain:</I> Pinky, are you pondering what I'm pondering?<BR><I>Pinky:</I> I think so, Brain, but "Snowball for Windows"?</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9116541</guid>
<pubDate>Sun, 18 Jan 2004 14:49:31 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9116537</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> :  <BLOCKQUOTE><SMALL>said by  pream <A HREF="/useremail/u/304287"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>I have done searches for both of these and cannot find them.  He is running NAV 2002.<br> <HR></BLOCKQUOTE><br><br>He may have these as hidden files. To unhide them, go to Control Panel\Folder Options\View and "uncheck" Hide protected operating system files.<br><br>Then recheck, as they are listed in running applications in HJT.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9116537</guid>
<pubDate>Sun, 18 Jan 2004 14:49:08 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9116528</link>
<description><![CDATA[<A HREF="/useremail/u/525050"><b>Zupe</b></A> :  <BLOCKQUOTE><SMALL>said by  pream <A HREF="/useremail/u/304287"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://server224.smartbotpro.net/7search/?003-nhp" >server224.smartbotpro.net/7search/?003-nhp</A><br><br>O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL (file missing)<br><br>O2 - BHO: (no name) - {338DB36D-828A-4D18-8864-977B09C4B8A7} - C:\WINDOWS\SYSTEM\QDBGHELP.DLL<br><br>O4 - HKLM\..\Run: [5QEKE7T5NG9WG2] C:\WINDOWS\SYSTEM\Rcn0.exe<br><br>O8 - Extra context menu item: Get It With Kontiki - res://C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL/201<br><br>O16 - DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} (XMirage Control) - &raquo;<A HREF="http://www.myfamily.com/plugins/ue/Install_UE.exe" >www.myfamily.com/plugins/ue/Install_UE.exe</A><br><br>O16 - DPF: {01118D00-3E00-11D2-8470-0060089874ED} (SupportSoft Password Reset Class) - &raquo;<A HREF="http://www.fastaccesstools.com/sdccommon/download/tgctlpw.cab" >www.fastaccesstools.com/sdccommo&middot;&middot;&middot;tlpw.cab</A> <HR></BLOCKQUOTE>You've got the Peper trojan among other things.<br><br>To deal with the Peper trojan, do the following: <br><br>1. Download and run this file to fix the Peper Trojan: &raquo;<A HREF="http://home01.wxs.nl/~kleyn080/uninst.exe" >home01.wxs.nl/~kleyn080/uninst.exe</A> <br><br>Double click on 'uninst.exe', let it run and terminate. <br><br>2. To delete the related files download the following tool: <br>&raquo;<A HREF="http://www.mjc1.com/files/mo/drpepertobackup.exe" >www.mjc1.com/files/mo/drpepertobackup.exe</A><br> <br>Double-click the downloaded file and it will extract to C:\drpeper <br><br>Navigate to the C:\drpeper folder and double-click "Find backup and Delete Peper files.vbs" <br><br>At the first prompt copy and paste: Rcn0.exe and hit ok. <br><br>You will get a confirmation notice, then a second prompt: <br>At the second prompt, paste: ZMZ4.EXE and hit ok. <br><br>It will find all the files, delete them and will make backups in the same folder. It will then open a text file (Peper.txt) with the list of all files deleted. Make sure that text file is saved. <br><br>Next, with all browser windows closed, rescan with Hijack This and put a check next to any of the items I listed above that remain, then click "Fix Checked".  Reboot, rescan with Hijack This and post a new log here together with the contents of the Peper.txt file you saved earlier.<br><SMALL>--<br><I>Brain:</I> Pinky, are you pondering what I'm pondering?<BR><I>Pinky:</I> I think so, Brain, but "Snowball for Windows"?</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9116528</guid>
<pubDate>Sun, 18 Jan 2004 14:48:23 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9116489</link>
<description><![CDATA[<A HREF="/useremail/u/304287"><b>pream</b></A> : I have done searches for both of these and cannot find them.  He is running NAV 2002.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9116489</guid>
<pubDate>Sun, 18 Jan 2004 14:43:16 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9116361</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> :  <BLOCKQUOTE><SMALL>said by  pream <A HREF="/useremail/u/304287"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>Shootthemessanger does not support Windows ME.<br> <HR></BLOCKQUOTE><br><br>I'm sorry. I had forgotten he was using ME.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9116361</guid>
<pubDate>Sun, 18 Jan 2004 14:29:07 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9116306</link>
<description><![CDATA[<A HREF="/useremail/u/304287"><b>pream</b></A> : Shootthemessanger does not support Windows ME.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9116306</guid>
<pubDate>Sun, 18 Jan 2004 14:21:19 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9115854</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : I cannot find anything on theses 2 exes and they seem to be suspicious.<br><br>C:\WINDOWS\SYSTEM\ZMZ4.EXE<br>C:\WINDOWS\SYSTEM\RSAQS5.EXE<br><br>Someone thinks that RSAQS5.EXE is a trojan, but I cannot confirm that.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9115854</guid>
<pubDate>Sun, 18 Jan 2004 13:31:53 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9115789</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : As a general point, your son may be getting pop ups as a result of running "Windows Messenger"<br><br>You can overcome this by downloading and running shootthemessenger from: &raquo;<A HREF="http://grc.com/stm/shootthemessenger.htm" >grc.com/stm/shootthemessenger.htm</A><br><br>Another way of stopping most pop ups is to DISABLE Java and Active Scripting in Internet Explorer. Go to Tools\Internet Options\Security and click the "Internet" icon and choose "Custom" and you can alter the settings there.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9115789</guid>
<pubDate>Sun, 18 Jan 2004 13:24:12 EDT</pubDate>
</item>

<item>
<title>Re: Popups</title>
<link>http://www.dslreports.com/forum/remark,9115711</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : I am NOT an expert, but I think you should have HJT fix the following entries.<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;server224.smartbotpro.net/7search/?003..<br>O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL (file missing)<br>O2 - BHO: (no name) - {338DB36D-828A-4D18-8864-977B09C4B8A7} - C:\WINDOWS\SYSTEM\QDBGHELP.DLL<br>O4 - HKLM\..\Run: [5QEKE7T5NG9WG2] C:\WINDOWS\SYSTEM\Rcn0.exe<br>O8 - Extra context menu item: Get It With Kontiki - res://C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL/201<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9115711</guid>
<pubDate>Sun, 18 Jan 2004 13:16:00 EDT</pubDate>
</item>

<item>
<title>Popups</title>
<link>http://www.dslreports.com/forum/remark,9115397</link>
<description><![CDATA[<A HREF="/useremail/u/304287"><b>pream</b></A> : I am my son's computer.  Windows ME.  He has a popup nightmare.  One after another.  He has allowed many people to download onto this system.  I have been working each time I am here to try to correct, with no success.  I have run Spybot.  Now Hijackthis.  Any help would be greatly appreciated.<br><br>Logfile of HijackThis v1.97.7<br>Scan saved at 12:37:45 PM, on 1/18/2004<br>Platform: Windows ME (Win9x 4.90.3000)<br>MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)<br><br>Running processes:<br>C:\WINDOWS\SYSTEM\KERNEL32.DLL<br>C:\WINDOWS\SYSTEM\MSGSRV32.EXE<br>C:\WINDOWS\SYSTEM\mmtask.tsk<br>C:\WINDOWS\SYSTEM\MPREXE.EXE<br>C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE<br>C:\WINDOWS\SYSTEM\MSTASK.EXE<br>C:\WINDOWS\EXPLORER.EXE<br>C:\WINDOWS\SYSTEM\SYSTRAY.EXE<br>C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE<br>C:\WINDOWS\SYSTEM\WMIEXE.EXE<br>C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE<br>C:\PROGRAM FILES\IPOD\BIN\IPODMANAGER.EXE<br>C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE<br>C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE<br>C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE<br>C:\PROGRAM FILES\IPOD\BIN\IPODSERVICE.EXE<br>C:\WINDOWS\SYSTEM\ZMZ4.EXE<br>C:\WINDOWS\SYSTEM\RSAQS5.EXE<br>C:\WINDOWS\SYSTEM\DDHELP.EXE<br>C:\WINDOWS\SYSTEM\STIMON.EXE<br>C:\DOWNLOAD\HIJACKTHIS\HIJACKTHIS.EXE<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &raquo;<A HREF="http://server224.smartbotpro.net/7search/?003-nhp" >server224.smartbotpro.net/7search/?003-nhp</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T WorldNet Service<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = &raquo;<A HREF="http://hometab.bellsouth.net/" >hometab.bellsouth.net/</A><br>O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL (file missing)<br>O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar_en_2.0.95-deleon.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O2 - BHO: (no name) - {338DB36D-828A-4D18-8864-977B09C4B8A7} - C:\WINDOWS\SYSTEM\QDBGHELP.DLL<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL<br>O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar_en_2.0.95-deleon.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme<br>O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE<br>O4 - HKLM\..\Run: [5QEKE7T5NG9WG2] C:\WINDOWS\SYSTEM\Rcn0.exe<br>O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe<br>O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe<br>O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager.exe<br>O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme<br>O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service<br>O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe<br>O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg<br>O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe<br>O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe<br>O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM<br>O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM<br>O8 - Extra context menu item: Get It With Kontiki - res://C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL/201<br>O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmsearch.html<br>O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmcache.html<br>O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmsimilar.html<br>O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmbacklinks.html<br>O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmtrans.html<br>O9 - Extra button: Related (HKLM)<br>O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)<br>O9 - Extra button: Encarta Encyclopedia (HKLM)<br>O9 - Extra 'Tools' menuitem: Encarta Encyclopedia (HKLM)<br>O9 - Extra button: Define (HKLM)<br>O9 - Extra 'Tools' menuitem: Define (HKLM)<br>O9 - Extra button: Real.com (HKLM)<br>O9 - Extra button: AIM (HKLM)<br>O9 - Extra 'Tools' menuitem: Turbo Download (HKLM)<br>O9 - Extra button: Dell Home (HKCU)<br>O12 - Plugin for .mfg: C:\PROGRA~1\INTERN~1\PLUGINS\npmirage.dll<br>O14 - IERESET.INF: START_PAGE_URL=http://www.worldnet.att.net<br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;lash.cab</A><br>O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - &raquo;<A HREF="http://www.installengine.com/engine/isetup.cab" >www.installengine.com/engine/isetup.cab</A><br>O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! WebCam Viewer Wrapper) - &raquo;<A HREF="http://chat.yahoo.com/cab/yvwrctl.cab" >chat.yahoo.com/cab/yvwrctl.cab</A><br>O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - &raquo;<A HREF="http://download.yahoo.com/dl/installs/yinst.cab" >download.yahoo.com/dl/installs/yinst.cab</A><br>O16 - DPF: {E87A6788-1D0F-4444-8898-1D25829B6755} (MSN Chat Control 4.0) - &raquo;<A HREF="http://fdl.msn.com/public/chat/msnchat4.cab" >fdl.msn.com/public/chat/msnchat4.cab</A><br>O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &raquo;<A HREF="http://www.apple.com/qtactivex/qtplugin.cab" >www.apple.com/qtactivex/qtplugin.cab</A><br>O16 - DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} (XMirage Control) - &raquo;<A HREF="http://www.myfamily.com/plugins/ue/Install_UE.exe" >www.myfamily.com/plugins/ue/Install_UE.exe</A><br>O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - &raquo;<A HREF="http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab" >download.macromedia.com/pub/shoc&middot;&middot;&middot;r/sw.cab</A><br>O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &raquo;<A HREF="http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37926.7612268519" >v4.windowsupdate.microsoft.com/C&middot;&middot;&middot;12268519</A><br>O16 - DPF: {01118D00-3E00-11D2-8470-0060089874ED} (SupportSoft Password Reset Class) - &raquo;<A HREF="http://www.fastaccesstools.com/sdccommon/download/tgctlpw.cab" >www.fastaccesstools.com/sdccommo&middot;&middot;&middot;tlpw.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &raquo;<A HREF="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab" >us.chat1.yimg.com/us.yimg.com/i/&middot;&middot;&middot;scom.cab</A><br>O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - &raquo;<A HREF="http://lg.home.microsoft.com/search/lobby/searchsettings.cab" >lg.home.microsoft.com/search/lob&middot;&middot;&middot;ings.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe" >a1408.g.akamai.net/7/1408/9955/2&middot;&middot;&middot;etup.exe</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,9115397</guid>
<pubDate>Sun, 18 Jan 2004 12:44:00 EDT</pubDate>
</item>

</channel>
</rss>
