Go Back   PCMech Forums > Help & Discussion > Internet, Web Applications, & The Cloud

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 06-06-2004, 11:23 PM   #1
USA Pride
 
QuickSilver's Avatar
 
Join Date: Feb 2003
Location: Montana
Posts: 1,876
Send a message via MSN to QuickSilver
Angry Fire A sudden onslaught of pop up windwos!

This would probably tick anybody off. I pride myself on keeping my computer clean and well guarded against this kind of thing, but in this case, something got through. I have been getting a huge ammount of popup windows all of the sudden. I never see the contents of the windows, and usually they are confined to the tool bar and never come up, thanks to my blockers. It still can be annoying however, as you will often end up with twice as many cubes on the tool bar as you have web sites that you are actually veiwing. I assume that I have an exe file hiding on my computer that is causing this, but finding it has proven difficult. Any ideas?
__________________
SUPPORT OUR TROOPS
QuickSilver is offline   Reply With Quote
Old 06-08-2004, 11:33 AM   #2
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 36,460
Standard solution - virus scan, Spybot, and Ad-Aware. If no joy, post a HJT log.
glc is offline   Reply With Quote
Old 06-08-2004, 10:13 PM   #3
USA Pride
 
QuickSilver's Avatar
 
Join Date: Feb 2003
Location: Montana
Posts: 1,876
Send a message via MSN to QuickSilver
HJT? Please elaborate.
QuickSilver is offline   Reply With Quote
Old 06-09-2004, 01:28 AM   #4
Certified Audio Nut
 
Hi Ho's Avatar
 
Join Date: Jul 2003
Location: Washington State
Posts: 7,202
Send a message via MSN to Hi Ho
HJT = Hijack This.
__________________
"I'm not lying. I'm writing fiction with my mouth." - Homer Simpson My Miscelaneous Gallery
ASUS P7P55D PRO / Intel Core i7 860 / 8GB Mushkin DDR3 1600 RAM / OCZ Vertex 2 120GB SSD / Seagate 1TB 7200.12 / Asus Radeon 5870 1GB / LG Super-Multi 22x SATA DVD-RW / Windows 7 Home Premium 64bit / Cable Modem / HT Omega Striker 7.1 Sound Card / FSP 700W PSU / Logitech MX1000 Wireless Laser Mouse / Asus 24" 16:9 LCD w/Webcam / Axiom Audiobyte 2.1 Speakers
Hi Ho is offline   Reply With Quote
Old 06-09-2004, 05:42 AM   #5
Member (11 bit)
 
mikeL's Avatar
 
Join Date: Nov 1999
Location: Northeast, Michigan
Posts: 1,063
Also use something other than IE
__________________
Registered linux user # 217167 - Be counted http://counter.li.org/
Currently running:
Desktop - XP Pro, Fedora
HP dv9700z CTO laptop, running Windows 7 Pro
mikeL is offline   Reply With Quote
Old 06-09-2004, 09:09 AM   #6
USA Pride
 
QuickSilver's Avatar
 
Join Date: Feb 2003
Location: Montana
Posts: 1,876
Send a message via MSN to QuickSilver
Thanks much!
QuickSilver is offline   Reply With Quote
Old 06-09-2004, 10:50 PM   #7
USA Pride
 
QuickSilver's Avatar
 
Join Date: Feb 2003
Location: Montana
Posts: 1,876
Send a message via MSN to QuickSilver
Ok, here is my HJT:

Logfile of HijackThis v1.97.7
Scan saved at 8:48:32 PM, on 6/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\Programs\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Programs\Logitech\MouseWare\system\em_exec.exe
E:\Programs\Security\NAV03\navapsvc.exe
E:\Programs\Security\OUTPOS~1.0\outpost.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\internet explorer\iexplore.exe
E:\Programs\Security\Proxomitron Naoko-4\Proxomitron.exe
E:\Programs\Sharing\KaZaA Lite\Kazaa.exe
E:\Programs\Sharing\KaZaA Lite\Speed Up.exe
E:\Programs\Utilities\Motherboard Monitor 5\MBM5.EXE
c:\program files\internet explorer\iexplore.exe
C:\Documents and Settings\Gman\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programs\FileReading\AdobeReader6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Programs\Security\NAV03\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Programs\Security\NAV03\NavShExt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] E:\Programs\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MBM 5] "E:\Programs\Utilities\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [Outpost Firewall] E:\Programs\Security\Outpost Firewall 1.0\outpost.exe /waitservice
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...8029.696400463
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
QuickSilver is offline   Reply With Quote
Old 06-09-2004, 11:44 PM   #8
Lest we forget
 
ghost2003's Avatar
 
Join Date: Jun 2003
Location: Ontario, Canada
Posts: 1,870
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
ghost2003 is offline   Reply With Quote
Old 06-10-2004, 09:44 AM   #9
Member (10 bit)
 
Join Date: May 2000
Location: PA USA
Posts: 1,004
I see Kazaa in there and I had several people with that that had the same problem. One lady's machine was ulmost unusable untill she got rid of Kazaa.(Broke her teenager's heart).
trulad
__________________
#1 HP 5310
500Hard Drive
350gb.Toshiba external back-up
4gb. Ram
Win.7 Home Premium 64bit.

#2 Sony Lap Top 500 gb. hard drive
3.0ghz AMD Athlon 4gb Ram
Win.7 Home Premium 64 bit
trulad is offline   Reply With Quote
Old 06-10-2004, 10:34 AM   #10
Member (11 bit)
 
Blue_Gundam2002's Avatar
 
Join Date: May 2003
Location: Houston, Texas
Posts: 1,340
Send a message via AIM to Blue_Gundam2002 Send a message via Yahoo to Blue_Gundam2002
Quote:
Originally posted by trulad
I see Kazaa in there and I had several people with that that had the same problem. One lady's machine was ulmost unusable untill she got rid of Kazaa.(Broke her teenager's heart).
trulad
I don't think its kazaa thats causing the problems, he's useing kazaa lite which is kazaa without the adware.
__________________
Main: ASUS P5k SE/Core 2 Duo E6550/4x1024mb DDR2 800
GeForce 8600 GT 256MB/WD 36.7GB Raptor - WD 320GB x2 - WD - 750GB x2 - WD 640GB

Laptop: Acer Aspire One AOA150
945GSE/Atom N270/1024mb DDR2 533/8.9" WSVGA/120GB HDD/2.3 lbs.

HTPC: Shuttle K48
945GC/Pentium E2180/2x1024mb DDR2 800/80GB HDD/Vizio V37L 37" LCD 1080i


Join us in the pcmech irc channel on undernet #Pcmech.
Blue_Gundam2002 is offline   Reply With Quote
Old 06-10-2004, 12:30 PM   #11
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
this is your problem
Run hijack this put a check next to these close all browsers and hit fix

Make sure not to miss one
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll


-----------------------------------------------------------------------------------------------------------------------------------

To enable the viewing of Hidden files follow these steps:
1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
6. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
7. Remove the checkmark from the checkbox labeled Hide protected operating system files.
8. Press the Apply button and then the OK button and shutdown My Computer.
9. Now your computer is configured to show all hidden files.


reboot into safe mode
How to boot into safe mode

delete these file
C:\WINDOWS\twaintec.dl
Lobos is offline   Reply With Quote
Old 06-10-2004, 12:32 PM   #12
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
or you can go here

http://www.pchell.com/support/twaintec.shtml
Lobos is offline   Reply With Quote
Old 06-10-2004, 10:36 PM   #13
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
sorry ghost you called it looking over the posts again

think i was tired and missed your post

Lobos
Lobos is offline   Reply With Quote
Old 07-13-2004, 05:17 PM   #14
USA Pride
 
QuickSilver's Avatar
 
Join Date: Feb 2003
Location: Montana
Posts: 1,876
Send a message via MSN to QuickSilver
Thanks guys! Problem solved. Wonder how I picked that crap up.
QuickSilver is offline   Reply With Quote
Old 07-13-2004, 05:37 PM   #15
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
get spyblaster if you have it update it

spyblaster has it in it's database

Try spyware blaster
spyware blaster will block spyware from comming in when you surf the net(compatible with IE, mozilla and firefox)

Lobos
Lobos is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 06:22 AM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0