Same Pop Ups Keep Showing up

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

CodeShark

Thread Starter
Joined
Dec 11, 2002
Messages
233
Hi i'm running Windows ME and I use a cable modem to go online. I keep getting pop ups from these 3 Links:
http://ads.popupsponsor.com
http://ad.doubleclick.net
http://216.76.4.207
Its always the same pop ups and its getting pretty annoying. I Ran the LATEST LAVA SOFT AD WARE and i found a lot of junk so I deleted them hoping it would fix my problems. It didn't, so I tried a Disk Clean up and I also Deleted every cookie I had and still the pop ups came. Then I tried my daily updated Mcaffee Virus scan and it still came up with nothing. After all this, the pop ups still come up and all I'm doing is chatting on aim. My explorer isn't even open and the pop ups just come. It's really ironic because the pop ups are about POP UP AD STOPPERS! So i downloaded Pop-Up stopper from downloads.com and it stops other pop ups but when the pop ups come from the links I typed above, they show up. The pop up stopper won't stop those ones.

And to speed things up, I posted the startup list results here as well. Can Anyone PLEASE HELP ME OUT? I'm fresh out of ideas. I dont know what else to do. I even went into internet explorer's options and added those sites to the restricted section as well as to block cookies from those sites and the pop ups still come!

StartupList report, 2/9/2003, 10:26:46 PM
StartupList version: 1.51
Started from : C:\UNZIPPED\STARTUPLIST151[1]\STARTUPLIST.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\PNPDEV.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\SUPPORT.COM\CLIENT\BIN\TGCMD.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\ALOGSERV.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\RNATHCHK.EXE
C:\PROGRAM FILES\AIM95\AIM.EXE
C:\WINDOWS\SYSTEM\WINSERVN.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\INSTANT
UPDATER\RULAUNCH.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\UNZIPPED\STARTUPLIST151[1]\STARTUPLIST.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
Adobe Gamma Loader.exe.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
OmgStartup = C:\Program Files\Common Files\Sony
Shared\OpenMG\OmgStartup.exe
Adaptec DirectCD = C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
ZTgServerSwitch = c:\program
files\support.com\client\lserver\server.vbs
NAV Premend OEM Utility = D:\0107301.SYM\PREMEND.EXE -silent
WinampAgent = "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
Tgcmd = "c:\program files\support.com\client\bin\tgcmd.exe" /server
QuickTime Task = C:\WINDOWS\SYSTEM\QTTASK.EXE
Plug and Play Devices = PnPDev.exe
TkBellExe = C:\Program Files\Common Files\Real\Update_OB\realsched.exe
-osboot
XupiterCfgLoader = C:\Program Files\Xupiter\XTCfgLoader.exe
DeadAIM = rundll32.exe C:\PROGRA~1\AIM95\DeadAIM.ocm,ExportedCheckODLs
Alogserv = C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
McAfee Guardian = "C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED
COMPONENTS\GUARDIAN\CMGRDIAN.EXE" /SU

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
SSDPSRV = C:\WINDOWS\SYSTEM\ssdpsrv.exe
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
Plug and Play Devices = PnPDev.exe
McAfeeVirusScanService = C:\Program Files\McAfee\McAfee
VirusScan\AVSYNMGR.EXE

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

AIM = C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
ContentService = C:\WINDOWS\SYSTEM\winservn.exe
McAfee.InstantUpdate.Monitor = "C:\Program Files\McAfee\McAfee Shared
Components\Instant Updater\RuLaunch.exe" /startmonitor
PopUpStopperFreeEdition = "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER
FREE EDITION\PSFREE.EXE"

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 9/2/2003, 19:25:14)

[rename]
NUL=C:\PROGRA~1\MCAFEE\MCAFEE~2\GUARDIAN\CMGRDENG.DLL
NUL=C:\PROGRA~1\MCAFEE\MCAFEE~2\GUARDIAN\CMGRDENG.DLL
C:\PROGRA~1\MCAFEE\MCAFEE~2\GUARDIAN\CMGRDENG.DLL=C:\PROGRA~1\MCAFEE\MCAFEE~2\GUARDIAN\RTB95271
NUL=C:\PROGRA~1\MCAFEE\MCAFEE~2\GUARDIAN\CMGRDIAN.EXE
NUL=C:\PROGRA~1\MCAFEE\MCAFEE~2\GUARDIAN\CMGRDIAN.EXE
C:\PROGRA~1\MCAFEE\MCAFEE~2\GUARDIAN\CMGRDIAN.EXE=C:\PROGRA~1\MCAFEE\MCAFEE~2\GUARDIAN\RTC95271
NUL=C:\PROGRA~1\MCAFEE\MCAFEE~2\INSTAN~1\TLSXPAND.DLL
NUL=C:\PROGRA~1\MCAFEE\MCAFEE~2\INSTAN~1\TLSXPAND.DLL
C:\PROGRA~1\MCAFEE\MCAFEE~2\INSTAN~1\TLSXPAND.DLL=C:\PROGRA~1\MCAFEE\MCAFEE~2\INSTAN~1\RTB95271
NUL=C:\WINDOWS\TEMP\PFT730~1\SETUP.EXE
NUL=C:\WINDOWS\TEMP\PFT730~1

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

--------------------------------------------------

C:\WINDOWS\WINSTART.BAT listing:

C:\WINDOWS\tmpcpyis.bat

--------------------------------------------------


Enumerating Task Scheduler jobs:

Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[sonyctl.sonycm]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\SONYCTL.DLL
CODEBASE =
http://supportcentral.sel.sony.com/sdccommon/download/sonyctl.CAB

[Support.com Configuration Class]
InProcServer32 = c:\program files\support.com\client\bin\tgctlcm.dll
CODEBASE =
http://supportcentral.sel.sony.com/sdccommon/download/tgctlcm.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE =
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE =
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

[NSUpdateLiteCtrl Class]
InProcServer32 = C:\WINDOWS\SYSTEM\NSUPDATE.DLL
CODEBASE = http://xbs.mtree.com/mt/dialers/on/US/NSupd9x.cab

[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[RdxIE Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\RDXIE.DLL
CODEBASE = http://207.188.7.150/037e9a383ea09716ef02/netzip/RdxIE6.cab

[IMViewerControl Class]
InProcServer32 = C:\WINDOWS\SYSTEM\CIMVIEW.DLL
CODEBASE =
http://companion.logitech.com/companion/logitech/ver1.3.0.2041/bin/imvid.cab

--------------------------------------------------
End of report, 7,609 bytes
Report generated in 0.350 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of
platform
/history - to list version history only
 
Joined
Nov 10, 2002
Messages
1,344
You have at least Xupiter on your machine. Download Spybot Search and Destroy from HERE

Before you scan click "Online" tab>Search for Updates and download all updates. Close down all Internet Explorer windows and scan.

"Fix" all the RED entries. Don't worry about the GREEN entries. They're harmless.

Good luck.
 

CodeShark

Thread Starter
Joined
Dec 11, 2002
Messages
233
Here's the updated start up list:

StartupList report, 2/10/2003, 5:06:12 PM
StartupList version: 1.51
Started from : C:\UNZIPPED\STARTUPLIST151[1]\STARTUPLIST.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\PNPDEV.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\SUPPORT.COM\CLIENT\BIN\TGCMD.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\ALOGSERV.EXE
C:\PROGRAM FILES\AIM95\AIM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\INSTANT UPDATER\RULAUNCH.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\RNATHCHK.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\UNZIPPED\STARTUPLIST151[1]\STARTUPLIST.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
OmgStartup = C:\Program Files\Common Files\Sony Shared\OpenMG\OmgStartup.exe
Adaptec DirectCD = C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
ZTgServerSwitch = c:\program files\support.com\client\lserver\server.vbs
NAV Premend OEM Utility = D:\0107301.SYM\PREMEND.EXE -silent
WinampAgent = "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
Tgcmd = "c:\program files\support.com\client\bin\tgcmd.exe" /server
QuickTime Task = C:\WINDOWS\SYSTEM\QTTASK.EXE
Plug and Play Devices = PnPDev.exe
TkBellExe = C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
DeadAIM = rundll32.exe C:\PROGRA~1\AIM95\DeadAIM.ocm,ExportedCheckODLs
Alogserv = C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
SSDPSRV = C:\WINDOWS\SYSTEM\ssdpsrv.exe
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
Plug and Play Devices = PnPDev.exe
McAfeeVirusScanService = C:\Program Files\McAfee\McAfee VirusScan\AVSYNMGR.EXE

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

AIM = C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
McAfee.InstantUpdate.Monitor = "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 10/2/2003, 16:37:6)

[rename]
C:\WINDOWS\APPLIC~1\SUPPORT.COM\PROFILES\MAC.ID=C:\WINDOWS\APPLIC~1\SUPPORT.COM\PROFILES\_TU4174.TMP
NUL=C:\WINDOWS\TEMP\GLB1A2B.EXE
NUL=C:\PROGRA~1\PANICW~1\POP-UP~1\UNWISE.EXE
NUL=C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
NUL=C:\PROGRA~1\PANICW~1\POP-UP~1\XAHOOK.DLL
NUL=C:\PROGRA~1\PANICW~1\POP-UP~1\XA\PSGAIN3.DLL
NUL=C:\PROGRA~1\PANICW~1\POP-UP~1\XA\PSIE6.DLL
NUL=C:\PROGRA~1\PANICW~1\POP-UP~1\XA\PSNS4.DLL
NUL=C:\PROGRA~1\PANICW~1\POP-UP~1\XA\PSNS7.DLL
NUL=C:\PROGRA~1\PANICW~1\POP-UP~1\XA\PSWMSG.DLL

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

--------------------------------------------------

C:\WINDOWS\WINSTART.BAT listing:

C:\WINDOWS\tmpcpyis.bat

--------------------------------------------------


Enumerating Task Scheduler jobs:

Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[sonyctl.sonycm]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\SONYCTL.DLL
CODEBASE = http://supportcentral.sel.sony.com/sdccommon/download/sonyctl.CAB

[Support.com Configuration Class]
InProcServer32 = c:\program files\support.com\client\bin\tgctlcm.dll
CODEBASE = http://supportcentral.sel.sony.com/sdccommon/download/tgctlcm.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[RdxIE Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\RDXIE.DLL
CODEBASE = http://207.188.7.150/037e9a383ea09716ef02/netzip/RdxIE6.cab

[IMViewerControl Class]
InProcServer32 = C:\WINDOWS\SYSTEM\CIMVIEW.DLL
CODEBASE = http://companion.logitech.com/companion/logitech/ver1.3.0.2041/bin/imvid.cab

--------------------------------------------------
End of report, 6,895 bytes
Report generated in 0.399 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Members online

No members online now.
Top