We'd like to remind Forumites to please avoid political debate on the Forum. This is to keep it a safe and useful space for MoneySaving discussions. Threads that are - or become - political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

help with cid and other pop ups - HJT log included

Options
124»

Comments

  • Browntoa
    Browntoa Posts: 49,340 Forumite
    Name Dropper Photogenic First Post First Anniversary
    Options
    then reboot and do a fresh hijackthis log
    Ex forum ambassador

    Long term forum member
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    First Anniversary Combo Breaker
    Options
    Some remnants of AVG still in there too. Use the removal tool ~
    http://www.avg.com/download-tools
    :idea:
  • thomas01155
    thomas01155 Posts: 2,369 Forumite
    First Post First Anniversary Combo Breaker
    Options
    Comodo Safesearch is a modded version of the ask toolbar.
    removing these will probably cause it to stop working.
    O2 - BHO: AskBar BHO - !!201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

    O3 - Toolbar: Ask Toolbar - !!3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
  • angelfire
    angelfire Posts: 866 Forumite
    First Anniversary Combo Breaker First Post
    Options
    Ok, I've followed Browntoa's instructions, fixed the four points of the old HJT log, deleted the fifth thingymebob, ran the Ccleaner, used the norton uninstaller, restarted, then ran a new HJT log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:06:39, on 1/2/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\COMODO\SafeSurf\cssurf.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - !!3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: Spybot-S&D IE Protection - !!53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DriveLetterAccess - !!5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - !!08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - !!08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    --
    End of file - 5750 bytes

    as far as I can see, the Comodo seems ok?
  • Reluctant_spender
    Options
    You are showing signs of having old java installed on your machine.

    Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
    1. Download the latest version of Java Runtime Environment (JRE) Version6 and save it to your desktop.
    2. Scroll down to where it says "Java Runtime Environment (JRE)6 Update 11...allows end-users to run Java applications".
    3. Click the "Download" button to the right.
    4. Select your Platform: "Windows".
    5. Select your Language: "Multi-Language".
    6. Read the License Agreement, and then check the box that says: "Accept License Agreement".
    7. Click Continue and the page will refresh.
    8. Click on the link to download Windows Offline Installation and save the file to your desktop.
    9. Close any programs you may have running - especially your web browser.
    10. Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
    11. Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
    12. Click the Remove or Change/Remove button.
    13. Follow the onscreen instructions for the Java uninstaller.
    14. Repeat as many times as necessary to remove each Java version.
    15. Reboot your computer once all Java components are removed.
    16. Then from your desktop double-click on jre-6u10-windows-i586-p.exe
    17. Follow the on screen instructions to install the latest Java version.

    Are you still getting pop ups?
  • angelfire
    angelfire Posts: 866 Forumite
    First Anniversary Combo Breaker First Post
    Options
    You are showing signs of having old java installed on your machine.

    Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
    1. Download the latest version of Java Runtime Environment (JRE) Version6 and save it to your desktop.
    2. Scroll down to where it says "Java Runtime Environment (JRE)6 Update 11...allows end-users to run Java applications".
    3. Click the "Download" button to the right.
    4. Select your Platform: "Windows".
    5. Select your Language: "Multi-Language".
    6. Read the License Agreement, and then check the box that says: "Accept License Agreement".
    7. Click Continue and the page will refresh.
    8. Click on the link to download Windows Offline Installation and save the file to your desktop.
    9. Close any programs you may have running - especially your web browser.
    10. Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
    11. Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
    12. Click the Remove or Change/Remove button.
    13. Follow the onscreen instructions for the Java uninstaller.
    14. Repeat as many times as necessary to remove each Java version.
    15. Reboot your computer once all Java components are removed.
    16. Then from your desktop double-click on jre-6u10-windows-i586-p.exe
    17. Follow the on screen instructions to install the latest Java version.
    Are you still getting pop ups?

    ok I followed the instructions above, thought i'd done the download correctly but it was quite confusing. Removed Java 5.0 then when I went to install the newer version from the icon on my desktop, i was prompted to go back online for a program to help it run or something?! think i've done something wrong! So far though, I ahven't any pop-ups
  • Reluctant_spender
    Options
    There are two ways to install this programme online or offline - either or should update your system.

    I'm glad you have no pop ups , I assume all is running well with your computer
  • thomas01155
    thomas01155 Posts: 2,369 Forumite
    First Post First Anniversary Combo Breaker
    Options
  • angelfire
    angelfire Posts: 866 Forumite
    First Anniversary Combo Breaker First Post
    Options
    Ok, s I've downloaded and installed the last java link posted and all seems ok. Once again, I would like to thank everyone for helping me with this problem. I really do not know what I would do without this site! I do try to learn from the instructions given in these techie forums, so as to avoid bothering people if there are problems I can solve myself, but in some cases, such as this one, I end up at a complete loss!

    Thanks again :-)
  • Browntoa
    Browntoa Posts: 49,340 Forumite
    Name Dropper Photogenic First Post First Anniversary
    Options
    fingers crossed...

    LOP/CID was always a so and so to remove ;)
    Ex forum ambassador

    Long term forum member
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 12 Election 2024: The MSE Leaders' Debate
  • 344.2K Banking & Borrowing
  • 250.4K Reduce Debt & Boost Income
  • 450.1K Spending & Discounts
  • 236.3K Work, Benefits & Business
  • 609.7K Mortgages, Homes & Bills
  • 173.6K Life & Family
  • 248.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards