Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HELP! PC Totally bogged


  • This topic is locked This topic is locked
9 replies to this topic

#1 fegleyj

fegleyj

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:13 PM

Posted 09 September 2004 - 06:11 PM

PLEASE HELP!!!

Quick Overview: I installed SP2 when it was released, it crashed my system due to an old ?microcode? appearantly. I formatted and re-installed WinXP Pro + SP1. Microsoft would not allow me to DL any updates other than SP2 so my PC went without updates for about a week before the problems started. Recently microsoft released their cumulative updates again, but it was too late and the damage was already done it seems. Now my PC is really bad. Uncontrolable pop-ups, random software installs without prompting, etc. I used to like Microssoft, but after what has happened, I HATE them. My PC had been runnin PERFECT for about 3 years with no spyware etc, and then this brings it down. Someone please help me restore some functionality until my next format and clean install!!

HijackThis Log:

Logfile of HijackThis v1.98.2
Scan saved at 7:20:06 PM, on 9/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\taskswitch.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\WinTools\WToolsA.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\Program Files\My Daily Horoscope\MyDailyHoroscope.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50032
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fark.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.download.dir", "D:\\temp\\New Folder\\Creampie");
user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("dom.disable_open_during_load", true);
user_pref("intl.charsetmenu.browser.cache", "windows-1252, ISO-8859-1");
user_pref("network.cookie.prefsMigrated", true);
user_pref("prefs.converted-to-utf8", true);
user_pref("privacy.popups.first_popup", false);
user_pref("signon.Si
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [woepuahlj] C:\WINDOWS\System32\zlyydbtg.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MyDailyHoroscope] C:\PROGRA~1\MYDAIL~1\MYDAIL~1.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - Startup: AdDestroyer.lnk = C:\Program Files\AdDestroyer\AdDestroyer.exe
O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1093608992453
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll



***********************************
END LOG

Thank you in advance.

Edited by fegleyj, 09 September 2004 - 06:23 PM.


BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,503 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:13 PM

Posted 09 September 2004 - 09:37 PM

Now please Download LSPFix from http://www.cexx.org/lspfix.htm and Run the Program. Disconnect from the Internet and close all Internet Explorer Windows. Check the "I know what I'm doing" Button and place all listings of c:\windows\system32\inetadpt.dll into the remove section by clicking on the button that points to the right. When all instances of this dll are in the Remove section. Press the finish button.

Then Reboot.

To see a tutorial on how to use this program click the link below:

Using LSP-Fix to remove LSP Spyware & Hijackers

Then,

Click on start, settings, control panel and double-click on add/remove programs. From with add/remove program uninstall the following if they exist:

Window Search
Win Tools
IEtools
IESearch
Windows Assistant
WindowsSA
Search Assistant
Windows Search Assistant

When uninstalling you wil prompted to insert a security code. Please do so and reboot when done.

If you do not see thsee two programs in your Add/Remove programs then download and run both of these uninstallers:

http://lop.com/new_uninstall.exe
http://lop.com/toolbar_uninstall.exe

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [woepuahlj] C:\WINDOWS\System32\zlyydbtg.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKCU\..\Run: [MyDailyHoroscope] C:\PROGRA~1\MYDAIL~1\MYDAIL~1.EXE
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - Startup: AdDestroyer.lnk = C:\Program Files\AdDestroyer\AdDestroyer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll

Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)

C:\PROGRAM FILES\Toolbar\
C:\PROGRAM FILES\COMMON FILES\WinTools\
C:\WINDOWS\System32\zlyydbtg.exe
C:\Program Files\TV Media\
C:\Program Files\SED\
C:\WINDOWS\conscorr.exe
C:\WINDOWS\bxxs5.dll
C:\PROGRAM FILES\MYDAILYHOROSCOPE\
C:\PROGRAM FILES\Web Offer\

Reboot your computer to go back to normal mode and post a new log.

#3 fegleyj

fegleyj
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:13 PM

Posted 09 September 2004 - 11:41 PM

I followed the step you gave me. As I was reading your solution, it was installing more spyware; ezula and something else. I did my best to remove those as well, but the one that seems to keep re-appearing is the "WinToolsA" thing. Anyway, I obviously have no idea what to do so here is the latest log:

Edited at 12:48am with new logfile after trying one more time to remove the "WintoolsA" entry, and restarting. Still seems to be pop-ups, but not as bad now


Logfile of HijackThis v1.98.2
Scan saved at 12:47:21 AM, on 9/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\System32\hpoipm07.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fark.com/
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.download.dir", "D:\\temp\\New Folder\\Creampie");
user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("dom.disable_open_during_load", true);
user_pref("intl.charsetmenu.browser.cache", "windows-1252, ISO-8859-1");
user_pref("network.cookie.prefsMigrated", true);
user_pref("prefs.converted-to-utf8", true);
user_pref("privacy.popups.first_popup", false);
user_pref("signon.Si
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1093608992453



*********************************
END LOG

How's it look now? I'm still having problems.

Edited by fegleyj, 09 September 2004 - 11:51 PM.


#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,503 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:13 PM

Posted 10 September 2004 - 08:09 AM

I actually do not see anything wrong here....

Please run two online virus scans:

http://housecall.antivirus.com/
http://www.pandasoftware.com/activescan/

Then let us know if its working better and what the scans found.

#5 fegleyj

fegleyj
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:13 PM

Posted 13 September 2004 - 09:33 PM

Sorry for the delay in my response. Have been busy. Here is the log file from one of the online virus scans. the other one didn't find anything. Also, I just realized that I am leaving out a vital part of the problem. The is an item in my Add/Remove programs list called "Ad Pop" which I assume is creating some of the pop-ups, if not all of them. It has no details of the program size or frequency of use like the other items, and everytime I click on "change/remove" it just blinks and is still there. I have searched google groups for possible answers, but due to the general nature of the search terms (ad, pop) I have found no other reports of this. Anyway, here is the log:


Incident Status Location

Virus:Trj/Downloader.GK No disinfected C:\Documents and Settings\Joseph\Local Settings\Temp\THI4686.tmp\polall1r.cab[polall1r.exe]
Virus:Trj/Downloader.GK No disinfected C:\Documents and Settings\Joseph\Local Settings\Temp\THI4F6E.tmp\polall1r.cab[polall1r.exe]
Please let me know if you know anythinbg about "Ad Pop", or how to remove these viruses. By the way, I am running Symantec Antivirus Corp. Edition ver. 8.1. How did I get these viruses? My software does not detect them, why is that? Is this program inadequate for virus protection?
Thanks.

Joe

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,503 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:13 PM

Posted 13 September 2004 - 09:41 PM

Download this file:

All3.zip - View Uninstall registry key

Extract it to c:\uninstall and then run the file found in the c:\uninstall folder. When it is done running it will open a notepad. Paste the contents of the notepad as a reply to this message

#7 fegleyj

fegleyj
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:13 PM

Posted 13 September 2004 - 11:36 PM

OK

**************************************8

3D Windows XP
3D Windows XP Screen Saver

rundll32.exe setupapi.dll,InstallHinfSection UninstallInstall 132 C:\WINDOWS\System32\3D Windows XP.inf
_______________________________
Ad Pop
Ad Pop

regsvr32 /u /s /c C:\WINDOWS\System32\adpop.dll
_______________________________
Ad-Aware SE Personal
Ad-Aware SE Personal

C:\PROGRA~1\Lavasoft\AD-AWA~2\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~2\INSTALL.LOG
_______________________________
ATI Display Driver
ATI Display Driver

rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
_______________________________
Azureus
Azureus

C:\Program Files\Azureus\Uninstall.exe
_______________________________
HijackThis
HijackThis 1.98.2

C:\HijackThis\HijackThis.exe /uninstall
_______________________________
hp officejet d series 1093564232
hp officejet d series

C:\WINDOWS\System32\hpocon09.exe /u 1093564232 /d "hp officejet d series"
_______________________________
ieupdate
Internet Explorer Q867801

C:\WINDOWS\ieuninst.exe C:\WINDOWS\INF\Q867801.inf
_______________________________
ImageDrive!UninstallKey
ImageDrive (Ahead Software)

C:\WINDOWS\UNIDRV.exe /UNINSTALL
_______________________________
KB810243
Windows XP Hotfix (SP2) [See KB810243 for more information]

no uninstaller
_______________________________
KB817778
Advanced Networking Pack for Windows XP

C:\WINDOWS\$NtUninstallKB817778$\spuninst\spuninst.exe
_______________________________
KB820291
Windows XP Hotfix - KB820291

C:\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.exe
_______________________________
KB821253
Windows XP Hotfix - KB821253

C:\WINDOWS\$NtUninstallKB821253$\spuninst\spuninst.exe
_______________________________
KB822603
Windows XP Hotfix - KB822603

C:\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.exe
_______________________________
KB823182
Windows XP Hotfix - KB823182

C:\WINDOWS\$NtUninstallKB823182$\spuninst\spuninst.exe
_______________________________
KB824105
Windows XP Hotfix - KB824105

C:\WINDOWS\$NtUninstallKB824105$\spuninst\spuninst.exe
_______________________________
KB824141
Windows XP Hotfix - KB824141

C:\WINDOWS\$NtUninstallKB824141$\spuninst\spuninst.exe
_______________________________
KB825119
Windows XP Hotfix - KB825119

C:\WINDOWS\$NtUninstallKB825119$\spuninst\spuninst.exe
_______________________________
KB826939
Windows XP Hotfix - KB826939

C:\WINDOWS\$NtUninstallKB826939$\spuninst\spuninst.exe
_______________________________
KB828035
Windows XP Hotfix - KB828035

C:\WINDOWS\$NtUninstallKB828035$\spuninst\spuninst.exe
_______________________________
KB828741
Windows XP Hotfix - KB828741

C:\WINDOWS\$NtUninstallKB828741$\spuninst\spuninst.exe
_______________________________
KB833407
Windows XP Hotfix - KB833407

C:\WINDOWS\$NtUninstallKB833407$\spuninst\spuninst.exe
_______________________________
KB835732
Windows XP Hotfix - KB835732

C:\WINDOWS\$NtUninstallKB835732$\spuninst\spuninst.exe
_______________________________
KB837001
Windows XP Hotfix - KB837001

C:\WINDOWS\$NtUninstallKB837001$\spuninst\spuninst.exe
_______________________________
KB839643
Windows XP Hotfix - KB839643

C:\WINDOWS\$NtUninstallKB839643$\spuninst\spuninst.exe
_______________________________
KB839645
Windows XP Hotfix - KB839645

C:\WINDOWS\$NtUninstallKB839645$\spuninst\spuninst.exe
_______________________________
KB840315
Windows XP Hotfix - KB840315

C:\WINDOWS\$NtUninstallKB840315$\spuninst\spuninst.exe
_______________________________
KB840374
Windows XP Hotfix - KB840374

C:\WINDOWS\$NtUninstallKB840374$\spuninst\spuninst.exe
_______________________________
KB841873
Windows XP Hotfix - KB841873

C:\WINDOWS\$NtUninstallKB841873$\spuninst\spuninst.exe
_______________________________
KB842773
Windows XP Hotfix - KB842773

C:\WINDOWS\$NtUninstallKB842773$\spuninst\spuninst.exe
_______________________________
KB870669
Microsoft Data Access Components KB870669

C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
_______________________________
LiveUpdate
LiveUpdate 1.80 (Symantec Corporation)

C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
_______________________________
Microsoft .NET Framework 1.1 (1033)
Microsoft .NET Framework 1.1

msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
_______________________________
Nero - Burning Rom!UninstallKey
Nero - Burning Rom (Web installer)

C:\WINDOWS\UNNERO.exe /UNINSTALL
_______________________________
Netscape (7.2)
Netscape (7.2)

C:\WINDOWS\NSUninst.exe /ua "7.2 (en)"
_______________________________
oeupdate
Outlook Express Q823353

C:\WINDOWS\oeuninst.exe C:\WINDOWS\INF\Q823353.inf
_______________________________
Q322011
Windows XP Hotfix (SP2) Q322011

C:\WINDOWS\$NtUninstallQ322011$\spuninst\spuninst.exe
_______________________________
Q327979
Windows XP Hotfix (SP2) Q327979

C:\WINDOWS\$NtUninstallQ327979$\spuninst\spuninst.exe
_______________________________
Q814995
Windows XP Hotfix (SP2) Q814995

C:\WINDOWS\$NtUninstallQ814995$\spuninst\spuninst.exe
_______________________________
Q819696
Windows XP Hotfix (SP2) Q819696

C:\WINDOWS\$NtUninstallQ819696$\spuninst\spuninst.exe
_______________________________
Q828026
Windows Media Player Hotfix [See Q828026 for more information]

C:\WINDOWS\$NtUninstallQ828026$\spuninst\spuninst.exe
_______________________________
QuickTime
QuickTime

C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
_______________________________
Spybot - Search & Destroy_is1
Spybot - Search & Destroy 1.3

"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
_______________________________
Tweak UI 2.10
Tweak UI

"C:\WINDOWS\System32\mshta.exe" "res://C:\WINDOWS\System32\TweakUI.exe/uninstall.hta"
_______________________________
Winamp
Winamp (remove only)

"C:\Program Files\Winamp\UninstWA.exe"
_______________________________
Windows Media Format Runtime
Windows Media Format Runtime

"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
_______________________________
Windows Media Player
Windows Media Player 10

"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
_______________________________
WinRAR archiver
WinRAR archiver

C:\Program Files\WinRAR\uninstall.exe
_______________________________
XviD MPEG4 Video Codec
XviD MPEG4 Video Codec (remove only)

"C:\WINDOWS\System32\xvid-uninstall.exe"
_______________________________
{01BDFB08-EE88-4E5E-94A6-AE9EDCFA40C5}
Microsoft IntelliPoint 4.0

no uninstaller
_______________________________
{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}
Symantec AntiVirus Client

MsiExec.exe /X{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}
_______________________________
{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}
WebFldrs XP

no uninstaller
_______________________________
{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}
Macromedia Flash MX

RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}\Setup.exe" -l0x9 UNINSTALL
_______________________________
{4D826618-59C6-11D4-976E-00C04F8EEB39}
Macromedia FreeHand 10

RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4D826618-59C6-11D4-976E-00C04F8EEB39}\Setup.exe" -l0x9 UNINSTALL
_______________________________
{7148F0A8-6813-11D6-A77B-00B0D0142050}
Java 2 Runtime Environment, SE v1.4.2_05

MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050}
_______________________________
{8B4AB829-DFD3-436D-B808-D9733D76C590}
Macromedia Dreamweaver MX

RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B4AB829-DFD3-436D-B808-D9733D76C590}\Setup.exe" -l0x9 mmUninstall
_______________________________
{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Edition 2003

MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
_______________________________
{90170409-6000-11D3-8CFE-0150048383C9}
Microsoft Office FrontPage 2003

MsiExec.exe /I{90170409-6000-11D3-8CFE-0150048383C9}
_______________________________
{930B2432-43D4-11D5-9871-00C04F8EEB39}
Macromedia Fireworks MX

RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{930B2432-43D4-11D5-9871-00C04F8EEB39}\Setup.exe" -l0x9 UNINSTALL
_______________________________
{A5BA14E0-7384-11D4-BAE7-00409631A2C8}
Macromedia Extension Manager

RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5BA14E0-7384-11D4-BAE7-00409631A2C8}\setup.exe" -l0x9 mmUninstall
_______________________________
{A7050037-F0EA-4BAB-BCD5-FC05507D6147}
Alt-Tab Task Switcher Powertoy for Windows XP

MsiExec.exe /I{A7050037-F0EA-4BAB-BCD5-FC05507D6147}
_______________________________
{B772E270-02DF-4B70-9FA8-1383BBB81FDD}
Intel® Processor Frequency ID Utility

MsiExec.exe /X{B772E270-02DF-4B70-9FA8-1383BBB81FDD}
_______________________________
{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1

MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
_______________________________
{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}
Microsoft Plus! for Windows XP

MsiExec.exe /I{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}
_______________________________
{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HighMAT Extension to Microsoft Windows XP CD Writing Wizard

MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
_______________________________
{FFFF6D5C-E2F1-4B40-BC89-8923312E89EB}}_is1
ACE Mega CoDecS Pack

"C:\Program Files\ACE Mega CoDecS Pack\unins000.exe"
_______________________________

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,503 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:13 PM

Posted 14 September 2004 - 03:12 PM

Can you see if :

C:\WINDOWS\System32\adpop.dll

Exists? If it does, zip it up and email it to grinler@yahoo.com

Then reboot into safe mode and delete it

#9 fegleyj

fegleyj
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:13 PM

Posted 14 September 2004 - 03:26 PM

Actually, the file did exist. I know because I previously searched my PC for any files containing "ad pop" and came up with one entry; adpop.dll Unfortunately, I immediately deleted the file. Although, I don't think I was in safe mode at the time, but I may have been... Anyway, the file is no longer there, but "Ad pop" is still present in my programs list. Did I mess up when I deleted that file. Any ideas on what to do next? Just so you know, I'm all backud up and ready to format if I must. I just hate to have to do that when the PC seems to be so close to being back to it's old self again. Thanks.

#10 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,503 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:13 PM

Posted 14 September 2004 - 06:07 PM

Yeah...if you want you can read this tutorial to remove that entry from your add/remove programs list:

How to Manually Remove Programs from the Add Remove Programs List

Other than that i dont see anything else wrong. Are you still having problems and if so what are they




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users