Hi, I'm using Win2K and incessant popups are driving me insane. I'm having a really hard time getting anything done. I am running ad-aware scans every 10 minutes, spybot, ms adware utility, you name it. I'm growing despondent.
Logfile of HijackThis v1.99.1 Scan saved at 10:50:55 AM, on 5/25/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\\WINNT\\System32\\smss.exe C:\\WINNT\\system32\\winlogon.exe C:\\WINNT\\system32\\services.exe C:\\WINNT\\system32\\lsass.exe C:\\WINNT\\system32\\svchost.exe C:\\WINNT\\system32\\spoolsv.exe C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\DefWatch.exe C:\\WINNT\\System32\\svchost.exe C:\\WINNT\\System32\\mnmsrvc.exe C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\Rtvscan.exe C:\\WINNT\\system32\\regsvc.exe C:\\WINNT\\system32\\MSTask.exe C:\\WINNT\\System32\\WBEM\\WinMgmt.exe C:\\WINNT\\system32\\mspmspsv.exe C:\\WINNT\\system32\\svchost.exe C:\\WINNT\\Explorer.EXE C:\\WINNT\\system32\\hkcmd.exe C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\vptray.exe C:\\Program Files\\QuickTime\\qttask.exe C:\\Program Files\\Glance\\Glance.exe C:\\Program Files\\PKWARE\\PKZIPO\\PKTray.exe C:\\Program Files\\Mozilla Firefox\\firefox.exe C:\\WINNT\\System32\\SCardSvr.exe C:\\Program Files\\Citrix\\ICA Client\\wfica32.exe C:\\Program Files\\Lavasoft\\Ad-Aware SE Personal\\Ad-Aware.exe C:\\PROGRA~1\\PKWARE\\PKZIPW4\\pkzipw.exe C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\HijackThis.exe
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =
- (no file) R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2}
- (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\\program files\\google\\googletoolbar1.dll O4 - HKLM\\..\\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\\..\\Run: [IgfxTray] C:\\WINNT\\system32\\igfxtray.exe O4 - HKLM\\..\\Run: [HotKeysCmds] C:\\WINNT\\system32\\hkcmd.exe O4 - HKLM\\..\\Run: [vptray] C:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus\\vptray.exe O4 - HKLM\\..\\Run: [gkrAK] C:\\documents and settings\\administrator\\local settings\\temp\\gkrAK.exe O4 - HKLM\\..\\Run: [picsvr] C:\\WINNT\\system32\\picsvr\\picsvr.exe O4 - HKLM\\..\\Run: [SunJavaUpdateSched] C:\\Program Files\\Java\\jre1.5.0_02\\bin\\jusched.exe O4 - HKLM\\..\\Run: [QuickTime Task] "C:\\Program Files\\QuickTime\\qttask.exe" -atboottime O4 - HKLM\\..\\Run: [tsvcin] C:\\WINNT\\system32\\n20050308.EXE O4 - HKLM\\..\\Run: [gcasServ] "C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe" O4 - HKLM\\..\\Run: [Nsv] C:\\WINNT\\system32\\nsvsvc\\nsvsvc.exe O4 - HKLM\\..\\Run: [KavSvc] C:\\WINNT\\system32\\unrank.exe reg_run O4 - HKLM\\..\\Run: [checkrun] C:\\winnt\\system32\\elitenic32.exe O4 - HKCU\\..\\Run: [Ehwuz] C:\\WINNT\\system32\\r?ndll32.exe O4 - HKCU\\..\\Run: [JBsqRUN8S] rsfxdo.exe O4 - HKCU\\..\\Run: [Lcbt] C:\\Documents and Settings\\Administrator\\Application Data\\ewah.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe O4 - Global Startup: Glance.lnk = C:\\Program Files\\Glance\\Glance.exe O4 - Global Startup: Microsoft Office.lnk = C:\\Program Files\\Microsoft Office\\Office\\OSA9.EXE O4 - Global Startup: PKZIP Attachments Status.lnk = C:\\Program Files\\PKWARE\\PKZIPO\\PKTray.exe O4 - Global Startup: rtdc.exe O8 - Extra context menu item: &Google Search - res://C:\\Program Files\\Google\\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\\Program Files\\Google\\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\\Program Files\\Google\\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\\Program Files\\Google\\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\\Program Files\\Google\\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\\Program Files\\Google\\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre1.5.0_02\\bin\\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre1.5.0_02\\bin\\npjpi150_02.dll O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\\Program Files\\Ebates_MoeMoneyMaker\\Sy350\\Tp350\\scri350a.htm (file missing) (HKCU) O10 - Unknown file in Winsock LSP: c:\\winnt\\system32\\dolsp.dll O10 - Unknown file in Winsock LSP: c:\\winnt\\system32\\dolsp.dll O10 - Unknown file in Winsock LSP: c:\\winnt\\system32\\dolsp.dll O10 - Unknown file in Winsock LSP: c:\\winnt\\system32\\dolsp.dll O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) -