TechSpot

Random IE Popups, Getting a TON of popups all the time

By taudelt39
Feb 1, 2005
Topic Status:
Not open for further replies.
  1. I have no idea how this happened (probably from just normal surfing) but I am getting random IE popups and I can't seem to fix it. i have run SpyBot 1.4 (Latest version and definitions) and Ad-Aware SE 1.05 (Latest Version and definitions) and I can't seem to get rid of them.

    I have posted my HijackThis Log in an attachment since it wouldn't allow me to upload URL links. PLEEEEEEEEEASE help me! Thanks.
    Darren

    Attached Files:

  2. RealBlackStuff

    RealBlackStuff TS Rookie Posts: 8,165

    Go to this post here first, and follow the instructions EXACTLY.
    How to remove Begin2Search / Coolwebsearch

    Boot into Safe Mode.

    Uninstall DAP, it is riddled with ads.

    Unless you know what these are good for, uninstall them as well:
    C:\Program Files\Rational\ClearCase\bin\albd_server.exe
    C:\Program Files\Kana WallChanger\KanaWall.exe

    While still in Safe Mode, run HJT standalone and let it 'fix' (if still there):

    C:\Program Files\Rational\ClearCase\bin\albd_server.exe
    C:\Program Files\Rational\ClearCase\bin\lockmgr.exe
    C:\Program Files\Rational\ClearCase\bin\cccredmgr.exe
    C:\PROGRA~1\DAP\DAP.EXE
    C:\Program Files\Kana WallChanger\KanaWall.exe
    C:\WINNT\system32\w?aclt.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = helpnow.cendant.com;
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {98274D33-A6F0-8700-D348-8D4DF6D12FB7} - C:\WINNT\system32\ottus.dll
    O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
    O4 - HKLM\..\Run: [CCDoctorLogonTesting] "C:\Program Files\Rational\ClearCase\bin\ccdoctor.exe" /LogonStartup
    O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
    O4 - HKCU\..\Run: [Kana WallChanger] "C:\Program Files\Kana WallChanger\KanaWall.exe"
    O4 - HKCU\..\Run: [Hck] C:\WINNT\system32\w?aclt.exe
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {332bd5a0-8000-11d7-b657-00c04faedb18} (Oracle JInitiator 1.1.8.22) -
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://us6.webex.com/client/v_mywebex/webex/ieatgpc.cab
    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.streamload.com/Upload/XUpload.ocx
    O23 - Service: Atria Location Broker - Unknown - C:\Program Files\Rational\ClearCase\bin\albd_server.exe
    O23 - Service: Atria Cred Manager - Unknown - C:\Program Files\Rational\ClearCase\bin\cccredmgr.exe
    O23 - Service: Atria Lock Manager - Unknown - C:\Program Files\Rational\ClearCase\bin\lockmgr.exe

    When done, delete the bold files. When a directory is also bold, delete everything in it, including that directory itself.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.