Okay, I'm not dumb when it comes to this stuff, but I have tried the following programs in removing the spyware from my computer, but I continuously get popups about once per minute, each from a bunch of different domains, but 70% end in 'yyy53.htm'. I also get flash popups that arnt in a browser window, just floating around.
The programs I've used are:
Ad Aware
Spy Sweeper S&D
Trend Micro Spy Sweeper
Microsoft AntiSpy Beta
CWShredder (continuouysly finds the same two stuff, but never removes all the way)
Kill2Me (But seems to fail since CWShreeder picks up this trace)
I've done some startups in safe mode and tried to do it that way too... but nothing.
It's corrupted BF2's punkbuster so I get the error "Inadequite OS Restrictions".
I attached the Hijack this log, but it's pretty clean, I'm at a loss, HELP WOULD BE GREATLY APPRECIATED!!!
EDIT:: Had problems attaching... I had to paste it (sorry)
EDIT::
COMMON POP UP ADDRESSES:
http://www.searc-h.com/normal/yyy53.html
http://www.super-coupon.com/normal/yyy53.html
http://www.great-coupon.com/normal/yyy53.html
http://www.deal-mobile.com/normal/yyy53.html
http://e.rn11.com/adbuys/a174-admed-ron
The programs I've used are:
Ad Aware
Spy Sweeper S&D
Trend Micro Spy Sweeper
Microsoft AntiSpy Beta
CWShredder (continuouysly finds the same two stuff, but never removes all the way)
Kill2Me (But seems to fail since CWShreeder picks up this trace)
I've done some startups in safe mode and tried to do it that way too... but nothing.
It's corrupted BF2's punkbuster so I get the error "Inadequite OS Restrictions".
I attached the Hijack this log, but it's pretty clean, I'm at a loss, HELP WOULD BE GREATLY APPRECIATED!!!
EDIT:: Had problems attaching... I had to paste it (sorry)
'Logfile of HijackThis v1.99.1
Scan saved at 3:05:10 AM, on 10/23/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Alex\My Documents\Spyware Removal\HijackThis.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O17 - HKLM\System\CCS\Services\Tcpip\..\{88F8D1BE-16AC-4AED-919E-5820FDAD8209}: NameServer = 64.233.207.2,192.168.0.200
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\r4p80e7ueh.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
EDIT::
COMMON POP UP ADDRESSES:
http://www.searc-h.com/normal/yyy53.html
http://www.super-coupon.com/normal/yyy53.html
http://www.great-coupon.com/normal/yyy53.html
http://www.deal-mobile.com/normal/yyy53.html
http://e.rn11.com/adbuys/a174-admed-ron