LPS500
29th Sep 2004, 21:07
Hi guys, hope you can help on this one........
Was visiting a flight sim website tonight and clicking on one of the icons on the site led to lots of pop up boxes and a shut down by the pc. Upon trying to restart the pc would get to the XP screeen where I click on my profile and enter the administrator password, but after entering said password it will restart shortly after saying 'loadind personal settings'. I've tried a repair and reload from my OEM disc but same same. With the repair though it says I've entered the wrong administrator password, which I haven't (after 6 attempts I'm sure). I'm now logged in on my flatmates profile that seems to work fine. I've scanned for adware using McAfee internet security suite, but nothing. The funny thing is I'm getting all sorts of pop ups when logged in, mostly about 'your pc is not secure' and dixons has somehow made itself my home page? Even my pprune password had to be reset before I could log in. I've run the hijackthis program and results are below. Can anyone help, please? Please tolerate my removal of the wiggly red faces when posting the log file. Thanks. LPS
Logfile of HijackThis v1.98.2
Scan saved at 21:42:27, on 29/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C: \WINDOWS\system32\rundll32.exe
C: \WINDOWS\Explorer.EXE
C: \Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C: \WINDOWS\Dit.exe
C: \WINDOWS\DitExp.exe
C: \WINDOWS\mHotkey.exe
C: \WINDOWS\System32\RunDll32.exe
C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
C: \Program Files\Logitech\Video\LogiTray.exe
C: \Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C: \Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C: \PROGRA~1\mcafee.com\agent\mcagent.exe
C: \Program Files\Logitech\MouseWare\system\em_exec.exe
C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C: \PROGRA~1\mcafee.com\vso\mcvsshld.exe
c: \progra~1\mcafee.com\vso\mcvsescn.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C: \Program Files\iTunes\iTunesHelper.exe
C: \Program Files\QuickTime\qttask.exe
C: \PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\knlwrap.exe
C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
C: \PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C: \WINDOWS\System32\ctfmon.exe
C: \WINDOWS\System32\LVComS.exe
C: \Program Files\Yahoo!\Messenger\ypager.exe
C: \Program Files\Logitech\Video\LowLight.exe
C: \Program Files\BTopenworld NetHelp\bin\mpbtn.exe
c: \progra~1\mcafee.com\vso\mcvsftsn.exe
C: \Program Files\Messenger\msmsgs.exe
C: \PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe
C: \PROGRA~1\Yahoo!\browser\ycommon.exe
C: \Program Files\Yahoo!\browser\ybrwicon.exe
C: \PROGRA~1\McAfee.com\Agent\mcupdui.exe
C: \Program Files\Internet Explorer\IEXPLORE.EXE
C: \Documents and Settings\Julia\My Documents\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http: //uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http: //uk.docs.yahoo.com/info/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http: //uk.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http: //www.dixons.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http: //uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http: //uk.docs.yahoo.com/info/bt_side.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.zestyfind.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http: //www.dixons.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c: \progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c: \program files\google\googletoolbar1.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C: \Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C: \WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C: \WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCMService] "C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C: \Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C: \Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C: \Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C: \Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C: \Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C: \Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c: \PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C: \PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c: \PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [VirusScan Online] "c: \PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C: \PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] C: \Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C: \Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C: \WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C: \WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CleanUp] C: \PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon
O4 - HKLM\..\Run: [DXDllRegExe] C: \WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C: \WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C: \Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Logitech Desktop Messenger.lnk = C: \Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C: \Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NetHelp.lnk = C: \Program Files\BTopenworld NetHelp\bin\matcli.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: BT Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra 'Tools' menuitem: BT &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \WINDOWS\web\related.htm
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C: \Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C: \Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C: \Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.zestyfind.com/app/DS4/DS4.cab
In case it helps a lot of pop ups are coming from this site:
http://e.rnll.com/a/a174-amed-ron
Thanks once again.
Was visiting a flight sim website tonight and clicking on one of the icons on the site led to lots of pop up boxes and a shut down by the pc. Upon trying to restart the pc would get to the XP screeen where I click on my profile and enter the administrator password, but after entering said password it will restart shortly after saying 'loadind personal settings'. I've tried a repair and reload from my OEM disc but same same. With the repair though it says I've entered the wrong administrator password, which I haven't (after 6 attempts I'm sure). I'm now logged in on my flatmates profile that seems to work fine. I've scanned for adware using McAfee internet security suite, but nothing. The funny thing is I'm getting all sorts of pop ups when logged in, mostly about 'your pc is not secure' and dixons has somehow made itself my home page? Even my pprune password had to be reset before I could log in. I've run the hijackthis program and results are below. Can anyone help, please? Please tolerate my removal of the wiggly red faces when posting the log file. Thanks. LPS
Logfile of HijackThis v1.98.2
Scan saved at 21:42:27, on 29/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C: \WINDOWS\system32\rundll32.exe
C: \WINDOWS\Explorer.EXE
C: \Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C: \WINDOWS\Dit.exe
C: \WINDOWS\DitExp.exe
C: \WINDOWS\mHotkey.exe
C: \WINDOWS\System32\RunDll32.exe
C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
C: \Program Files\Logitech\Video\LogiTray.exe
C: \Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C: \Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C: \PROGRA~1\mcafee.com\agent\mcagent.exe
C: \Program Files\Logitech\MouseWare\system\em_exec.exe
C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C: \PROGRA~1\mcafee.com\vso\mcvsshld.exe
c: \progra~1\mcafee.com\vso\mcvsescn.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C: \Program Files\iTunes\iTunesHelper.exe
C: \Program Files\QuickTime\qttask.exe
C: \PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\knlwrap.exe
C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
C: \PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C: \WINDOWS\System32\ctfmon.exe
C: \WINDOWS\System32\LVComS.exe
C: \Program Files\Yahoo!\Messenger\ypager.exe
C: \Program Files\Logitech\Video\LowLight.exe
C: \Program Files\BTopenworld NetHelp\bin\mpbtn.exe
c: \progra~1\mcafee.com\vso\mcvsftsn.exe
C: \Program Files\Messenger\msmsgs.exe
C: \PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe
C: \PROGRA~1\Yahoo!\browser\ycommon.exe
C: \Program Files\Yahoo!\browser\ybrwicon.exe
C: \PROGRA~1\McAfee.com\Agent\mcupdui.exe
C: \Program Files\Internet Explorer\IEXPLORE.EXE
C: \Documents and Settings\Julia\My Documents\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http: //uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http: //uk.docs.yahoo.com/info/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http: //uk.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http: //www.dixons.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http: //uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http: //uk.docs.yahoo.com/info/bt_side.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.zestyfind.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http: //www.dixons.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c: \progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c: \program files\google\googletoolbar1.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C: \Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C: \WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C: \WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCMService] "C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C: \Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C: \Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C: \Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C: \Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C: \Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C: \Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c: \PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C: \PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c: \PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [VirusScan Online] "c: \PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C: \PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] C: \Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C: \Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C: \WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C: \WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CleanUp] C: \PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon
O4 - HKLM\..\Run: [DXDllRegExe] C: \WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C: \WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C: \Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Logitech Desktop Messenger.lnk = C: \Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C: \Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NetHelp.lnk = C: \Program Files\BTopenworld NetHelp\bin\matcli.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: BT Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra 'Tools' menuitem: BT &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \WINDOWS\web\related.htm
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C: \Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C: \Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C: \Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.zestyfind.com/app/DS4/DS4.cab
In case it helps a lot of pop ups are coming from this site:
http://e.rnll.com/a/a174-amed-ron
Thanks once again.