Popup problems with IE

Status
Not open for further replies.

dodger

Beta member
Messages
2
Hi,

I've managed to wean myself off of IE - I now use Firefox - but apparently there are a few buggers still in residence as I get multiple popups at different times of the day - out of nowhere seemingly. These uninvited popups all have the IE title bar - even tho I've used Firefox for a couple of weeks now.

I've run adaware and SpyBot and cleaned out as far as what they found...

I ran Hi Jack this as per other posts on the same subject. I'm printing the log here. Would one of you please take a look and see what you think? I would really appreciate it. :)

=======================================
Logfile of HijackThis v1.97.7
Scan saved at 10:16:29 AM, on 7/13/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\documents and settings\kdok\local settings\temp\k9hRv7j.exe
C:\documents and settings\kdok\local settings\temp\k9hRv7j.exe
C:\WINNT\system32\athnlet.exe
C:\WINNT\system32\inrnrw.exe
C:\WINNT\system32\Kkyqfy.exe
C:\WINNT\system32\MtyJ6.exe
A:\HijackThis-1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kdok.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {00000EF1-0786-4633-87C6-1AA7A44296DA} - C:\WINNT\system32\ATPART~1.DLL
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [k9hRv7j.exe] C:\documents and settings\kdok\local settings\temp\k9hRv7j.exe
O4 - HKLM\..\Run: [2MB4@674LD9MH@] C:\WINNT\system32\CpbFG.exe
O4 - HKLM\..\Run: [374P3EP] indava.exe
O4 - HKLM\..\Run: [k9hRv7j] C:\documents and settings\kdok\local settings\temp\k9hRv7j.exe
O4 - HKLM\..\Run: [qasmwrw] C:\WINNT\system32\athnlet.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [alchem] C:\WINNT\alchem.exe
O4 - HKLM\..\Run: [inrnrw] C:\WINNT\system32\inrnrw.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38029.1129166667
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Dodger
 
I believe this is related to Windows messenger. Not to be confused with messenger. It needs to be disabeled. I had the same prob a few years ago, disabeling fixed the prob. Scuzzbzll advertisers figured out a way to use the windows messenger to feed you there garbage. Do a search on windows messenger and you can probally figure out how to diable. Sorry I disabeled and forgot...lol
 
Thanks - I'll check into that. :)

Does anyone else see anything in there that needs to be removed, please?

Thanks
Dodger
 
Hi dodger

looks like you have some infections

Run an online antivirus check from at least one and preferably 2 of the following sites....select autoclean click below

Housecall
Panda scan
RAV


Lobos

post another log afterwards
 
Status
Not open for further replies.
Back
Top Bottom