Strange IE window poping up.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Kraven, Oct 17, 2004.

  1. Kraven

    Kraven Private E-2

    I have an Internet explorer window that keeps poping up out of nowhere and the only thing in the page is a message that is a little different each time. Examples :

    sendExternalEvent('EVENT:IEBROWSER:trk.bestmagsdirect.com/a/44/e/84/m/Contextual-RON/');

    sendExternalEvent('EVENT:IEBROWSER:69.20.56.3/normal/yyy12.html');

    It comes from a site called ad-w-a-r-e.com and is from a different spot on the site each time. Examples :

    http://www.ad-w-a-r-e.com/cgi-bin/PopupV2?ID={D9D6B70E-53F7-44BD-9C8A-625A091D7C9F}&AD=Revenue

    http://www.ad-w-a-r-e.com/cgi-bin/PopupV2?ID={D9D6B70E-53F7-44BD-9C8A-625A091D7C9F}&AD=Freeze

    It appears to be sending out different info each time and every time it does it downloads more spyware to my computer. I have ran the following programs in attempt to get rid of it. I ran these in safe mode as well and with my system restore turned off.
    Before I ran my Nortons a 2nd time I went to Trend Micro's Free Online Virus Scan. Then in safe mode I ran my Norton antivirus, then I uninstalled it and installed avast antivirus and ran it. I ran McAfee AVERT Stinger. Then I manually removed my temporary internet files then ran CCleaner. I ran Ad-aware SE with the VX2 cleaner plugin. I ran spybot and CWshredder. I ran Kill2me. I also ran HijackThis!
    When I run these programs it comes up witht bargain buddy and all that stuff and then I run the ad-aware and spybot a second time and they are all gone but then this silly page pops up again and all of a sudden I have several instances of spyware on my PC.
    So far nothing has gotten rid of this problem and now I have a 2nd Internet explorer window that pops up with my homepage and it is www.spotresults.com.
    I am at my wit's end on this one. Anyone have any suggestions.

    Thank You,

    Kraven
     
  2. jarcher

    jarcher I can't handle a title

  3. Kraven

    Kraven Private E-2

    Yes, I have ran everything in your tutorial. Here is my hijackthis logfile.

    Logfile of HijackThis v1.97.7
    Scan saved at 7:23:26 PM, on 10/17/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Jamie\Desktop\spyware tools\hjt\HijackThis.exe

    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1098050887703
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  4. jarcher

    jarcher I can't handle a title

    Have you?
    your version of HJT is not up to date, get that here:
    http://majorgeeks.com/download3155.html

    and save it to
    C:\Program Files\HJt\

    and rerun HJT and post it as an attachment as a .txt file
    if you cannot find how to do that here:

    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    just ask. . . . your log is attached
     

    Attached Files:

  5. Kraven

    Kraven Private E-2

    Here it is.
     

    Attached Files:

  6. jarcher

    jarcher I can't handle a title

    please move HJT from
    C:\Documents and Settings\Jamie\Desktop\spyware tools\hjt\HijackThis.exe

    to

    C:\Program Files\hjt\HijackThis.exe
    close all browser windows (including this one)
    re-run and
    and re-post

    thank you

    but from what you do have your hjt looks clean
    what exactly is the problem?
     
  7. jarcher

    jarcher I can't handle a title


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds