Explorer popup windows, often blank

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cpg_nq, Jul 18, 2006.

  1. cpg_nq

    cpg_nq Private E-2

    Please help with explorer popping up windows. I've been through the read & run me first steps. Attached log files. Had a bit of trouble with mcafee blocking the online bitdefender due to mcafee seeing buffer over flow. bitdefender listed two entries and cleaned on the first run through before it got blocked. These were both
    C:\Documents and Settings\All Users\Application Data\HeckAimRdrJump\16 Poll.exe
    Possibly a detect then clean/delete. As they weren't detected the second run through.

    Hijack log looks sad with so much being started on boot.
    I don't have an ipod so if you can also suggest how to not start the ipod services.

    Thanks
     

    Attached Files:

  2. cpg_nq

    cpg_nq Private E-2

    To Help solve this Windows XP SP2 internet Explorer problem I'm having I've add mcafee's logs of the buffer overflow blocking it did while running bitdefender.
     

    Attached Files:

  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  4. cpg_nq

    cpg_nq Private E-2

    Thankyou, so very much for your time.

    The steps were clear and easy to follow. That said, I hope I didn't miss any steps.

    So far so good. No popups yet.

    How does the Hijack log look now?

    regards
    cpg
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds