1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

HELP with pop ups after closing IE

Discussion in 'Malware and Virus Removal Archive' started by Topnotch, 2004/04/02.

Thread Status:
Not open for further replies.
  1. 2004/04/02
    Topnotch

    Topnotch Well-Known Member Thread Starter

    Joined:
    2003/12/27
    Messages:
    92
    Likes Received:
    0
    I need some help... just recently I must have picked up some "pop up" program off the web and now whenever I close out of Internet Explorer, pop ups start popping up!! I do have a pop up blocker as part of my Earthlink account. I have ran the most recent adware and also the most recent Nortons virus. Adware did find about a dozen things that I had it fix, but the pop ups still come up after closing IE. Any suggestions??/


    Thanks a lot!!

    I am running Windows 98
    Internet Explorer 5.5
     
  2. 2004/04/02
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Hi Topnotch - Welcome to the Board :)

    Suggest you run Spybot as well - see my signature for link. Be sure to update the reference files of Ad-aware and Spybot before running them - they are updated frequently.

    If this fails to cure the problem download and run HijackThis and post the log here. Do not attempt to fix anything yourself! Let the experts look over it first.
     

  3. to hide this advert.

  4. 2004/04/02
    Topnotch

    Topnotch Well-Known Member Thread Starter

    Joined:
    2003/12/27
    Messages:
    92
    Likes Received:
    0
    Thanks Pete

    Thanks for the response Pete and the welcoming. It has been a couple of years since I have posted here, I have to admit all you guys are great!

    I forgot to mention that I did also run Spybot and it found a few things also, but still have the same problem. I did like you said and downloaded Hijack and ran it, here is the results...... I sure am glad you can make since out of all this, I don't have a clue..


    Logfile of HijackThis v1.97.7
    Scan saved at 12:03:53 PM, on 4/2/04
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\STARTER.EXE
    C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
    C:\PROGRAM FILES\COMMON FILES\SHUTTLE TECHNOLOGY\ICONFIG.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\COMMON FILES\ADAPTEC SHARED\CREATECD\CREATECD50.EXE
    C:\PROGRAM FILES\EARTHLINK TOTALACCESS\TASKPANL.EXE
    C:\PROGRAM FILES\DIAMOND\INCONTROL TOOLS 98\DMHKEY.EXE
    C:\PROGRAM FILES\MSAC-FD1\MSSTAT.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\SYSTEM\SENCODEM.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\COMMON FILES\UPDATER\WUPDATER.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\PROGRAM FILES\INSTANT MESSENGER\AIM.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
    F1 - win.ini: run=hpfsched
    O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
    O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
    O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - (no file)
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [ICONFIG.EXE] C:\PROGRA~1\COMMON~1\SHUTTL~1\ICONFIG.EXE "Software\Shuttle Technology\07810005 "
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\BXXS5.DLL,DllRun
    O4 - HKLM\..\Run: [yjav] C:\WINDOWS\yjav.exe
    O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CREATECD\CREATE~1.EXE -r
    O4 - HKLM\..\Run: [SENCODEM] C:\WINDOWS\SYSTEM\SENCODEM.exe
    O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKCU\..\Run: [E6TaskPanel] "C:\PROGRAM FILES\EARTHLINK TOTALACCESS\TASKPANL.EXE" -winstart
    O4 - Startup: InControl Desktop Manager.lnk = C:\Program Files\Diamond\InControl Tools 98\DMHKEY.EXE
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: Memory Stick Monitor.lnk = C:\Program Files\MSAC-FD1\MSstat.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: Instant Messenger (SM) (HKLM)
    O9 - Extra button: Yahoo! Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
    O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell.com/us/en/systemprofiler/SysProfLCD.CAB
    O16 - DPF: {DD3641E5-A9CF-11D1-9AA1-444553540000} (Surround Video V3.0 Control Object) - http://www.sunterra.com/downloads/svh/svideo3.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} (WONWebLauncher Class) - http://hoylegames.sierra.com/cab/WONWebLauncherControl.cab
     
  5. 2004/04/02
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Topnotch - I'm no expert on these logs either :D - but I know where there are a few!

    Moving this thread to Security/Virus/Spyware
     
  6. 2004/04/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi Topnotch. :)

    Please download, install and immediately update Ad-aware. Configure as such;

    From main window :Click "Start" then " Activate in-depth scan "
    Then......
    Click "Use custom scanning options>Customize" and have these options on: "Scan within archives" , "Scan active processes ", "Scan registry ", "Deep scan registry" , "Scan my IE Favorites for banned URL" and "Scan my host-files "
    Then.....
    Go to Tweak>Scanning engine and tick "Unload recognized processes during scanning" ...........then........ "Cleaning engine" and tick "Let windows remove files in use at next reboot "

    Then...... click "proceed" to save your settings.
    Run Adaware, delete all it finds.
    Also visit Doxdesk. Follow any instructions given to remove parasites if found.
    Reboot and run another HJT scan and post log.
     
  7. 2004/04/02
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Thanks, Dave - had a feeling you would be around!
     
  8. 2004/04/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You bet! :D

    I'll be gone for a few hours. Check in when I get back.
     
  9. 2004/04/02
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Me too - past midnight in UK :)
     
  10. 2004/04/02
    Topnotch

    Topnotch Well-Known Member Thread Starter

    Joined:
    2003/12/27
    Messages:
    92
    Likes Received:
    0
    Dave & Pete,

    I want to say a very BIG thank you to both of you!!! The suggestion you gave me Dave did the trick! It is funny though, I did almost everyting you mentioned earlier except for tweaking the custom settings on the Adware, that must have been the trick.

    Thanks Pete for stearing me in the right direction!!

    I am so glad that there is a website like this out there where good people are out to help others!!

    Thanks again you two!!

    Andy
     
  11. 2004/04/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Topnotch,

    I'm glad the tweaking did the trick, but I would like to apologize for telling you to d/l and run Ad-aware when you stated in your first post you had already run it. I first saw your post in the IE section and marked it read. I came back later, after it was moved, and read only new posts, forgetting you had run it already. I should have instead suggested you check the version and make sure you are using the latest build. It is 6.181, and it's important not to use older versions with newer reference files. That said, did Doxdesk find anything? Your HJT log had quite a bit of junk in it that neither Ad-aware, Spybot or Doxdesk would fix and I do recommend you post another log so we can finish the cleanup. I just kinda don't feel right getting the task half done. :D If you decide to, also let me know if you use Earthlink for your homepage and search.
     
  12. 2004/04/02
    Topnotch

    Topnotch Well-Known Member Thread Starter

    Joined:
    2003/12/27
    Messages:
    92
    Likes Received:
    0
    Hey Dave,

    I did go to Doxdesk and it found no parasites. I then scanned another HJT log and here it is......... By the way, yes I do use Earthlink as my homepage and search. Thanks again for all the help, I really do appreciate it!!



    Logfile of HijackThis v1.97.7
    Scan saved at 9:03:23 PM, on 4/2/04
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\STARTER.EXE
    C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
    C:\PROGRAM FILES\COMMON FILES\SHUTTLE TECHNOLOGY\ICONFIG.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\COMMON FILES\ADAPTEC SHARED\CREATECD\CREATECD50.EXE
    C:\PROGRAM FILES\EARTHLINK TOTALACCESS\SPYWARE BLOCKER\SPYWAREBLOCKER.EXE
    C:\PROGRAM FILES\EARTHLINK TOTALACCESS\TASKPANL.EXE
    C:\PROGRAM FILES\DIAMOND\INCONTROL TOOLS 98\DMHKEY.EXE
    C:\PROGRAM FILES\MSAC-FD1\MSSTAT.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OUTLOOK.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    F1 - win.ini: run=hpfsched
    O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [ICONFIG.EXE] C:\PROGRA~1\COMMON~1\SHUTTL~1\ICONFIG.EXE "Software\Shuttle Technology\07810005 "
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [yjav] C:\WINDOWS\yjav.exe
    O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CREATECD\CREATE~1.EXE -r
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\EarthLink TotalAccess\Spyware Blocker\SPYWAREBLOCKER.EXE" /0
    O4 - HKCU\..\Run: [E6TaskPanel] "C:\PROGRAM FILES\EARTHLINK TOTALACCESS\TASKPANL.EXE" -winstart
    O4 - Startup: InControl Desktop Manager.lnk = C:\Program Files\Diamond\InControl Tools 98\DMHKEY.EXE
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: Memory Stick Monitor.lnk = C:\Program Files\MSAC-FD1\MSstat.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: Instant Messenger (SM) (HKLM)
    O9 - Extra button: Yahoo! Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
    O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell.com/us/en/systemprofiler/SysProfLCD.CAB
    O16 - DPF: {DD3641E5-A9CF-11D1-9AA1-444553540000} (Surround Video V3.0 Control Object) - http://www.sunterra.com/downloads/svh/svideo3.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} (WONWebLauncher Class) - http://hoylegames.sierra.com/cab/WONWebLauncherControl.cab
     
  13. 2004/04/03
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    belgiandip.com Popups = winpup

    and Adaware will now fix it (I think, looks as if it has)but you might want to do some extra cleanup also.But first.

    Are your search's being redirected ?
    Misspell something in IE's address-bar and try , what happens?
    this line might indicate a coolweb infection
    > R1------Search Bar = about :blank

    Make a new folder within the my documents folder and put hijackthis.exe there., and if you've fixed anything put the backups there also.

    Also if you have been troubleshooting and have disabled anything in msconfig since you started having problems
    recheck then and restart the PC come back and post another log.
    and disregard the instructions below for now.

    Start Hijackthis and place a check next to these items
    Close all browser windows and shut down all other programs(even folders) that show in the task-bar. Then Hit fix selected
    [items in blue are recommended or optional]

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about :blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about :blank


    O4 - HKLM\..\Run: [yjav] C:\WINDOWS\yjav.exe before fixing check the file properties of this file,I see no info on it, that in itself is a bad indication

    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


    O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} (WONWebLauncher Class) - http://hoylegames.sierra.com/cab/WO...cherControl.cab
    Looks like a lagit game but the same csdl is used by some bad guys,fix it. Sierra should have known better.

    Reboot <<<<

    C:\Program Files\Common files\updater<< delete that folder if still present
    If you dont already in folder options have windows show all hidden files and folders.

    C:\WINDOWS\SYSTEM open the system folder
    (system32 on XP systems)
    Be very CAREFULL please.
    check the properties of them to be sure, they will be 2-8 <random> characters named files
    right click on the file in the context menu choose properties then version tab
    Highlight > "Internal Name" if it says > pupdate.exe ,werule or winpup,
    Then its safe to delete them.

    Some examples(but you still have to check the properties!) are

    Dont confuse it with WINPOPUP.EXE which is a windows file
    Winpup32.exe, winupie.exe, pup.exe, OVER.EXE ,winpup.exe , ogonl.exe, daplginb.exe
    SENCODEM.exe pup.exe XPANDE.exe

    According to kephyr's corner website
    telnat.exe, comms.exe, ogonl.exe, erflib_Perfdata_1c4P.exe, idimapm.exe, sign32i.exe, _874c.exe, fffilto.exe, axdrvf.exe, svpcntsr.exe, iprt400o.exe, ppmgmta.exe, jl11i.exe, insw.exe, p2ress.exe, tl3d32c.exe, NWISEU.exe, etshn.exe, snppagnp.exe, vicap32a.exe, _1252c.exe, ceclis.exe, dsmsexta.exe, inw.exe, skquouid.exe, skquotad.exe, erberosk.exe, ERNEL32K.exe, uaucltw.exe, sbmonu.exe, RLMONU.exe, rlu.exe, ingp.exe, etn.exe, arrhookn.exe, BTSTATN.exe, xpande.exe, axqueuef.exe, AXSVCF.exe, ingerf.exe, GI32G.exe, etc
    ==============
    If you've installed "Free History Cleaner" winpup probably came with it, or perhaps some other supposedly free program.

    also if your comfortable working with regedit take a look here and see if these keys exist

    [-HKEY_LOCAL_MACHINE\Software\pup]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\comms]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\pup]
     
  14. 2004/04/03
    Topnotch

    Topnotch Well-Known Member Thread Starter

    Joined:
    2003/12/27
    Messages:
    92
    Likes Received:
    0
    Thanks Lonny

    You are right, it was Belgiandip.com pop ups that I was having the problem with. I did everything you suggested in your post and everything seems to be working just fine.......THANK YOU!!

    By the way, I did get rid of the yjav.exe part, I could not find the program anywhere, so I went ahead and put a check mark in that box also.

    Thanks again for all your help, it is so nice to have a place such as this that you can turn to for help and advice.

    Take care,
    Andy
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.