1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Two instances of IE that won't close

Discussion in 'Malware and Virus Removal Archive' started by shadowhawk, 2004/09/29.

Thread Status:
Not open for further replies.
  1. 2004/09/29
    shadowhawk

    shadowhawk Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    985
    Likes Received:
    0
    Yesterday I stupidly visited a site with Internet Explorer that wouldn't work in Firefox. This morning I realized I'd been zapped with spyware. I ran the usual scans, which found CoolWWWSearch and Lop. I was pretty sure I'd gotten rid of CoolWWWSearch til I went back into IE and realized it had the CoolWWWSearch bar and the start page had been hijacked. Some of Firefox's settings had been altered too, but were easily changed back.

    I disabled the search bar in IE, and it made me type in a number to do, to be sure I wasn't a bot...

    I downloaded CWShredder and scanned with it. All it found was a little search component, which it got rid of. However when I looked in EndItAll, I saw two instances of IE, one that had Search off to the right of it.

    I ran HijackThis and got rid of anything questionable I found.

    I think I have CoolWWWSearch off my system, but I can't get rid of those two instances of IE.

    Ah I just realized this probably belongs in the security forum. Feel free to move it. Any help appreciated.
     
    Last edited: 2004/09/29
  2. 2004/09/29
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0

  3. to hide this advert.

  4. 2004/09/29
    shadowhawk

    shadowhawk Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    985
    Likes Received:
    0
    I ran Adaware SE again, this time full scan and it found Lop. It had to reboot to get it off. It must've been Lop doing it.
     
  5. 2004/09/29
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    shadowhawk--I understand that things are back to being OK. Great!!
    I have seen that often multiple scans with AdAware or SpybotS&D are a good idea.
    You may want to delete previous System Restore points, since they might reintroduce the same problems.
     
  6. 2004/09/29
    BillyBob Lifetime Subscription

    BillyBob Inactive

    Joined:
    2002/01/07
    Messages:
    6,048
    Likes Received:
    0
    VERY, VERY good sugestion.

    BillyBob
     
  7. 2004/09/29
    shadowhawk

    shadowhawk Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    985
    Likes Received:
    0
    I disabled System Restore for my drives. Is it OK to re-enable it now?

    edit: After I thought Lop was gone, the icons reappeared on my desktop and there were again two instances of IE. I ran another full scan with Adaware SE and this time it found 96 instances of Lop.

    I had it delete all of them and then deleted some questionable files I found in my Program Files folder. I hope this is it.

    edit: Turns out I forgot to decline the sponsor for Messenger Plus and that's how I got that spyware. Now I've reinstalled sans the sponsor, so hopefully no more trouble.
     
    Last edited: 2004/09/29
  8. 2004/09/29
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    If you continue to have problems, we may need to move this to security. Coolweb and Lop both have newer versions that are super hard to spot and remove.

    Lonny & Mark can do it, probably Dave, and possibly a couple of others. Not me though. I don't follow that stuff closely enough. You almost gotta live on the security forums to keep up with the newer nasties and how to spot them & kill them.
     
    Newt,
    #7
  9. 2004/09/30
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Well, this should be in the security forum IMHO... Moving.
     
    Arie,
    #8
  10. 2004/10/01
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    I would suggest installing the IESpyads.Reg file for now. That second instance of IE is running an ActiveX control, and chances are this site is in this REG file. This file merges hundreds of sites into the Restricted Zone. and once a site goes into the Restricted, any future and current ActiveX processes connecting to those sites are halted, due to default settings. I set everything to disable in that zone.
     
  11. 2004/10/01
    shadowhawk

    shadowhawk Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    985
    Likes Received:
    0
    Where can I find this file? I only got one search result in Google, and it was for this site.
     
  12. 2004/10/01
    Bmoore1129

    Bmoore1129 Geek Member

    Joined:
    2002/06/11
    Messages:
    1,675
    Likes Received:
    3
    Look in Mark62 signature above your post
     
  13. 2004/10/01
    shadowhawk

    shadowhawk Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    985
    Likes Received:
    0
    Thanks I got it! Weird thing happened when I right clicked on the ZIP file to scan for viruses. I got this popup from Kerio asking about a modified program, one Logitech QuickCam photo album. I clicked Deny because I hadn't made any changes to it. Then the the box sat there like it was frozen, so I brought up Task Manager to try and shut it down. All of a sudden MS Word and two instances of an MP3 tag editor I use opened by themselves. I shut these down and the box was gone. I right clicked the ZIP again and noticed that the menu item to scan for viruses was gone. So I opened eTrust and looked around in its options, couldn't find one to bring it back, so I closed eTrust. And now the menu item to scan is back again.

    Weird... :confused:
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.