This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] internet explore windows open on their own

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I am new here. I use aol and sometimes when I close a window, internet explorer starts open windows on it own. They open faster then you can close them and I only thing I can do is hit CTRL, ALT, and delete to close aol. I was trying AT&T services but I have not been using it. When I close aol, the AT&T screen pops up complete with a password typed in but I can tell it's not my password. It never actually connects though. Here is my log I hope you can help. Thanks a lot. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:21:59.75 on Mon 05/31/2010 Internet Explorer: 6.0.2800.1106 ============== Pseudo HJT Report =============== uStart Page = hxxp://www.emachines.com/ uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.emachines.com uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/ uURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll mURLSearchHooks: IAOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol toolbar\aoltb.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: {549B5CA7-4A86-11D7-A4DF-000874180BB3} - No File BHO: AOL Toolbar Loader: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol toolbar\aoltb.dll BHO: CNisExtBho Class: {9ecb9560-04f9-4bbc-943d-298ddf1699e1} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton internet security\norton antivirus\NavShExt.dll BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File TB: Web assistant: {0b53eac3-8d69-4b9e-9b19-a37c9a5676a7} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton internet security\norton antivirus\NavShExt.dll TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol toolbar\aoltb.dll EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [] mRun: [SunKistEM] c:\program files\emachines bay reader\shwiconem.exe mRun: [Lexmark X84-X85 Button Monitor] c:\progra~1\lexmar~1\ACMonitor_X84-X85.exe mRun: [Lexmark X84-X85 Button Manager] c:\progra~1\lexmar~1\AcBtnMgr_X84-X85.exe mRun: [PrinTray] c:\windows\system32\spool\drivers\w32x86\3\printray.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [URLLSTCK.exe] c:\program files\norton internet security\UrlLstCk.exe mRun: [SSC_UserPrompt] c:\program files\common files\symantec shared\security center\UsrPrmpt.exe mRun: [HostManager] c:\program files\common files\aol\1273117047\ee\AOLSoftware.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime IE: &AOL Toolbar Search - c:\documents and settings\all users\application data\aol\ietoolbar\resources\en-us\local\search.html IE: {6224f700-cba3-4071-b251-47cb894244cd} - c:\program files\icq\ICQ.exe IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: {761EA70E-F9C2-4DD1-B6F7-7A2AA8A6987E} = 205.188.146.145 Notify: igfxcui - igfxsrvc.dll ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2010-05-31 15:24 –d—– c:\program files\Trend Micro 2010-05-06 17:20 89 a——- c:\windows\kodakPS.us.ini 2010-05-06 15:41 –d—– c:\windows\system32\bits 2010-05-06 15:40 –d—– c:\windows\system32\PreInstall 2010-05-06 15:40 22,752 a——- c:\windows\system32\spupdsvc.exe 2010-05-06 15:40 –d-h— c:\windows\$hf_mig$ 2010-05-06 11:52 –d—– c:\program files\common files\Software Update Utility 2010-05-06 11:52 –d—– c:\program files\AOL Toolbar 2010-05-04 21:09 331,776 a——- c:\windows\system32\winhttp.dll 2010-05-04 21:09 17,408 a——- c:\windows\system32\qmgrprxy.dll 2010-05-04 21:09 7,680 -c—— c:\windows\system32\dllcache\bitsprx2.dll 2010-05-04 21:09 7,168 -c—— c:\windows\system32\dllcache\bitsprx3.dll 2010-05-04 21:09 158,720 ——– c:\windows\system32\xpob2res.dll 2010-05-04 21:09 7,680 ——– c:\windows\system32\bitsprx2.dll 2010-05-04 21:09 7,168 ——– c:\windows\system32\bitsprx3.dll 2010-05-04 20:31 –d—– c:\windows\system32\SoftwareDistribution 2010-05-04 20:21 217,816 a——- c:\windows\system32\wuaucpl.cpl 2010-05-04 20:21 186,136 a——- c:\windows\system32\wuaueng1.dll 2010-05-04 20:21 167,704 a——- c:\windows\system32\wuauclt1.exe 2010-05-04 02:29 184,320 a——- c:\windows\system32\OESICore.dll 2010-05-04 02:29 45,056 a——- c:\windows\system32\HSSICore.dll 2010-05-04 02:29 40,960 a——- c:\windows\system32\HS_live.ocx 2010-05-04 02:23 98,136 a——- c:\windows\gzip.exe 2010-05-04 01:06 –d—– c:\program files\Homestead 2010-05-03 23:23 –ds—- c:\documents and settings\us\UserData 2010-05-03 21:23 24 a——- c:\windows\AM_D7.PRF 2010-05-03 21:23 –d—– C:\Kodak Pictures 2010-05-03 18:48 –d—– c:\program files\Norton Internet Security 2010-05-03 18:48 2,397 a——- c:\windows\system32\drivers\symlcbrd.sys 2010-05-03 18:29 201,488 a——- c:\windows\system32\THUMBVW.DLL 2010-05-03 18:21 –d—– c:\windows\system32\Adobe 2010-05-03 17:49 90,112 —–r– c:\windows\bwUnin-6.1.2.93-7288971L.exe 2010-05-03 17:49 –d—– c:\windows\BWKDLogs 2010-05-03 17:49 –d—– C:\KPCMS 2010-05-03 17:48 197,632 a——- c:\windows\system32\kpcp32.dll 2010-05-03 17:48 133,120 a——- c:\windows\system32\sprof32.dll 2010-05-03 17:48 86,016 a——- c:\windows\system32\PrintAPI.dll 2010-05-03 17:48 73,839 a——- c:\windows\system32\KodakOneTouch.dll 2010-05-03 17:48 37,376 a——- c:\windows\system32\kpsys32.dll 2010-05-03 17:48 19,456 a——- c:\windows\system32\kcm2sp.dll 2010-05-03 17:48 –d—– c:\windows\system32\color 2010-05-03 17:44 –d—– c:\program files\common files\KODAK 2010-05-03 17:43 –d—– c:\program files\KODAK 2010-05-03 17:39 15,664 a——- c:\windows\system32\PSUITE.SCR 2010-05-03 17:39 78 a——- c:\windows\psuite.ini 2010-05-03 17:39 –d—– c:\program files\MGI 2010-05-03 17:32 299,520 a——- c:\windows\uninst.exe 2010-05-03 17:32 20 a——- c:\windows\ACMonitor_X84-X85.ini 2010-05-03 17:31 14,208 ac—— c:\windows\system32\dllcache\usbscan.sys 2010-05-03 17:31 14,208 a——- c:\windows\system32\drivers\usbscan.sys 2010-05-03 17:31 33,792 a——- c:\windows\system32\LXBOUSCI.EXE 2010-05-03 17:31 4,672 a——- c:\windows\system32\LXBOUSCI.DLL 2010-05-03 17:30 –d—– c:\program files\LexmarkX84-X85 2010-05-03 17:25 208,896 a——- c:\windows\system32\wmpns.dll 2010-05-03 17:25 –d—– c:\documents and settings\us\WINDOWS 2010-05-03 17:25 –d—– c:\docume~1\us\applic~1\Symantec 2010-05-03 17:25 –d—– c:\documents and settings\us 2010-05-03 17:08 286,720 a——- c:\windows\system32\msh263.drv 2010-05-03 17:07 1,929,952 ac—— c:\windows\system32\dllcache\wuaueng.dll 2010-05-03 17:06 504,320 a——- c:\windows\system32\logonui.exe 2010-05-03 17:05 557,056 a——- c:\windows\system32\comctl32.dll 2010-05-03 17:00 –d–r– C:\Program Files 2010-05-03 17:00 –d–r– c:\documents and settings\all users\Documents 2010-05-03 16:57 –d–r– c:\windows\Offline Web Pages 2010-05-03 16:56 -cdshr– c:\windows\system32\dllcache 2010-05-03 16:55 –d—– c:\windows\CACHE ==================== Find3M ==================== 2010-05-04 02:25 2,232 a——- c:\windows\java\packages\data\5VZTZFBB.DAT 2010-05-04 02:25 155,995 a——- c:\windows\java\packages\V1R7HR73.ZIP 2010-05-04 02:24 2,678 a——- c:\windows\java\packages\data\7J17N3BL.DAT 2010-05-04 02:24 2,678 a——- c:\windows\java\packages\data\5RJNVDB3.DAT 2010-05-04 02:24 2,678 a——- c:\windows\java\packages\data\UYZFPN71.DAT 2010-05-04 02:24 2,678 a——- c:\windows\java\packages\data\TFD75JRR.DAT 2010-05-04 02:24 2,678 a——- c:\windows\java\packages\data\7B1JHBTV.DAT ============= FINISH: 17:27:59.17 ===============
Hi,

Please post attach.txt contents too. Then run GMER:

Download GMER here by clicking download exe -button and then saving it your desktop:
  • Double-click .exe that you downloaded
  • Click rootkit-tab, uncheck files option and then click scan.
  • Don't check
    Show All
    box while scanning in progress!
  • When scanning is ready, click Copy.
  • This copies log to clipboard
  • Post log (if the log is long, archive it into a zip file and attach instead of posting) in your reply.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 5/3/2010 1:24:04 PM System Uptime: 5/31/2010 10:57:46 AM (7 hours ago) Motherboard: | | Processor: Intel® Celeron® CPU 2.66GHz | J2E1 | 2666/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 75 GiB total, 68.678 GiB free. D: is CDROM () E: is CDROM () F: is Removable G: is Removable H: is Removable I: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1: 5/3/2010 5:24:07 PM - System Checkpoint RP2: 5/3/2010 5:33:15 PM - Unsigned printer driver Lexmark X84-X85 installed. RP3: 5/3/2010 5:43:34 PM - Installed KODAK Picture Software and Apple QuickTime RP4: 5/3/2010 5:44:25 PM - Installed KODAK Camera Connection Software RP5: 5/3/2010 5:45:00 PM - Installed KODAK Camera Connection Software Help RP6: 5/3/2010 5:45:50 PM - Installed KODAK Picture Transfer Software RP7: 5/3/2010 5:48:43 PM - Installed KODAK One Touch to Better Pictures RP8: 5/4/2010 6:33:20 PM - System Checkpoint RP9: 5/5/2010 7:18:34 PM - System Checkpoint RP10: 5/6/2010 3:39:58 PM - Software Distribution Service 3.0 RP11: 5/6/2010 3:40:09 PM - Installed Windows XP KB898461. RP12: 5/6/2010 3:40:54 PM - Installed Windows Installer KB893803v2. RP13: 5/6/2010 3:41:11 PM - Installed Windows XP KB842773. RP14: 5/6/2010 3:41:46 PM - Installed Windows XP KB899591. RP15: 5/7/2010 6:52:12 PM - System Checkpoint RP16: 5/8/2010 7:14:13 PM - System Checkpoint RP17: 5/9/2010 9:16:34 PM - System Checkpoint RP18: 5/10/2010 9:50:50 PM - System Checkpoint RP19: 5/11/2010 10:09:44 PM - System Checkpoint RP20: 5/12/2010 10:21:49 PM - System Checkpoint RP21: 5/14/2010 4:58:10 PM - System Checkpoint RP22: 5/15/2010 6:47:43 PM - Installed HiJackThis RP23: 5/16/2010 7:38:50 PM - System Checkpoint RP24: 5/17/2010 11:40:54 PM - System Checkpoint RP25: 5/19/2010 12:16:43 AM - System Checkpoint RP26: 5/20/2010 8:50:15 AM - System Checkpoint RP27: 5/21/2010 12:56:32 PM - System Checkpoint RP28: 5/22/2010 3:05:55 PM - System Checkpoint RP29: 5/23/2010 5:17:57 PM - System Checkpoint RP30: 5/24/2010 7:05:36 PM - System Checkpoint RP31: 5/25/2010 7:59:14 PM - System Checkpoint RP32: 5/26/2010 8:10:47 PM - System Checkpoint RP33: 5/27/2010 11:32:26 PM - System Checkpoint RP34: 5/29/2010 10:37:09 AM - System Checkpoint RP35: 5/30/2010 6:19:14 PM - System Checkpoint ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Illustrator 9.0.1 Adobe Photoshop 6.0 Adobe Reader 6.0 Adobe SVG Viewer America Online (Choose which version to remove) AOL Instant Messenger (SM) AOL Toolbar BigFix CC_ccProxyMSI CC_ccStart ccCommon CompuServe Download Updater (AOL LLC) eMachines Bay Reader HiJackThis Homestead SiteBuilder ICQ Intel® Extreme Graphics Driver Intel® PRO Network Adapters and Drivers Internet Explorer Q831167 Java 2 Runtime Environment, SE v1.4.2 KODAK Camera Connection Software KODAK Camera Connection Software Help KODAK Memory Albums KODAK One Touch to Better Pictures KODAK Picture Software KODAK Picture Transfer Software KODAK Software Updater Learn2 Player (Uninstall Only) LiveReg (Symantec Corporation) LiveUpdate 1.90 (Symantec Corporation) MGI PhotoSuite 8.1 (Remove Only) Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft VC9 runtime libraries Microsoft Works 7.0 MSRedist Netscape 6 (6.2.1) Norton AntiSpam Norton AntiVirus Norton Internet Security Norton Internet Security (Symantec Corporation) Norton WMI Update PowerDVD QuickTime RealPlayer Basic Realtek AC'97 Audio Security Update for Windows XP (KB899591) SoftV92 Data Fax Modem with SmartCP Symantec Script Blocking Installer Update for Windows XP (KB898461) Viewpoint Manager (Remove Only) Viewpoint Media Player (Remove Only) WebFldrs XP Winamp (remove only) Windows Backup Utility Windows Installer 3.1 (KB893803) Windows Movie Maker 2.0 Windows XP Hotfix - KB810217 Windows XP Hotfix - KB823182 Windows XP Hotfix - KB824105 Windows XP Hotfix - KB824141 Windows XP Hotfix - KB825119 Windows XP Hotfix - KB826939 Windows XP Hotfix - KB828028 Windows XP Hotfix - KB828035 Windows XP Hotfix - KB828741 Windows XP Hotfix - KB835732 Windows XP Hotfix - KB837001 Windows XP Hotfix - KB842773 ==== End Of File ===========================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-06 16:57:29
Windows 5.1.2600 Service Pack 1
Running: zvrxk5qd.exe; Driver: C:\DOCUME~1\us\LOCALS~1\Temp\kftcqpod.sys


—- System - GMER 1.0.15 —-

SSDT E1663558 ZwConnectPort

—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xF7E69510]
init C:\WINDOWS\System32\Drivers\sunkfilt.sys entry point in "init" section [0xF7DC3300]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)

—- EOF - GMER 1.0.15 —-
Hello again,

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.


Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI