I've managed to catch a bug on my system and I can't seem to shake it. Symptoms are the seemingly random opening of a FireFox (default web browser) window displaying an advertisement. This doesn't always happen when I otherwise have FireFox open. I've scanned with AdAware, SpyBot, MS Defender, and McAfee VirusScan, all to no avail. The buggers even come up booted in Safe Mode w/ Networking. System is fully patched, all scanners were updated with latest definitions before scanning in Safe Mode. HijackThis log (taken in Safe Mode) posted below. Any help in prying this thing out of my system would be greatly appreciated!
Thanks!
JW
ps - FYI, I've got a Creative sound card, NVidia video board, and Epson printer – software associated with these devices seems to account for a lot of the log entries below…
———————————————————————–
Logfile of HijackThis v1.99.1
Scan saved at 9:15:43 PM, on 8/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
I know you have run several scans, but please do these and let's see the results.
STEP 1.
====== SpySweeper
Download the trial version of Spy Sweeper from Here
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)
If you are taken to the internet page, just close the page.
You will be prompted to check for updated definitions, please do so.
(This may take several minutes)
Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.
Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!
When the sweep has finished, click Remove. Click Select All and then Next
From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.
STEP 2.
======
The Ewido program’s detection rate is excellent. After the Trial has expired, the auto updates and real time protection stop but you can still update it manually and run scans anytime you want.
First download ewido anti-spyware from HERE and save that file to your
desktop. This is a 30 day trial of the program
Once you have downloaded ewido anti-spyware, locate the icon on the desktop
and double-click it to launch the set up program.
Once the setup is complete you will need run ewido and update the definition
files.
On the main screen select the icon "Update" then select the "
Update now" link.
Next select the "Start Update" button, the update will start and a
progress bar will show the updates being installed.
Once the update has completed select the "Scanner" icon at the top of
the screen, then select the "Settings" tab.
Once in the Settings screen click on "Recommended actions" and then
select "Quarantine".
Under "Reports"
Select "Automatically generate report after every scan"
Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
Reboot your computer into SafeMode. You can do this by restarting
your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter. IMPORTANT: Do not open any other windows or
programs while ewido is scanning, it may interfere with the scanning proccess:
Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
Select the "Scanner" icon at the top and then the "Scan" tab
then click on "Complete System Scan".
ewido will now begin the scanning process, be patient this may take a little
time. Once the scan is complete do the following:
If you have any infections you will prompted, then select "Apply all
actions"
Next select the "Reports" icon at the top.
Select the "Save report as" button in the lower left hand of the
screen and save it to a text file on your system (make sure to remember where
you saved that file, this is important).
Close ewido and reboot your system back into Normal Mode and post the
results of the ewido report scan.
Empty Recycle Bin
Reboot
Please post the results from SpySweeper, ewido and a new hijackthis log.
:mozilla.46:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.47:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.48:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.49:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.11:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.57:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined).
:mozilla.13:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.38:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.34:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.35:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.36:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.37:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.10:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.6:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.7:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.8:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.9:D:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\c7amwuae.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
::Report end
HijackThis—————————————-
Logfile of HijackThis v1.99.1
Scan saved at 10:27:04 PM, on 8/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You may receive pop-up asking if you will allow script to run when you perform the following instructions. Please allow the script to run.
Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.
IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
If you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."…then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.
Alas, this does not seem to have fixed the problem, either. Really driving me batty. At least I only get about 1-2/hour.
They come regardless of whether or not I have Firefox open already.
I'm off on vacation for a week.. will have to pound at this some more when I return. Thanks again for all your help, and I'm open to any more suggestions you may have!
JW
Susan,
Been away longer than expected – things got busy w/ the start of a new semester @work and I haven't had time to deal with this. Just getting back to it now…
So, I think I've noticed the pattern that the title bar of all of the popups includes "NSIS Media."
I poked around, found in /Program Files/Common Files/ a folder named NSIS, in which there was actually an uninstaller. Keeping my fingers crossed that there will be no more popups…
If I see another one, I'll post up those HijackThis logs from the Uninstall Manager.
Thanks!
JW
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI