Computing.Net > Forums > Security and Virus > POPNAV Virus/Will not go away

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

POPNAV Virus/Will not go away

Reply to Message Icon

Name: Mrnyc01
Date: January 20, 2004 at 13:03:10 Pacific
OS: Windows XP Pro
CPU/Ram: 1.4/128
Comment:

Hi -

Keep getting popnav virus. Used cwshedder here is my log..thanks guys:


Logfile of HijackThis v1.97.7
Scan saved at 3:56:56 PM, on 1/20/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\LEXBCES.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\AnyPoint\APSERVER.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\BellSouth\Connection Tool\IPClient.exe
C:\Program Files\BellSouth\Connection Tool\IPMon32.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\WINDOWS\System32\iefeatures.exe
C:\WINDOWS\System32\lexpps.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\Intel\AnyPoint\DShmap.exe
C:\Program Files\Intel\AnyPoint\iss_srvr.exe
C:\Program Files\BellSouth\Connection Manager\CManager.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\PROGRA~1\Intel\AnyPoint\contctrl.exe
C:\PROGRA~1\BROADJ~1\CLIENT~1\CFD.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\system32\logon.scr
C:\Documents and Settings\johnson\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seekseek.com/quicksearch.asp?session=0E66F60F-0611-436A-AA82-D82E3F49FF87&version_id=18
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_2_3_0.dll
O2 - BHO: (no name) - {5074851C-F67A-488E-A9C9-C244573F4068} - C:\WINDOWS\ieasst.dll
O2 - BHO: (no name) - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_2_3_0.dll
O4 - HKLM\..\Run: [SystemTray] "SysTray.Exe"
O4 - HKLM\..\Run: [PrinTray] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe"
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\BellSouth\Connection Tool\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\BellSouth\Connection Tool\IPMon32.exe"
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /nosystray
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] "C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe"
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] "C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe"
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.exe TWEAKUI.CPL,TweakMeUp
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: Connection Manager.lnk = C:\Program Files\BellSouth\Connection Manager\CManager.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O4 - Global Startup: Sharing and Mapping Software.lnk = C:\Program Files\Intel\AnyPoint\DShmap.exe
O4 - Global Startup: Wireless Control Panel.lnk = C:\Program Files\Intel\AnyPoint\wcpanel.exe
O4 - Global Startup: Internet Sharing Server.lnk = C:\Program Files\Intel\AnyPoint\iss_srvr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh309190.dll/201
O8 - Extra context menu item: Save with Download Manager... - C:\Program Files\J River\Media Jukebox\DMDownload.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra 'Tools' menuitem: Turbo Download (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: Win32 Classes -
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/FIX19105/flash.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020323/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe
O16 - DPF: {6EB5B540-1E74-4D91-A7F0-5B758D333702} (nCaseInstaller Class) - http://bis.180solutions.com/activexinstallers/Installer/nCaseInstaller.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/hitthepros03/bellsouth/wtinst.cab
O16 - DPF: {DBAE7000-01EC-4162-8FEB-8A27AC937CA0} (HDPluginCtrl Class) - http://webpdp.gator.com/4/download/hdplugin_1015_bundle43v1d12.cab



Sponsored Link
Ads by Google

Response Number 1
Name: Wombat
Date: January 20, 2004 at 13:10:46 Pacific
Reply:

Read up on fixing it yourself here...

http://www.spywareinfo.com/~merijn/htlogtutorial.html#r


0

Response Number 2
Name: Mrnyc01
Date: January 20, 2004 at 13:28:05 Pacific
Reply:

tried that ...didn't work


0

Response Number 3
Name: mamabear
Date: January 20, 2004 at 13:46:34 Pacific
Reply:

Download Ad-aware Build 6.181 (free version) from here.

This link will tell you how to update your ref files (which you should do after installation and before each scan because they are updated frequently).

This link will tell you how to configure AAW for a full custom scan. After configuring the settings, when you click on "scan now", make sure that "custom" scan is checked, not "smart" scan.

This link will tell you how to remove unwanted objects.

If this doesn't clean it up, post back.



0

Response Number 4
Name: Mrnyc01
Date: January 20, 2004 at 17:23:16 Pacific
Reply:

YOU GUYS ARETHE BOMB!!! That Ad-ware worked! I was running an older version and it did not remove it. Thanks again!


0

Response Number 5
Name: Russell Trevena
Date: January 25, 2004 at 10:13:10 Pacific
Reply:

I'm having the same issue. After running Ad-ware, what should I delete to get rid of POPNAV?


0

Related Posts

See More



Response Number 6
Name: Mike Giambrone
Date: January 26, 2004 at 15:13:33 Pacific
Reply:

I discovered a program called iefeatures.exe running in processes in my Task Manager. I found it in my C:windows/system32 directory. I renamed it and rebooted and POPNAV went away.


0

Response Number 7
Name: prakashgeorge
Date: January 31, 2004 at 12:54:11 Pacific
Reply:

Mike Giambrone,

Thank you for your insight. It works!!!
Got the culprit: "iefeatures.exe". No more POPVAVs!!


0

Response Number 8
Name: Carla Baron
Date: February 5, 2004 at 02:34:48 Pacific
Reply:

Hi, Mike ..

I also found the "iefeatures.exe" in my C:windows/system32 directory . Also in "Prefetch".

My question is:

Do I delete completely these items, or "rename" both files as you suggested ??? "Renaming" is better than "deleting" ???

Thanks for replying a.s.a.p.


0

Response Number 9
Name: EMHOB
Date: February 5, 2004 at 18:12:22 Pacific
Reply:

is the "iefeatures" under my computer, c drive, windows, system?? and is the icon 3 cubes w/ a "m", "f", and "c"???? i am trying to get rid of popnav also


0

Response Number 10
Name: Carla Baron
Date: February 5, 2004 at 20:57:05 Pacific
Reply:

Troubled...

I just ran a system search with the term "iefeatures.exe" typed in search box. You'll see it there. Make sure you also search in all files, including "hidden files", when you do.

That should do it.


0

Response Number 11
Name: alsted
Date: February 6, 2004 at 08:39:58 Pacific
Reply:

i will be trying the above but i have turned popnav.com into the FTC at www.ftc.gov/ftc/complaint.htm along with whenu.com and ihatepopups.com and ask that others do as well as the feds what to know and add to their hunt ... whenu.com has a number of lawsuits happening and with luck so will popnav.com and others

thanks


0

Response Number 12
Name: deepak_patel
Date: February 6, 2004 at 19:10:05 Pacific
Reply:

thanks for helping me. i had the same problem with popnav and all the extra popup ads. does anyone know what the source is or how this program made its way on to my computer?


0

Response Number 13
Name: deepak_patel
Date: February 7, 2004 at 12:06:43 Pacific
Reply:

there is also a internetfeatures.exe file that is part of this popnav file. its a small 24Kb file that once i deleted the rest of the popups went away. i restarted my computer and everything is fine.


0

Response Number 14
Name: kristi
Date: February 8, 2004 at 17:18:18 Pacific
Reply:

i am having this same problem. i have located the iefeatures file in windows\system along with the other file mentioned a few posts up that is 24kb. i was able to delete that file but keep getting the message of access denied when i try to either rename or delete the iefeatures file. is there any way i can get around this? this popnav crap is killing me!


0

Response Number 15
Name: deepak_patel
Date: February 8, 2004 at 19:07:05 Pacific
Reply:

(making sure you are looking in hidden files too)

easiest thing i found was to do a search on ALL applications created on or after january 31 2004. look for anything that has to deal with iefeatures and delete them. once you have done this restart your computer.

i also did another search on all applications on the whole computer and deleted any other program that has that 3 cube icon that the iefeatures.exe file had. i beleve there were 2 more of them in addition to the files directly asociated with iefeatures. This step may not be neccesary for everyone but it did get rid of the remaining pop-ups that didnt go away the first time.


0

Response Number 16
Name: JeffreyAHayes
Date: February 12, 2004 at 19:48:49 Pacific
Reply:

This POPNAV is driving me nuts. I've tried deleting IEFEATURES.exe and INTERNETFEATURES.exe. I've also tried to run AD-AWARE 6.0, but it hangs when it goes to quarantine files. I'd sure appreciate any help. Here's the output of Hijackthis.

Logfile of HijackThis v1.97.7
Scan saved at 7:26:47 AM, on 2/12/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\SSDPSRV.exe
C:\WINDOWS\SYSTEM\DEVLDR16.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\WINDOWS\SYSTEM\PELMICED.exe
C:\CFGSAFE\AUTOCHK.exe
C:\IBMTOOLS\APTEZBTN\APTEZBP.exe
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.exe
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.exe
C:\WINDOWS\SYSTEM\HPZTSB05.exe
C:\PROGRAM FILES\CLEARSEARCH\LOADER.exe
C:\WINDOWS\SYSTEM\MSBB\MSBB.exe
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.exe
C:\PROGRAM FILES\NETSCAPE\NETSCAPE\NETSCP.exe
C:\WINDOWS\TWAIN\A4s2\Watchdog.exe
C:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.exe
C:\PROGRAM FILES\MICROSOFT BROADBAND NETWORKING\MSBNTRAY.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\WINDOWS\RUNDLL32.exe
C:\PROGRAM FILES\MICROSOFT BROADBAND NETWORKING\IPHLPSVR.exe
C:\HJT\HIJACKTHIS.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://alltelnet.custhelp.com/cgi-bin/alltelnet.cfg/php/enduser/home.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://popnav.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by ALLTEL Internet
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.alltel.net/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL (file missing)
O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - C:\WINDOWS\SYSTEM\BTIEIN.DLL
O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\PROGRAM FILES\LYCOS\SIDESEARCH\SIDESEARCH1311.DLL
O2 - BHO: Clear Search - {00000000-0000-0000-0000-000000000240} - C:\PROGRAM FILES\CLEARSEARCH\IE_CLRSCH.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.exe
O4 - HKLM\..\Run: [AAACLEAN] c:\windows\rundll.exe setupx.dll,InstallHinfSection DefaultInstall 128 C:\WINDOWS\INF\AAACLEAN.INF
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\AUTOCHK.exe
O4 - HKLM\..\Run: [AEZBProc] c:\ibmtools\aptezbtn\aptezbp.exe
O4 - HKLM\..\Run: [Speed racer] C:\Program Files\Creative\PlayCenter\CTSRReg.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.exe
O4 - HKLM\..\Run: [ZIBMACC] c:\windows\rundll.exe setupx.dll,InstallHinfSection DefaultInstall 128 C:\WINDOWS\INF\ZIBMACC.INF
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.exe /LOADQUIET
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\SYSTEM\stcloader.exe
O4 - HKLM\..\Run: [ClrSchLoader] \Program Files\ClearSearch\Loader.exe
O4 - HKLM\..\Run: [MSVersion] C:\WINDOWS\SYSTEM\INTERNETFEATURES.exe
O4 - HKLM\..\Run: [iefeatures] C:\WINDOWS\SYSTEM\IEFEATURES.exe
O4 - HKLM\..\Run: [msbb] C:\WINDOWS\SYSTEM\MSBB\MSBB.exe
O4 - HKLM\..\Run: [IYBPFW] C:\WINDOWS\IYBPFW.exe
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.exe -r
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\RunServices: [AIM] C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\RunServices: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Watchdog.lnk = C:\WINDOWS\TWAIN\A4s2\Watchdog.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: AOL Instant Messenger (SM) (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Sidesearch (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37995.646412037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab



0

Response Number 17
Name: Carla Baron
Date: February 12, 2004 at 22:58:25 Pacific
Reply:

Hey, Jeffrey ..

Here's what I did, and so far ... so good.

I ran a search of ALL files & folders in "C" drive (don't forget to add "hidden" files to the list) - in the box marked "all or part of the file name", type in "iefeatures.exe" ... then in the box "a word or phrase in the file", type in "popnav".

Delete each of these found by right-clicking, one by one. Then make sure you empty your recycle bin.

Then, go look in C:windows/system32 directory ... also in "Prefetch" for file named "iefeatures.exe".

Rename this file to whatever.

Run a complete deep scan with Ad-aware after this.

No more Popnav hell for me. Life is so very good now. :)

Let me know if that works for you.

~ Carla



0

Response Number 18
Name: hamop78
Date: February 13, 2004 at 15:42:43 Pacific
Reply:

Well Carla

Did all
Searched all files including hidden
deleted what I could
renamed all others

searched for word popnav

Ran REGEDIT looking for all or part
Deleted regestry keys

emptied all recycle bins including norton protected

Ran Adaware twice

within 5 minutes after reboot

IT'S BACK

----- It keeps coming back!!! HELP


0

Response Number 19
Name: JeffreyAHayes
Date: February 13, 2004 at 17:05:20 Pacific
Reply:

Carla,
Thanks for the help, but I realize I posted to the wrong forum. I'm running Windows 98 SE. I'll see what I can find in the right forum.

Jeffrey


0

Response Number 20
Name: Carla Baron
Date: February 14, 2004 at 00:13:16 Pacific
Reply:

Harris ..

I also have downloaded Spybot Search & Destroy. This may help immunize your system after you clean it.


Check your "favorites" listings to see if Popnav added search features there, along with Ebay, etc. Delete all that you didn't place there yourself. (That happened in my system.)

Also - did you do a COMPLETE DEEP SCAN of all your files in "C" drive per directions with Ad-aware ? You must customize your scan first. I'll list link to steps here:

How To: Perform a "Full Scan" With Ad-aware 6 Build 181

http://www.lavahelp.com/howto/fullscan/index.html

Follow these steps exactly.

Let me know if you're still having trouble.

~ Carla


0

Response Number 21
Name: Soteria
Date: February 16, 2004 at 13:57:50 Pacific
Reply:

I have also been plagued by popnav hijacking my computer, installing itself, adding itself and "internet tools", "ebay", "stop popups", etc., to my favorites AND putting icons on my desktop! Every time it happens, I feel like I've been MUGGED. I will try the previous advice. I use WinPatrol, Browser Hijack Blaster, Ad Aware, popup blockers, banned web sites, filters and SpyBot and it gets past them ALL!! What good will it do to search and delete if it continues to COME BACK? I don't understand how they are doing this despite all the blocks, scans and such available.


0

Response Number 22
Name: Carla Baron
Date: February 16, 2004 at 20:07:22 Pacific
Reply:

Soteria ..

I actually didn't delete the file marked "iefeatures.exe" - I renamed it. That way, it can't recognize that file in my task manager. After deleting all the extraneous files I talked about earlier in Favorites, and in your searches, rename that file.

Worked for me !

~ Carla


0

Response Number 23
Name: mel
Date: February 17, 2004 at 19:20:04 Pacific
Reply:

I've been reading the posts, and I've located the iefeatures.exe file, but I am denied access when I try to delete it OR rename it. What do I do?? please help, thank you!


0

Response Number 24
Name: Carla Baron
Date: February 17, 2004 at 21:01:17 Pacific
Reply:

Mel ...

I renamed this file from the list in my task manager file :

C:windows/system32 directory

I did NOT rename it while still in the search listings. I went DIRECTLY to the Windows directory, right-clicked on this file "iefeatures.exe", then clicked on "rename".

Let me know how it goes.

~ Carla


0

Response Number 25
Name: mel
Date: February 19, 2004 at 13:28:06 Pacific
Reply:

Carla-
Thank you so much for your reply. Please excuse my computer illiteracy, but I'm not sure if I'm going about this in the right way. I've found iefeatures through my computer at C:windows/system (it is not system32 on mine), and I try to rename it, but access is denied! I am told, again, that the program may be protected or it is running. Please send any feedback! Thank you so much, again!

-Mel


0

Response Number 26
Name: Carla Baron
Date: February 19, 2004 at 19:00:40 Pacific
Reply:

Have you deleted everything in a complete search with the name on file of "iefeatures.exe" ??? Then delete everything (you must do one by one in search by right-clicking) with name "popnav" in 2nd box as "word or phrase in the file". Then after that, go find that file again in "C". Rename, if you can.

Also - did you download Ad-Aware and Spybot Search & Destroy for your system ??? Remember to do deep scan as I outlined above.

~ Carla


0

Response Number 27
Name: mel
Date: February 20, 2004 at 16:43:14 Pacific
Reply:

Carla-

I ran a search under popnav and deleted all of those, but I still cannot delete or rename iefeatures.exe from either location. I've run adaware, spybot, and spyhunter multiple times to no avail! Any other suggestions?? thanks again!

-Mel


0

Response Number 28
Name: Carla Baron
Date: February 20, 2004 at 20:49:15 Pacific
Reply:

Try opening up your "C" drive, and locate that file in the hidden files in Windows. These generally are hidden until you deliberately open the entire content for viewing. You'll see a 3-cube icon next to it. Perhaps from there directly (be careful not to mess up any other function) - then try to rename file by right-clicking on it.

Hey - how come I am the only one helping here ???? No one else seems to be contributing ... I actually have another career I am tending to, but hope all this has helped. :)

~ Carla


0

Response Number 29
Name: Arkady
Date: February 22, 2004 at 19:43:54 Pacific
Reply:

Mel -

I had the same problem with iefeatures.exe. It would not allow me to access it, and it was obviously spawning all the files that Ad-Aware (latest release) was removing after every reboot. Here's how I fixed the problem (mind you I am running 98, but I suspect XP will be similar enough for this to be useful to you.)

Registry editor (Run - Regedit from the start menu)

HKEYS_LOCAL MACHINE
Software
Microsoft
Windows
Current Version
Run

In the run key was a value telling my computer to run iefeatures.exe on startup. It should be pretty obvious. I simply deleted the value, and rebooted. Now that the computer wasn't running the program I could rename it, just to be on the safe side.

As a matter of infantile vengeance after a wasted evening away from my home and family, I also opened iefeatures.exe (with Wordpad) and vandalized its evil code with random typing and profanities. Not perhaps as efficient as a shredder program, but more cathartic.

Hope this helps.

Arkady


0

Response Number 30
Name: rocksclimber
Date: February 22, 2004 at 20:53:26 Pacific
Reply:

I had the same problem as the previous user when attempting to rename the "iefeatures.exe" file in my system folder. I am running Windows 98. I kept getting an error message stating that the file i was trying to rename was write-protected.

I solved this problem by restarting in MS-DOS mode. I used MS-DOS commands to rename the rename the "iefeatures.exe" file.

All of that popnav garbage is gone.

Thanks to Carla Baron's suggestions above.


0

Response Number 31
Name: dbuskirk
Date: February 24, 2004 at 11:39:12 Pacific
Reply:

Actually you do not want to just rename it. I'll write this in the most basic of terms so that all who see this site may follow along.

1) You'll want to go to Run-> Type in "Regedit" and hit enter. When this dialog box pops up click on "Enter" and then "Find". Search for "iefeatures.exe" when it finds it - Delete it.

2) Now press Ctl+Alt+Delete at the same time and under Processes you'll see "iefeatures.exe" End Process.

3) Now go back to "Start" and click on "Search" do a SEARCH on "iefeatures.exe". There will be two referneces to this. One in Windows/System32 directory and one in the Windows/Prefetch directory. Delete these. If you cannot, this means they are running in the background.

This is the cleanest and most effective way to get rid of this. If you just rename it you'll stil have it referneced in your Registry.



0

Response Number 32
Name: Carla Baron
Date: February 25, 2004 at 16:51:38 Pacific
Reply:

It's weird, but I went back to look for the file "iefeatures.exe" after I renamed it something else, & it is no longer there !

I searched all over that file where I had originally found it in C:windows/system32 directory.

I am assuming that when I had done my deep scan with Adaware as outlined above, that took care of deleting that obnoxious nuisance altogether.

I still to this very day have no more Popnav invading my life ! And it feels so good !!!

(Just wanted to share that update.)


0

Response Number 33
Name: Bert M
Date: February 29, 2004 at 06:07:49 Pacific
Reply:

I have been using Ad-aware, but like some of you, the Popups keep coming back. I wasn't able to delete iefeatures.exe due to it supposedly being a read only file, but I was able to delete it from my registry and I haven't had a popup in almost a week.
Go to Start, pick run, type in regedit and enter. Go to HKEY_LOCAL_MACHINE/SOFTWARE/MICROSOFT/WINDOWS/CURRENTVERSION/RUN. Pick iefeatures.exe and delete it. Exit regedit. It worked for me. Good luck.

Bert

Bert M


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: POPNAV Virus/Will not go away

SPYWARE/PORN wont go away!!!! www.computing.net/answers/security/spywareporn-wont-go-away/5164.html

Searchv doesnt go away www.computing.net/answers/security/searchv-doesnt-go-away/6821.html

IST wont go away! www.computing.net/answers/security/ist-wont-go-away/12820.html