PDA

View Full Version : IE features hijack aka Popnav


Pieter_Arntz
January 2nd, 2004, 07:25 AM
Hijacks the startpage to popnav.com and produces popups.

In a HijackThis log fix:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.popnav.com

O4 - HKLM\..\Run: [MSVersion] C:\WINDOWS\System32\iefeaturesversion.exe
O4 - HKLM\..\Run: [iefeatures] C:\WINDOWS\System32\iefeatures.exe

O16 - DPF: {2CAB81F6-1CBB-49FD-809E-B2D37D0CFFED} (IEFeature Class) - hxxp://www.popmonster.com/control/src/iefeatures.ocx

After a reboot delete these files:
C:\WINDOWS\System32\MSrdk.xml
C:\WINDOWS\System32\iefeaturesversion.exe
C:\WINDOWS\System32\iefeatures.exe

HTH,

Pieter

Pieter_Arntz
January 19th, 2004, 03:53 AM
New version using this entry:

O4 - HKLM\..\Run: [MSVersion] C:\WINDOWS\System32\ClrSchP038.exe

Pieter_Arntz
March 15th, 2004, 02:57 PM
And another version:

O4 - HKLM\..\Run: [SearchNavVersion] C:\Documents and Settings\subfl0wer\searchnavversion.exe
O4 - HKLM\..\Run: [searchnav] C:\Documents and Settings\subfl0wer\searchnav.exe