since this morning i have been frequently encountering random pop-up IE ads, random IE clicking noises and sound-only, uncloseable ads. please help me out here.
i have also performed a MBAM security check and saved the log.

Dani AI

Generated

Good start by @virusrmash for posting the scan and by for asking for deeper logs. Sound‑only, uncloseable ads that spawn Internet Explorer windows are frequently caused by injected browser components (toolbars/BHOs), persistent startup items, scheduled tasks or a hidden process that launches IE. Malwarebytes is a good first step, but deeper inspection of startup and kernel/rootkit indicators is often required.

Immediate containment and practical steps:

  • When an ad plays, open Task Manager and note extra iexplore.exe processes; use End Process Tree to stop the audio temporarily. Disconnect the PC if popups keep occurring.
  • Reboot into Safe Mode with Networking and run an updated full scan with anti‑malware tools.
  • Use Autoruns (Sysinternals) to inspect Run/RunOnce, Scheduled Tasks and Browser Helper Objects; disable unknown/non‑Microsoft entries rather than deleting them immediately.
  • In Internet Explorer use Manage Add‑ons to disable unfamiliar toolbars/extensions and check the browser shortcut properties for appended URLs.
  • Inspect the hosts file at C:\Windows\System32\drivers\etc\hosts for unexpected redirects and back it up before editing.

About the logs requested by : DDS provides a readable snapshot of services, startup items and key registry entries; GMER looks for hidden modules/rootkit hooks. Save the text logs and paste them here (not screenshots). Run GMER only if comfortable—it can produce noisy output and in rare cases destabilize a system; volunteers can interpret its output and point to safe removal steps.

Do not run advanced removal tools like ComboFix without guidance. Check the related thread linked for similar cases but back up or create a restore point first. Post the DDS/GMER outputs plus a short list of suspicious startup entries and volunteers will identify the exact items to remove.

Recommended Answers

All 4 Replies

i have also performed a MBAM security check and saved the log.

Please post your MBAM log. Also, please follow the linky below and post the requested scanlogs (including a fresh MBAM with updated database):

http://www.daniweb.com/forums/thread134865.html

With any luck, I or another volunteer will be able to assist you further as time permits.

Cheers :)
PP

Please post your MBAM log. Also, please follow the linky below and post the requested scanlogs (including a fresh MBAM with updated database):

http://www.daniweb.com/forums/thread134865.html

With any luck, I or another volunteer will be able to assist you further as time permits.

Cheers :)
PP

here is my MBAM log:
PS: should i perform a full scan, or quick scan with Microsoft Malicious Software Removal Tool?

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4345

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

25/07/2010 3:49:05 PM
mbam-log-2010-07-25 (15-49-05).txt

Scan type: Full scan (C:\|)
Objects scanned: 245796
Time elapsed: 1 hour(s), 8 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{f3fee66e-e034-436a-86e4-9690573bee8a} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{f3fee66e-e034-436a-86e4-9690573bee8a} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f3fee66e-e034-436a-86e4-9690573bee8a} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f3fee66e-e034-436a-86e4-9690573bee8a} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{f3fee66e-e034-436a-86e4-9690573bee8a} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

should i perform a full scan, or quick scan with Microsoft Malicious Software Removal Tool?

Don't worry about that one - I'd like to see the GMER logs and DDS.

PP:)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.