Bloody pop-ups!!! please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Alan Gee, Nov 17, 2005.

  1. Alan Gee

    Alan Gee Private E-2

    Ive recently started getting those cassava casino,thorntons toffees,betting exchanges,mobile phone pop-ups.
    Ive tried everything i can think of,including looking on the forums with people with the same problem, to no avail.
    I like to think i know my way around my pc but im stumped here.
    Ive used AVG Free,MS Anti-spyware,Reg.Mechanic and recently downloaded Hijack This,following the instructions and tutorials given,i still dont see anything.
    Can someone have a look and maybe offer their opinions and solutions please.
    Should i bin AVG for Norton 2005?
    All the best.

    P/s-tried to attach logfile but dont know if its worked
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis
     
  3. Alan Gee

    Alan Gee Private E-2

    Thanks for getting back man. Just before i posted the question i had ran hijack,ms anti-spy,avg,reg mechanic etc but i was still getting pop-ups. Later i downloaded CWShredder but nothing was present but i havent had popup since-really strange.
    Anyway,ever since then,my avg free is now telling me it "cant update as it cant verify its electronic certificate". and i have the windows security center balloon constantly on in my taskbar.
    Is this all related? Are some of my programs i use causing others not to work properly.?
    Ive sent a fresh log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look like you ran ALL of the READ & RUN ME. I do not see evidence of multiple online scanners being run and I cannot tell that Spybot has been installed and run.

    You should also run this Disable/Remove Windows Messenger to disable Windows Messenger.
     
  5. Alan Gee

    Alan Gee Private E-2

    Thanx, Ive got ms anti-spy,avg,cwshredder,bit defender,reg.mechanic,yahoo anti-spy tool and hijack this. Do i definetly need it or is what i using enough?
    Alan
     

    Attached Files:

  6. Alan Gee

    Alan Gee Private E-2

    Ignore Previous Email Please!!!!!!!!!!

    I D/loaded An Ran Spybot,heres A Fresh Log Attached For You.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions in the READ & RUN ME are written for a reason and we do need them to be followed. You should have already run Spybot before your first message was posted. You said you followed the instructions!!!!

    If you are still having problems, go back and run ALL steps in the order written of the READ ME. Make sure you use Spybot's SDhelper and Immunize features.

    If you still have any problems afterwards, explain what they are.
     
  8. Alan Gee

    Alan Gee Private E-2

    Yeah,i had run most of your recommendations in the read n run section-just not in a specific order.
    Anyway,ive done it again for you, Spybot,Bit Defender,CWShredder,Ms.Anti-Spy and Hijack.
    I also did the uninstall Windows Messenger.
    Everythings been fine lately,apart from the Avg not being able to update.
    Could you check my log and see if you think my pc is clean now please.
    Thanks for all your help man!!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In my previous message I repeated the below:
    which is also in the READ ME. Is there a reason you are not doing this? If you did this, the SDhelper function would show as an O2 BHO line in your HJT log. I do not see it, thus it appears to me that either Spybot was not installed and run or you just did not follow the instructions.

    Also you still have not run at least two online scanners per step 5. Only BitDefender shows as being run.

    At anyrate, your log is clean other than: C:\Program Files\Kazaa Lite K++\KazaaLite.kpp

    A clean HJT this log does not necessary mean a PC is free of malware. It just means nothing in what HJT has the ability to report is a problem.
     
  10. Alan Gee

    Alan Gee Private E-2

    God knows whats going on,i couldnt get the sd helper thing-when i click on immunize,the box says "150 bad products are now blocked" even if i search Help i cant find it.Unless you mean the browser helper to stop bad downloads?

    Anyway never mind,thanx for all your help,really appreciated.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is called: Resident "SDHelper" (Internet Explorer bad download blocker) and it should be checked by default when you first install Spybot which is what we request in the sticky. You can find it in Advanced Mode under Tools and Resident!

    If you are only seeing 150 bad products blocked you either have the wrong version of Spybot or you have not installed the updates.
     
  12. Alan Gee

    Alan Gee Private E-2

    Hmmm Thank you,i think ive got a buckshee version of Spybot coz once i check the browser helper on etc its still only 150 bad products and under Tools-resident -Theres nothing there!! Im binning this one and will install a diff/newer version.
    Ill do this eventually mate!!!!!!!!!!!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Under the Mode, Advanced, Tools, Resident area there are two check boxes that can be checked. One is for SDhelper.

    I have 8226 bad products blocked with the latest update to Spybot.

    What version of Spybot do you have and what is the last detections date?
     
  14. Alan Gee

    Alan Gee Private E-2

    Yes my man,i re-installed another version of spybot, i done everything you said and ive got 8226 products blocked. i mustve had an older version or skipped an option.
    Ive also deleted AVG and put in NAV 2005.
    Ive attached another log to show you how its looking now.
    I hope i dont have any more probs so you can finally praise me.!!!!

    All the best to you.Thanx for all your help
    Alan G
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember message # 2, where I said:
    Our directions are important. Neglecting them always causes problems.

    And now you can see the line I was referring to:
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    Your log is clean! Are you having any other malware problems? If not then it is time to work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds