popup when opening the website majorgeeks

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cher_hc_43, Feb 25, 2006.

  1. cher_hc_43

    cher_hc_43 Private First Class

    When I opened this website I got a security breach warning about the blackworm virus, has anyone else got the same message? It said I need to download security software to prevent further attacks of malware, am I infected or is it just another annoying popup that comes up, God I have a lot of protection on my computer I have ad-aware, Windows Defender,Spybot search and destroy and spy sweeper, also have Norton anti virus installed, How can I tell if I am infact infected with the blackworm virus if none of the other programs find it.

    cheryl
     
  2. cher_hc_43

    cher_hc_43 Private First Class

    Re:how do you do attachments

    I am attaching what was viewed on my screen, when I hit the ok button on the security breach it brought me up a download page, is this a malware scam? please check it out and get back to me as soon as possible

    thank you
    cheryl

    ok the upload failed can some tell me how to do
    the attachments
     
  3. Corporal Punishment

    Corporal Punishment Administrator Staff Member

    Well -- I can tell you that we dont run pop ups at MajorGeeks.com, so it has to be a scam of some sort. If it is every time you enter, it is probably malware. You should see our guide here http://forums.majorgeeks.com/showthread.php?t=35407
    and see if that helps.

    As for attachments...Did you get an error message?
     
  4. cher_hc_43

    cher_hc_43 Private First Class

    yes i did i got an error message, i wanted to post what popped up on my comuter but it wouldnt let me, any suggestions? and it isnt your website that did it, it just happened to pop up when I opened your website, sorry i must have put it down wrong.
     
  5. cher_hc_43

    cher_hc_43 Private First Class

    also I have ran ad-aware, windows defender and spybot and neither one has found anything, I am running norton and spy sweeper now, will let you know the results, I do know that yesterday I went to a website called myspacerosks.com and my norton popped up saying that I was attacked and had to do several scans to get rid of the malware it found Adware.QoolAid and Spyware.SafeSurfing and now I just got a porno popup, am I infected is that why this is happening and what do I do to get rid of these annoying things?

    thank you
    cheryl
     
  6. Corporal Punishment

    Corporal Punishment Administrator Staff Member

    I think the survey says....YES! ;)

    Yeah, just go through that guide I linked you to step by step and we can go from there after that.
     
  7. cher_hc_43

    cher_hc_43 Private First Class

    for spybot I get the bad checksum error when trying to update the program, how do I go to a different server?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are listed directly to the right of the Search for updates button !
     
  9. cher_hc_43

    cher_hc_43 Private First Class

    ok did the spybot update, ran the bitdefender and panda spyware scan, bitdefender found nothing but the panda found stuff, should I attach the log so you can see what it found, and if you wanrt me to attach it how do I go about doing that? tried it once before and got an error message, I know I am still infected because I am, still getting those annoying popups.

    thanks
    cheryl

    should have mentioned that I disabled the
    view hidden,system files and folders and
    did a scan with all the utilities that I have
    ad-aware, spybot and windows defender and it
    found nothing, so need help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this a continuation of fixing the PC in the below thread that you never followed up on?

    http://forums.majorgeeks.com/showthread.php?t=85286

    You must not disable viewing of hidden and system files until your PC is clean (even then it is not necessary).

    Are you running ALL the steps in the READ & RUN? Step 7 for HJT explains how to attach a log. The same logic works for any attachment.
     
  11. cher_hc_43

    cher_hc_43 Private First Class

    I did all necessary scanning before I disabled the filed, and still nothing was found, and I am still getting the pop ups, they seem to be pornographic popups even though no-one has visited a pornographic site and I notice winfixer pops up to, and no this si a new problem that is happening and started this morning after my daughter used my computer and went to a myspacelayouts or something to do with myspace, and now I am having these popups.

    cheryl

    if I did it right I have attached my panda scan
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still need to leave hidden & system file viewing enabled until ALL of your problems are fixed. You are only wasting time if you change it back to default.

    Attach your HJT log too (make sure it is installed properly).

    You need to delete the below files:
    C:\Documents and Settings\cheryl carney\Local Settings\Temp\ICD1.tmp\UWA6P_0001_N68M2301NetInstaller.exe
    C:\Documents and Settings\cheryl carney\Local Settings\Temporary Internet Files\Content.IE5\FR9NJP8W\WinAntiVirusPro2006ScannerInstall[1].cab[UWA6P_0001_N68M2301NetInstaller.exe]

    Additional special steps to delete C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s UWA6P_0001_N68M2301NetInstaller.exe
    del UWA6P_0001_N68M2301NetInstaller.exe
    exit
     
  13. cher_hc_43

    cher_hc_43 Private First Class

    I dont have HJT, do I need to run hijack this, and if I do how do I go about doing that? how do I find those files that I need to delete, I have windows xp,

    thank you
    cheryl
     
  14. cher_hc_43

    cher_hc_43 Private First Class

    I received another pop up window stating there was a security breach, I am attaching the massage that I received can anyone tell me what it is, I also ran the read me first all of the steps accept the HJT I am waiting for a reply on my last message before I run the HJT.

    thanks
    cheryl
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can run Windows Explorer to delete the first two and follow the directions I already gave you for the third file.

    It is part of the READ & RUN ME process that you are supposed to be following. See step 7. Have you run ALL the other steps in the READ & RUN ME from step 0 thru step 6? If not, you must run ALL of them in the order given.
     
  16. cher_hc_43

    cher_hc_43 Private First Class

    I'm sorry for all of the questions but I am really frustrated, I had followed all the steps in the Read me First page and I am trying to find the files that you listed, I cant seem to locate them, do I need to enable the hidden files in order to find them? I will wait for your answer before I go there, also when I went to the MSCONFIG I noticed the UWA6P_0001_N68 was there at startup so I took the check mark out of the box, it looks like to me that something was installed without my knowledge, I was readding somewhere that there are websites that are being attacks by this WinSoftware Installer or Winfixer, it is hard to locate these, I am having a real hard time and it seems that every scan I do wether it is an online scan ir the programs I have nothing catches it. What am I doing wrong, I followed step by step in our read me first.
    \
    cheryl
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you followed the READ ME and listed to what I stated in my previous messages, you should already have viewing of hidden and system files enabled. Are you saying you still did not do that?

    The READ ME is not completed until steps 0 thru 7 have been completed. Step 6 requires two online scan logs to be attach and step 7 requires a HijackThis log to be attached. You said BitDefender did not find anything so that means only Panda's log needed to be posted and you did that; however you did not read and follow the directions in step 7 for HijackThis. Step 7 also tells you specfically NOT to use msconfig to disable any startups.

    You are making things take way to long. Your first message should not have been posted until you had the Bitdefender, PandaActiveScan, and HijackThis logs all completed and attached. We are now on msg 17.
     
  18. cher_hc_43

    cher_hc_43 Private First Class

    Sorry, how do I go about running HJT, I have never done that before, and I was trying to look for the files, I went into temporary internet files and OH MY GOD there was a lot of pronographic temp files on there, how in the heck did they get there, no-one has even gone to any sites like that, I deleted them all and ran the ccleaner, should I go back to my msconfig and put a check mark back in the thing I disabled?

    thank you
    cheryl
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try this again! READ THE READ & RUN ME STEP 7!
     
  20. cher_hc_43

    cher_hc_43 Private First Class

    ok I ran the HJT and got a read out but I dont know how to post it so you can look it over, on the instructions for posting a log it says to go to the bottom page and hit the advanceed button but I dont see anything, can you please tell me how to do it?

    thank you
    cheryl
     
  21. cher_hc_43

    cher_hc_43 Private First Class

    ok I ran the HJT and got a read out but I dont know how to post it so you can look it over, on the instructions for posting a log it says to go to the bottom page and hit the advanceed button but I dont see anything, can you please tell me how to do it?

    thank you
    cheryl

    figured it out hope you are able to read it, let me know
     

    Attached Files:

  22. cher_hc_43

    cher_hc_43 Private First Class

    I am posting another HJT log because I fogot to go back into the msconfig and enable the UWA6P, hope this helps

    cheryl
     
  23. cher_hc_43

    cher_hc_43 Private First Class

    ok why cant i submit another hjt log
     
  24. cher_hc_43

    cher_hc_43 Private First Class

    ok it worked
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I knew with a little perseverance you would figure out the HijackThis stuff. ;)

    Let's see what we can do to get you fixed up.

    You need to do this (I gave it to you previously)
    Have you run the below steps yet:

    Virtumonde aka Trojan Vundo Removal

    If not , please do so and attach the requested log.

    Is your Spy Sweeper a paid version?
    Also what version number is it?
     
  26. cher_hc_43

    cher_hc_43 Private First Class

     
  27. cher_hc_43

    cher_hc_43 Private First Class

     
  28. cher_hc_43

    cher_hc_43 Private First Class

    ok I ran the VundoFix and followed all the steps, but there was no log to attach because it didnt prompt me to save or anything, is there a log somewhere on my computer that it saved to?

    cheryl
     
  29. cher_hc_43

    cher_hc_43 Private First Class

    ok I should have looked before I wrote the last message, I found the log and I am attaching it.

    cheryl

    p.s.
    I ran the CMD again just in case
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That seems to have fixed your Virtumonde problems. Attach a new HJT log so we can see what may remain.

    How are things working right now?
     
  31. cher_hc_43

    cher_hc_43 Private First Class

    ok will do, so far so good I havent had any pop ups, its been great, hey when I run the hJT to I enable the hidden files and folders?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's not jump ahead but as I stated before, there is no reason to change those settings back unless you feel uncomfortable being able to see those folders and files. Just realize if you change it back, you not only allow Windows to hide system files and folders but you allow malware to hide too.
     
  33. cher_hc_43

    cher_hc_43 Private First Class

    I ran the HJT with the hide files and folders hidden if you want me to uncheck that and do another scan let me know.

    cheryl
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis has nothing to with that option! It is for Windows Explorer only!
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs for anything like MyWay, MyWarSearch, or MyWaySearchBar etc and uninstall if found.
    It's a good thing there are no files we need to delete or you would be changing the hidden files settings again since you did not wait to change it until your PC was completely clean.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
    O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
    O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  36. cher_hc_43

    cher_hc_43 Private First Class

    OK did all the steps that were required, I think everything is running ok, I havent had any more of those annoying popups, and it seems like everything is in order, I am posting my last HJT log, the reason for me hitting the hide folder and files is to prevent any unnecessary deleting of files since I do have 3 kids and I never know if they are going to going into my explorer, so I think it is save to have them hidden, but I ran the hjt with the folders and files showing.

    thank you for all of your help you are a life saver, I really mean it!

    cheryl

    p.s.
    and thank you for taking your sunday time to help me. :)
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!

     
  38. cher_hc_43

    cher_hc_43 Private First Class

    thank you for all your help! :)
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds