pc-on-internet pop ups won't go away

Discussion in 'Malware Help (A Specialist Will Reply)' started by havalina, Apr 2, 2008.

  1. havalina

    havalina Private E-2

    i ran all the basic scans and cleaning procedures, and i still have these pop ups that ask me to down load some antispyware program on a screen made to look like a vista screen. the logs are attached. this all began about three days ago, the only new thing i can remember doing on my computer is using pandora, the music genome radio site, but i have many friends who have used this without problems, so i don't think that was it. also, a friend sent me a picture that i didn't scan before opening, but i was expecting it, but who knows, not me!

    i attached the mbam and sas logs, but it keeps telling me the me the mgtools zip folder is invalid
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are not supposed to be uploading the MGtools folder. You need to attach the C:\MGlogs.zip file.
     
  3. havalina

    havalina Private E-2

    i meant the file. the one i am trying to attach reads c:/mgtools/zip.exe

    its the only mgtools zip file i see, i don't know what i'm doing wrong, but obviously its something.
     
  4. havalina

    havalina Private E-2

    ok, so i found the mglogs.zip folder, but i see no .zip file. i'm attaching the one labeled hijack this. if you need one of the others, or if i've done something wrong still, let me know
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not what we asked you for. C:\MGlogs.zip does not equal C:\MGtools\zip.exe


    We don't want you to attach the hijackthis log or an other files from the MGtools folder. You are looking in the wrong place. The READ ME said the log will be in your root folder which is normally C:\MGlogs.zip
     
  6. havalina

    havalina Private E-2

    sorry, i figured out what i was doing wrong. hopefully this is the right folder.

    ps. i think its rather obvious i don't know much about computers, so please be patient, and thanks for helping.

    pps the pop-ups are happening more frequently now, it used to be like once every 5 or so pages and now its almost every time i open a new tab or window. when i run the super anti spyware, its better for a little while, but then it gets worse (and it seems to get worse quicker now)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java(TM) SE Runtime Environment 6 Update 1

    Now we will use Avenger to remove some files and registry entries. Note I'm removing all the copies of MGtools.exe that you put on your Desktop as they do not belong there per the READ ME.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\Temp
    C:\Users\Haley\AppData\Local\Temp\

    Now run Ccleaner!

    Now please download the current version of MGtools.exe (updated twice in the last 2 days) and this time save it to C:\MGtools.exe as requested in the READ ME.

    Now run the C:\MGtools.exe file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger ( c:\avenger.txt )

    Make sure you tell me how things are working now!
     
  8. havalina

    havalina Private E-2

    i did everything you said to, but i had some error messages. i assume the errors for avenger will be in the log, but when i tried to delete the c:\windows\temp folders and files, i couldn't delete JET7944.tmp because it was in use, even though all programs were closed, and i couldn't delete ~DF1469.tmp from c:\users...\temp for the same reason. also, whenever i download anything, it automatically goes to my desktop and i don't know how to change that, for the mgtools.exe. could you please let me know what i need to do for that? i am running vista if that makes any difference. i've attached the avenger log as requested, though i couldn't get it to upload from the c:\avenger.txt, so i saved it to the desktop and uploaded it from there. i can see the file in the upload manager screen, but it won't let me upload it. i don't understand why?

    things are always better after i run cc cleaner, but the problem will usually return after being online for a bit. i don't go to any unusual websites, i mainly just check my email, look on craigslist, and check my myspace. i mean, i do your basic surfing, but i don't dl games or look at videos (occasionally on youtube) or visit porn sites or anything like that. i've tried to pay attention to see if its after visiting one particular site that the problem returns, but as far as i can tell, its just random. all the pop ups have pc-on-internet in their addresses, or tracking something. i would tell you exactly what it is, but my history was deleted with cc cleaner. other than the pop-ups, my computer seems to be working fine, maybe a teensy bit slower, but i don't run any major programs, itunes and microsoft word are about it, so i don't know if i would even notice if it was slower. i use either mozilla or opera as a browser, i only use ie for netflix watchitnow.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds