Can't Get Rid of this Pop Up

Discussion in 'Malware Help (A Specialist Will Reply)' started by stldirty, May 24, 2006.

  1. stldirty

    stldirty Private E-2

    every few minutes, no matter what i'm doing. a pop up comes up on my screen that looks like this.

    http://img.photobucket.com/albums/v139/stldirty/popupshit.jpg

    all the popups looks similar with that same "click here to open site" at the top. i've ran ad aware, spybot, online virus scanners, avg antivirus, ccleaner etc etc etc.

    i'm going to attach my hijack this log if it helps any
     

    Attached Files:

  2. stldirty

    stldirty Private E-2

    anyone?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, what is HBCUconnect? Are they your ISP? If so, you may need to blame them for popups!

    Note: I see Ares and Limewire running. They come bundled with malware. Supposedly new versions of Limewire are clean but P2P programs in general are not safe to use.
     
  5. stldirty

    stldirty Private E-2

    hbcuconnect is just a regular website. and yea. i uninstalled limewire. i left ares because i've had it forever w/o problems. and i'll get right to running those programs and posting the logs.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see that HBCUConnect is Historically Black Colleges & Universities

    But they do have annoying popups on there page that you need to click to have them hidden. This may not be your problem though. I think you have a LOP infection.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean you just uninstalled it now???

    See where Ares is list in the following: Spyware Info's Clean and Infected File Sharing Programs
     
  8. stldirty

    stldirty Private E-2

    hmm. i didn't have any problems until i installed limewire though. i think ad-aware had fixed anything that ares had installed. think i should uninstall ares too?
     
  9. stldirty

    stldirty Private E-2

    lop infection?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! As the link indicates, it come bundled with malware.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. stldirty

    stldirty Private E-2

    ok here's the deal. i ran everything. the bitdefender online scanner found 4 viruses and deleted them but some shit happened wit my browser that didn't allow me to save the log file. i remember one was in an mirc folder. all 4 were trojans though. i got the log from panda scan and hijack this though.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I expected, you have a bunch of LOP infections. You forgot to disable Spybot's Teatimer as mentioned in the READ ME. You really should not run this while having Windows Defender installed either. They will conflict with each other and cause excessive use of system resources. Also Spybot's Teatimer can make it very difficult to fix malware problems.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    You also did not disable the use of MSconfig per step 7 of the READ ME. We will fix this in the below procedure anyway.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [Junk Copy] C:\DOCUME~1\Jarett\APPLIC~1\MODE1L~1\Findplandefault.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\All Users\Application Data\name real bits bird <--- delete the whole folder
    C:\Documents and Settings\Jarett\Application Data\Curb Skip Proc <--- delete the whole folder
    C:\Documents and Settings\Jarett\Application Data\mode 1 list <--- delete the whole folder
    C:\Program Files\Support.com <--- delete the whole folder
    D:\Program Files\NetPumper <--- delete the whole folder
    C:\WINDOWS\launcher.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  14. stldirty

    stldirty Private E-2

    ok my teatimer was already disabled when i got there.

    but i did all u said and here's my updated hijack this log.
     

    Attached Files:

    Last edited by a moderator: May 26, 2006
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't quote messages unless really necessary to make comments on specific points. It just clutters the thread up and I don't need to see what I already posted.

    You forgot to answer my question:
    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds