Getting supicious pop ups after 2 refromatts.

Discussion in 'Malware Help (A Specialist Will Reply)' started by harry hu ha, Aug 19, 2006.

  1. harry hu ha

    harry hu ha Private First Class

    Well the title almost says it all.

    For the past week I have been getting these pop ups on my computer that tell me that "windows has found 55 critical System errors" and to visit Blank Site. But the Window Does not look like an acual microsoft windows Window. It does not contain the word Microsoft, It has no mocrosoft or windows symbols, it Pops up ever 2-3 minutes, almost every time it pops up it tells me to visit a different site and install the sites software. (I Have not Visited or installed anything they have been telling me to install) The pop ups Slow my computer right down, Take up my bandwidth when trying to play "World Of Warcraft" , the pop ups have not stopped after 2 full formats. I have even changed from an old (Unregistered copy) of WIndows XP Pro. To a legit and registered version of Windows XP Home. and it's still sticking around.

    When I go to work I usually Leave my computer on and I usually work 8am-5pm And when I get home, There is 100+ pop ups of Different sizes and styles waiting on my desktop. I usually Exit each one individually and count them just for my personal records.

    Before I formatted the first time I installed Zone alarm Suite and Ran it. The pop ups were blocked but the Internet was still so lagged and stopped me from playing W.o.W. More than Half of the time I would have to unplug the modem and Router for roughly 30 seconds then Plug it back in in order to have an active internet connection.

    I am Using a router and Sharing an internet connection with a room mate and He has not had any problems at all. His internet is still as fast as ever, No Lag in Wow, And Most importantly NO POP UPS.

    I have ran bitdefender and Panda active scan and They both found stuff but it never solved the problem. I messed up by not Saving the BDscan report as Told and Hope that you can still view it in the .HTML format I accidently Saved it as.

    I'm really not sure what to do anymore. I have been avoiding the Computer all together because it just makes me so flustered and frusterated.

    Like I said I Have just freshly reformatted. I have only Downloaded the bitdeffender files, Panda files and Sunlife Java files I was told to in the sticky to remove malware. I have Installed my Sound card driver, lan driver (For the interenet, Off the motherboard drivers disc I got with the PC) and the drivers for my USB 2.0 Card (Also of the provided disc)

    There is nothing else on my computer. Yet the pop ups and lag will not stop!!!

    it's driving me mad. If anyone can help I'd really really Appreciate it. I'll do anything you tell me to and cooperate 100%.

    Thanks In advance.

    P.S. Here are the Reports from the two scans and a Screen shot of one of the many variations of the pop ups.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. If that does not help, you will need to complete ALL of the instructions below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. harry hu ha

    harry hu ha Private First Class

    Still got problems. Logs attached.

    OK So, I previously posted a thread saying that I was Getting supicious pop ups and even after 2 reformats they were still hapening. I was told to follow the read and run thread, Post all the logs from all the programs and then repost if i'm still having the problem. Well I'm still having the pop ups. There Driving me mental. I can't use my computer and every time I try it's just plain annoying.

    Please help me!!!!

    Attached are the logs from all the programs.
     

    Attached Files:

  4. harry hu ha

    harry hu ha Private First Class

    Re: Still got problems. Logs attached.

    Here's the second set of logs. There in no specific order. Sorry if there saposed to be.

    Also Heres the original thread I posted which includes a Screen shot of one of the many variations of the pop up.

    http://forums.majorgeeks.com/showthread.php?t=100238
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Still got problems. Logs attached.

    And you should have remained in your original thread. I'm merging you back.

    You have three problems!

    1) Delete this file C:\WINDOWS\system32\taskmanger.exe use safe mode if necessary.

    2) You biggest problem is that your system is WAY out of date with Windows Updates which is a major security risk. You MUST get updated.

    3) You have NO PROTECTION software installed. A very bad idea and it leaves you open to thousands of infections an messages like you are getting.
    • No antivirus
    • No antispyware blocking tool
    • No firewall
     
    Last edited: Aug 23, 2006
  6. harry hu ha

    harry hu ha Private First Class

    Well like I said, I just reformatted twice to try and solve this problem. Probably not the best solution but I didn't know what to do.

    I haven't updated yet because I wanted to solve this problem first, Before I install anything onto the Hardrive. But if updating will get rid of this problem then I guess I was wrong tonot update.

    Lastly, for the fire wall, anti virus, and Spyware blocker. The same goes for these as where I haven't installed them yet because of this problem I got. I was gonna wait and see what Happens with it before I load up my hardware with programs and documents. I'm accually really worried about this damn thing and refuse to do anything else other than what you suggest I do in order to get rid of this pest.

    But one thing i don't understand, is how did this "Intruder" Survive not only one, but two reformats? I even changed the operating system to Windows XP home. It's a 100% legal copy I recently purchased and everything I just don't get it.

    Also, I only get the pop up when the internet is connected to my computer. The other computer attached to the router, Using the same IP and everything has never had a problem. Both computers have been online playing World Of Warcraft together and mine lags like crazy and keeps the window keeps getting closed by this pop up. This is driving me mad!!!!

    But I'm gonna try updating windows, Deleting the Taskmanager.exe and installing Zone alarm suite. If all that doesn't solve my problem I'll probably be back here for another solution/suggestion.

    Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no intruder as far as I can see. The problem is that you have no protection, your OS is not updated and is unpatched, and every malware creator in the world loves PCs like this that are connected to the internet. They can find you in as little as a few minutes of first connecting and they will start sending garbage your way.

    A PC (whether brandnew, freshly formatted,....etc) should not be connected to the internet at all until at a minimum the below have already been installed:
    - antivirus application
    - firewall software (even if your router has a hardware firewall)
    - antispyware with Realtime blocking
    - SpywareBlaster with all protection enabled
    - Spybot with SDhelper and Immunize used

    Then as soon as you connect to the internet ALL Windows OS updates should be obtained and then updates for all the above software should be obtained.
     
    Last edited: Aug 23, 2006
  8. harry hu ha

    harry hu ha Private First Class

    First of all let me start off by saying thank you soo soo much.

    I have been on the internet for 10 minutes now and it has not givin me 1 pop up!!!!!!

    all I have done so far is update my windows fully and Delete the Taskmanager.exe. I will Install the rest of the programs you have mentioned and be on my marry way.

    I have been a member for a fair while now and You guys have always been so helpful. Thank you for everything you have done.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds