Persistent pop-ups...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by oneone, Oct 19, 2004.

  1. oneone

    oneone Private E-2

    Hello,

    I seem to be getting pop-ups even when I'm not in IE. I have tried all the malware/spyware removal programs and none have worked so far.

    Any help would be much appericiated.

    Many thanks.
     
  2. lschmidt

    lschmidt Private E-2

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you meant by " have tried all the malware/spyware removal programs".

    Please follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Also from the Alternate Scans section of the Read Me, run A-squared
     
  4. oneone

    oneone Private E-2

    Sorry if I was unclear, I meant that I had tried all the steps from the guide and they were still popping up.

    The problem that I get is that the pop up will minimize anything I'm in and then display itself. No popup blocker i've tried stops this, including the one from panicware.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run A-squared?

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  6. Saurabh

    Saurabh Private E-2

    Hi, I am having the same problems for two weeks now and am just fed up :mad: :rolleyes:

    i have also followed all the steps in the guidlines but they still keep popping up every 20 or 30 seconds. What is A-squared?

    can i post my Hijackthis log somewhere for you to review as well???

    please please help!!
     
  7. oneone

    oneone Private E-2

    I have run A-squared and my log file is attached.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run the Symantec online scan. It may have fix at least one of your problems.
    I'm working on your log now. I'll be back shortly.

    Do you recognize the URL in the below line:
    O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
     
  9. oneone

    oneone Private E-2

    No, I don't recognize that link.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
    O2 - BHO: (no name) - {480DF32B-9584-4490-BCB2-F39B59819CEC} - C:\WINDOWS\system32\geb.dll (file missing)
    O4 - HKLM\..\Run: [sysu] "C:\progra~1\ddm\sysu.exe"
    O4 - Global Startup: Search.vbs
    O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
    O15 - Trusted Zone: *.windupdates.com
    Boot into safe mode and use Windows Explorer to delete:
    C:\program files\ddm <---- the whole directory
    C:\Windows\Search.vbs or C:\Windows\system32\Search.vbs

    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. oneone

    oneone Private E-2

    OK, I did all of that but C:\program files\ddm was not there and neither was the search.vbs in any folders. I have no pop-ups yet but I have only been on for a few minutes, will let you know what's happened later on.

    My log is attached.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your current log looks okay, but in the future please remember all browsers must be shutdown when running HijackThis to scan and especially when fixing items with HijackThis. You had this running:
    C:\Program Files\Internet Explorer\iexplore.exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds