Popup website

Discussion in 'Software' started by b1jqxk44, Feb 19, 2015.

  1. b1jqxk44

    b1jqxk44 Specialist

    Every time I turn on my computer a website pops up. I downloaded a game from the site. I went to program files and deleted the internet short cuts from the game, but it still pops up.
    I've look at Firefox setting, but could not find it. what else can I try to get rid of this pop up.

    Asus (tower)
    AMD A8-5500 with Radeon HD Graphics 3.20 GHz
    Ram 6 GB
    Motherbroad: F2A85-M/CM1745/DP_MB
     
  2. b1jqxk44

    b1jqxk44 Specialist

    It can't be Malware, because I have MalwareBytes Premium 2.0.4 1028. MalwareBytes would have detected it when I downloaded it. I'll attach a log anyways. I'm sure it is a setting in Firefox which I'm over looking.
     

    Attached Files:

  3. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    What website pops up? I can see a popup when you open a browser but not when you turn on the computer unless something is set in startups that was not uninstalled. (That's why I don't add/remove programs; I use Revo Uninstaller to remove all the bits and pieces scattered all over the computer).
     
  4. b1jqxk44

    b1jqxk44 Specialist

    It's called "The one website.com". It pops up when my browser opens up.
    My browser automaticly open, because my apartment building has free WIFI and we have to log in. before I have internet access. Soon as I have access it pops up.

    I've been reading the Malware forum stickys all afternoon and doing what they told me to do, and it still pops up. So i'm sure it is not malware.
     
  5. b1jqxk44

    b1jqxk44 Specialist

    The same on IE
     
  6. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

  7. b1jqxk44

    b1jqxk44 Specialist

    I found the cause of the pop up and deleted it. It was HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer.exe\RunMRU. I only deleted the one key with
    The one website.com in it, and no more pop up.
     
  8. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Thing is while deleting a registry key from malware are you really sure you are free from malware??

    A trip via the read and run me + posting a thread in malware forum is advisable just to make sure, you maybe full free from what you have just done but, I personally wouldnt be, I would run multiple security apps and seek advice.
     
  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    I agree JoeRay12 and with plodr's link to a legit site from a search only aims more at malware. it may not be but you never know. Thing is not putting yourself in this malware position in the first place as in #2
     
  10. b1jqxk44

    b1jqxk44 Specialist

    I just did the read+run me for the third time now, and the same result nothing found, i'll post the results. I'm going to do a virus scan now and post it when done.
     

    Attached Files:

  11. b1jqxk44

    b1jqxk44 Specialist

    Here's the virus results.
    I'm going to read the read+run me again to make sure I didn't miss anything
     

    Attached Files:

  12. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Sadly application that you scanned with "may" not find all malware, hence the custom tools that the RRMF guide has, that where created by Chaslang, these dig deeper than traditional tools like AVG and MBAM, but need a expert eye to review them

    If I was worried by malware I would not fully trust a AIO scanner, I would trust an expert in malware removal as they not slight variances in log files to what should or should not be resident. While you may not now have malware visable, you may have a compromised link into your PC. This may just have been a browser hijack, seems strange on multiple browsers but never know.

    Personally I would RRMF and attach logs in the Malware forum for Chas, Tim, Emms et al to look over
     
  13. b1jqxk44

    b1jqxk44 Specialist

    I'll go thought the RRMF again post in the Malware Forums.
    The pop up came back. it looks like this.
     

    Attached Files:

  14. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Yeah looks like a browser hijacker and at times these cannot be removed by the normal AV apps, but need a bit of manual help, good luck in malware forum and I know the folks in there will sort you out.

    At times you can remove parts of these but there is one remaining bit that just recovers the hijack again, sneaky buggers.

    Thanks for the image that helps others and me in an ID of this.
     
  15. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Just as a thought and looking at this hijacker, do you have this folder c:\program files\theonewebsite.com

    also do you have c:\documents and settings\all users\start menu\programs\startup\home.url (Home url)?

    Delete both and look in add/remove but this does not negate using the RRMF and having the malware folk look at your logs as with one malware infection generally comes a few tailgaters.
     
  16. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Yes, now that I see the popup, I searched again and this hijacker has been around since 2009!
    I found these instructions from 2009
     
  17. b1jqxk44

    b1jqxk44 Specialist

    I deleted c:\programfiles\theonewebsite the other day. In c:\ Documents and Setting\.....\home.url had to drop the .url to delete that file. I shut down the computer and restarted it 5 times just to make sure. Thanks again plodr and DavidGP.
     
  18. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    I'd still head to the malware section and do all the scans and post results.

    Just because you got rid of this, it does not guarantee there isn't something else lurking in the computer.
     
  19. theefool

    theefool Geekified

    I didn't want to jump in here, but I will. Just because you think you got rid of the issue, doesn't prove that it is now gone. It is recommenced to be safe than having any future issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds