searchmall link

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nkkraker, Jun 20, 2004.

  1. nkkraker

    nkkraker Private E-2

    Please help....I have downloaded and run adware spybot S&D...Cw shredder and finally the Hijack this program....I can not get away from this SearchMall Link website...The website keys in and highlights certain works like worm...virus...etc....and then if you click on the word it will take me to a site for Virus Hunter...The search mall link also highlights other words that take me to some not so nice websites....Please help.....I am including the results of my hijack this file....Please note I have deleted many times the files in hijack this that do say searchmall link....My restore computer is off......



    <SPAN style="FONT-SIZE: 9pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: 'MS Mincho'"><FONT face="Courier New">R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://thesearchmall.com/index.php
     
  2. TaLoN

    TaLoN Private E-2

    What is your OS?
    Is that your complete log?
    Have you rebooted your computer?
     
  3. nkkraker

    nkkraker Private E-2

    Sorry...I am using a windows XP system I have rebooted numerous times over the last three days and I have run all of the programs like listed in the forum....O am including the whole list again....



    <SPAN style="mso-fareast-font-family: 'MS Mincho'"><FONT face="Courier New">Running processes:
     
  4. TaLoN

    TaLoN Private E-2

    my logs look like this:

    Logfile of HijackThis v1.97.7
    Scan saved at 12:41:31 PM, on 6/21/2004
    Platform: Windows XP SP2, v.2149 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2149)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    c:\Program Files\Norton AntiVirus\navapsvc.exe
    c:\Program Files\Norton Personal Firewall\NISUM.EXE
    C:\WINDOWS\system32\S3tray2.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trillian\trillian.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 5 for hijackthis.zip\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
    O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


    what does it say is your default page?
    open Hijack This
    click on the config
    click om the main

    are you up to date?
    click on the misc tools
    click update
     
  5. nkkraker

    nkkraker Private E-2

    Talon,


    I appreciate any help you can give me...My default start page is www.optonline.net I now have been re hijacked by www.all about searching...I have adware spybot search and destroy spy sweeper and I am using the Trend Micro system anti virus...Oh yeah I have now downloaded Stopzilla to stop pop ups.....I am a little frustrated and may throw the computer in the fireplace....
    I am completely up to date and I am now sending you the newsest version of my hijack this file.... Please help.....
    .
    ogfile of HijackThis v1.97.7
    Scan saved at 9:31:13 PM, on 6/21/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\STOPzilla!\szntsvc.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Softex\OmniPass\Omniserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
    C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
    C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
    C:\Program Files\Softex\OmniPass\OPXPApp.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
    C:\Program Files\Logitech\ImageStudio\LogiTray.exe
    C:\WINDOWS\System32\LXSUPMON.EXE
    C:\Program Files\OfferApp\OfferApp.exe
    C:\Program Files\Trend Micro\Internet Security\pccguide.exe
    C:\Program Files\STOPzilla!\Stopzilla.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
    C:\WINDOWS\TEMP\Rem14.exe
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 9 for hijackthis.zip\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = allaboutsearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\SZIEBHO.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: ThunkGreyWindow - {83ECDCC0-3699-7A71-601E-41B3FEAAA992} - C:\PROGRA~1\ITCHTE~1\debug type.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
    O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
    O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -tray
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [OfferApp] C:\Program Files\OfferApp\OfferApp.exe
    O4 - HKLM\..\Run: [fwpvjdxuj] C:\WINDOWS\System32\gtuiwwa.exe
    O4 - HKLM\..\Run: [mxkhenwp] C:\WINDOWS\mxkhenwp.exe
    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
    O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
    O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
    O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
    O4 - HKLM\..\Run: [for store] C:\PROGRA~1\exitlicense\Copy Drive Extra.exe
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
    O4 - HKCU\..\Run: [MProcessor] "C:\Program Files\\MProcessor\mprocessor.exe"
    O4 - Startup: Compaq Organize.lnk = ?
    O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
    O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
    O9 - Extra button: MoneySide (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
     
  6. TaLoN

    TaLoN Private E-2

    I'll get back to your log

    I am not sure on how up to date you are on XP

    service pack 2 as a pretty impresive firewall and pop up blocker
    get it here:
    http://www.majorgeeks.com/download4169.html

    but, click start>run type msconfig click ok
    click the start up

    make sure there is nothing out of place
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    nkkraker,

    You need to run this Peper Trojan removal tool:
    http://www.memorywatcher.com/uninst.exe
    Also run this online scan: http://housecall.trendmicro.com/housecall/start_corp.asp


    Shut down all applications and run HijaakThis again and have it fix:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = allaboutsearching.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: ThunkGreyWindow - {83ECDCC0-3699-7A71-601E-41B3FEAAA992} - C:\PROGRA~1\ITCHTE~1\debug type.dll
    O4 - HKLM\..\Run: [fwpvjdxuj] C:\WINDOWS\System32\gtuiwwa.exe
    O4 - HKLM\..\Run: [mxkhenwp] C:\WINDOWS\mxkhenwp.exe
    O4 - HKLM\..\Run: [for store] C:\PROGRA~1\exitlicense\Copy Drive Extra.exe
    O4 - HKCU\..\Run: [MProcessor] "C:\Program Files\\MProcessor\mprocessor.exe"


    Do you know what OfferApp is? I get mixed messages searching on it.
    Some ignore it. The other half say delete it. I would remove
    O4 - HKLM\..\Run: [OfferApp] C:\Program Files\OfferApp\OfferApp.exe


    You need to boot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam

    Now delete the following:

    C:\WINDOWS\TEMP\Rem14.exe
    C:\PROGRA~1\ITCHTE~1\debug type.dll
    C:\WINDOWS\System32\gtuiwwa.exe
    C:\WINDOWS\mxkhenwp.exe
    C:\PROGRA~1\exitlicense\Copy Drive Extra.exe

    Delete the below too if you decided to get rid of OfferApp stuff:
    C:\Program Files\OfferApp\OfferApp.exe

    Reboot in normal mode and run, UPDATE, and scan with Ad-aware and Spybot (BE SURE TO UPDATE FIRST).
     
  8. nkkraker

    nkkraker Private E-2

    Chaslang,


    I have done everything you asked and still the first line keeps coming back R01 all about searching.... Please take another look at my log file this is from this evening.

    Thank you so much for your help......
    Logfile of HijackThis v1.97.7
    Scan saved at 9:56:13 PM, on 6/23/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\STOPzilla!\szntsvc.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Softex\OmniPass\Omniserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
    C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
    C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
    C:\Program Files\Softex\OmniPass\OPXPApp.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
    C:\Program Files\Logitech\ImageStudio\LogiTray.exe
    C:\WINDOWS\System32\LXSUPMON.EXE
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\Program Files\Trend Micro\Internet Security\pccguide.exe
    C:\Program Files\Trend Micro\Internet Security\PCClient.exe
    C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
    C:\Program Files\STOPzilla!\Stopzilla.exe
    C:\PROGRA~1\EXITLI~1\Copy Drive Extra.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 14 for hijackthis.zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = allaboutsearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
    O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
    O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
    O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
    O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
    O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -tray
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
    O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
    O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
    O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
    O4 - HKLM\..\Run: [for store] C:\PROGRA~1\EXITLI~1\Copy Drive Extra.exe
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Startup: Compaq Organize.lnk = ?
    O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
    O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
    O9 - Extra button: MoneySide (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you deleted this line:
    O4 - HKLM\..\Run: [for store] C:\PROGRA~1\EXITLI~1\Copy Drive Extra.exe

    and then deleted the file after booting in safe mode. If you are sure, do it again but this time delete the whole directory: C:\PROGRA~1\EXITLI~1

    Also, again have HijaakThis fix this:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = allaboutsearching.com

    The go to Internet Explorer, Tools, Internet Options, Programs tab and select Reset Web Settings. Then go back to the General tab and select Delete Cookies. Then select Delete Files and in the popup window enable deletion of all offline content too. Then click OK. While still on the General tab set your home page to something useful (like www.majorgeeks.com). Click Apply and OK. Let's see if this helps. If this does not resolve the problem then take a look at this link which states that allaboutsearching supplies an uninstaller for their search engine and their toolbar:
    http://www.kephyr.com/spywarescanner/library/allaboutsearching/index.phtml


    The next line has changed. It used to show C:\WINDOWS\System32\SZIEBHO.dll where it now shows no file. I believe this is part of StopZilla which you appear to be using. What happened here?
    O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
     
  10. nkkraker

    nkkraker Private E-2

    Chaslang,

    I can't begin to thank you enough. My problem is fixed and with any luck I will remain free of these stupid hijackiing websites.... I did load the Stopzilla but it does not seem to do much for blocking popups.I am considering un installing this. My trend micro system anti virus program catches alot of websites but then puts up the system alert. I don't see a button anywhere for silencing this? It does not block pop ups?

    I would appreciate if you could recomend a pop up blocker? Preferably, free of course?

    Once again, thank you for your help over the past week and a half....I would never have been able to do this myself....

    The internet has now become worse then telemarketers that used to call the house. We need to do something about this?

    Thanks again,
    NKKRAKER
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome! I don't use any popup blockers so I do not really have a preference or know which are considered the best. I know some people make use of toolbars like Google as an addon to Internet Explorer to block popups. I personally do not want any of these toolbars. Here are a couple of free popup blockers available on MG's:

    Pop-Up Stopper Free Edition: http://www.majorgeeks.com/download457.html
    Smart Popup Blocker: http://www.majorgeeks.com/download4213.html

    You could also try a browser with built in popup blocking. Many people here on MG's like:

    MyIE2 Combo: http://www.majorgeeks.com/download1244.html
    or
    MyIE2 Lite: http://www.majorgeeks.com/download1167.html
    or
    Avant Browser: http://www.majorgeeks.com/download2346.html
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds