Something keeps trying to connect me to sites

Discussion in 'Malware Help (A Specialist Will Reply)' started by thetada, Jun 4, 2008.

  1. thetada

    thetada Private E-2

    Hi,

    I have a problem with my computer and I would be really grateful, as I always am when I come to this site, if someone could help me.

    This concerns a Toshiba laptop, Intel CPU, 1.73Ghz, 1014 MB ram, 80GB hard drive. It runs Vista. I've carried out all the steps outlined in the clean up thread.

    The problem I'm having doesn't seem that serious but all the same, I don't want to assume it's not when it is, and anyway, it's bugging me. Basically, everytime I open Firefox, I get a series of windows popping up in the bottom right hand corner of the screen informing me that I'm trying to connect to various rogue sites. The sites have names like:

    myspacesurfer

    http://privacyinvisi.info/index.php?hl=f5&q=uggc://jjj.lnubb.pb

    http://57456345.info/index.php?hl=f5&q=uggc://jjj.lnubb.pbz

    Obviously I'm not trying to connect to them but even though my virus program (it's PC-cillin), spots these connection attempts, it's not clear to me whether it's actually stopping them, or if they're doing any damage, or could do.

    I'm attaching the logs. I didn't get a log from SAS because it didn't find anything.

    Thanks

    thetada
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested log from MGtools so that we can help you.
     
  3. thetada

    thetada Private E-2

    Sorry, got confused. Hope this is right.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have Spybot installed, but it appears that you may not have used the Immunize feature. Please run it now and Immunize your PC. Make sure you do not stop (TrendMicro may complain) it from Immunizing the hosts file.


    Please download and run the below tool since you still seem to have some of Nortons stuff installed:

    Norton Removal Tool (SymNRT)

    Then download the current version of FireFox from here: Mozilla Firefox Do not install yet.

    Then I want you to uninstall the current version of FireFox that you have installed. Then delete the C:\Program Files\Mozilla Firefox folder.

    Now reboot!!! After reboot, install the new version of FireFox.

    Are you still having problems?
     
  5. thetada

    thetada Private E-2

    Hi,

    I've done the steps you suggested but the pop ups are still there. What should I try next?
     
  6. thetada

    thetada Private E-2

    Sorry to write twice but the pop ups have become much more frequent, it used to be eight when I opened firefox and then no more but I've had about 40 this time and they keep coming back.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer all of the below questions:
    1. Do the popups occur if you use IE instead of FireFox?
    2. Do the popups occur if you boot in safe mode and run FireFox?
    3. Are the popups from your firewall? Can you post a snapshot of one (make sure it is legible. Only capture the popup not the whole screen).
    Please run this Using BitDefender Online Scan and attach the reuqested log. Follow the instructions properly. You should be renaming the HTML file into a text file so that it can be uploaded.
     
  8. thetada

    thetada Private E-2

    1. Do the popups occur if you use IE instead of FireFox?
    No
    2. Do the popups occur if you boot in safe mode and run FireFox?
    Yes
    3. Are the popups from your firewall? Can you post a snapshot of one (make sure it is legible. Only capture the popup not the whole screen).

    Yes, they're from my firewall / anti-virus program (PC-cillin, trend micro). I just realised I had that firewall on and the windows one as well, so I've switched off the windows one but I'm still getting the popups. I've posted one.

    Please run this Using BitDefender Online Scan and attach the reuqested log. Follow the instructions properly. You should be renaming the HTML file into a text file so that it can be uploaded.

    I've done that. I had to stop the first scan because it was taking so long so I've posted both logs, but the second one's empty. The first scan deleted three trojans, two were in Sunjava files. I've just switched to the newest Java, as per the Major Geeks instructions. Should I delete the program files folder for the older one?

    Thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That address is to some kind of proxy hosting company. Do you or anyone else using this PC use a proxy server? Is this a home PC or a company owned PC? Does Performance Systems International mean anything to you?


    Please do the below.


    Flush Java Cache


    Click Start > Control Panel and select Programs and double click the Java icon (be patient, it may take a while to open) Now click the General tab and under the Temporary Internet File area Click the Settings button and then click the Delete Files... button. In the next popup click OK.

    If you have multiple Java plugin icons in Control Panel follow the above to clear all their caches


    Flush FireFox Cache



    To flush your FireFox Cache:
    • click Tools
    • select Options
    • select Privacy
    • in the section labeled Private Data click Clear Now

    Flush Internet Explorer Cache



    To flush your Internet Explorer Cache:
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.
    Flush DNS Server

    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window




    Please run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below log
    • C:\MGlogs.zip
    Are you still seeing this popup in your firewall? When exactly does it happen? Does it happen only when FireFox is first open or does it happen at later times too? Does it happen as new tabs are opened? Does it happen with each site you goto? What Addons have you installed in FireFox?
     
  10. thetada

    thetada Private E-2

    That address is to some kind of proxy hosting company. Do you or anyone else using this PC use a proxy server? Is this a home PC or a company owned PC? Does Performance Systems International mean anything to you?

    Performance Systems Int doesn't mean anything to do me. The PC is mine, it's a home PC, however, I just bought it second hand. I bought it from a girl who doesn't strike me as the type to do anything like hacking. Can you have a proxy server built into your browser system? I've updated Firefox per your instructions so I guess I'd have to have set it up again to do so if you could. Anyway, I did notice the other day when I used Anonymouse that the Firewall didn't like it and gave me a pop up. That didn't bother me because I knew why it was happening but the others are a mystery.


    Are you still seeing this popup in your firewall? When exactly does it happen? Does it happen only when FireFox is first open or does it happen at later times too? Does it happen as new tabs are opened? Does it happen with each site you goto? What Addons have you installed in FireFox?

    I'm still seeing the popups. It happens only when I've just opened up Firefox, apart from the other day when I reinstalled Firefox, that time they were popping up all the time. now it's gone back to them only popping up just after I've started Firefox. There's usually eight or nine of them. It doesn't happen as new tabs are opened, or with each site I go to, it's only when I open Firefox. Addons wise I've got scribe fire, talkback, united states dictionary and yoono.

    Thanks
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Disable all of your FireFox AddOns and then see what happens.
     
  12. thetada

    thetada Private E-2

    SUCCESS!!!

    Thank you. What should I do now? Ditch all the addons? Because I'm rather partial to the Google Toolbar. Do I need to selectively prune them? Is Firefox no longer the browser of choice? Also, should I do a registry fix now that I've taken all these measures?

    Thanks again
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Enable them one at a time to see which one or which ones are the cause.

    There is nothing wrong with FireFox. Just like IE, when you allow things to be added onto the browser, you have to be aware of what you are adding and the effects. There is no real proof that anything is really wrong with the software causing your firewall popup. It could just be checking for a required update or it could be part of how the software works to get info. If you told you firewall to block that and always do the same thing, it should not be asking you all the time. If you did that, does the addon that is causing it still appear to work as desired?

    Not sure what you mean? A fix to what?
     
  14. thetada

    thetada Private E-2

    Okay, I meant should I use the registry function on CCleaner. I decided it probably wouldn't do any harm. Anyway, I think I can take it from here.

    Thanks as ever for your help and expertise.

    Stop a netizen from getting phished and he'll stay sane another day.
    Teach him not to get phished and he'll stave off [including but not restricted to] heart failure, high blood pressure, insanity... with only a modest amount of medication.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually we don't normally recommend doing this as stated in the READ & RUN ME where we say
    It is not that is necessarily a problem using the Issues tab, but it could be and in most cases it is better to not fix it if it is not broken. ;)


    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds