traffic explorer

Discussion in 'Malware Help (A Specialist Will Reply)' started by phatdoughnut, Sep 7, 2005.

  1. phatdoughnut

    phatdoughnut Private E-2

    Well i just started getting serious pop ups again. one of them is this damn traffic explorer, and some other trojans. I ran through the "READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal" like always because i like to take care of problems my self, ran both of the online virus scans, i like bitdefender alot because it seems to find stuff that AdwareSE and spybot miss.

    I managed to kill 2-3 trojans and other BS stuff. butt i still keep getting this damn traffic exploere pop up. its annoying me some of the other pop ups dont even fully load when they pop up, just a blank page. i keep running through the "READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal " and the online scans, and they find nothing!!!

    The pop ups happen randomly.. sigh

    any suggestions?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below exactly:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. phatdoughnut

    phatdoughnut Private E-2

    So im not sure exactly how to shut down all the processes, i know i have alot open, is it just throught the task manager? cause im not sure exactly which ones to turn off if it is.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log shows no signs of any malware. This does not necessarily mean your system is clean. It just means you HJT log does not show anything.

    Are you still getting popups? When do you get them? All the time? What do they say? Do you only get them when connected to the internet? To what site or sites?

    Are you sure that they are not occurring due to the fact than you have Windows Messenger running? It has been know to cause popups?
     
  5. phatdoughnut

    phatdoughnut Private E-2

    never had pop up problem with etheir messenger.

    Pop ups happen randomly some times i get non, some times a bunch!, when i am on a couple of forums, but they dont support pop ups, when im searching google, surfing, ebay.

    I got a couple of them while doing bitdefender, they were anti virus ads.

    they are mostly Ads, car insurance, trips, poker games.

    I did i get this pop up with this lady? it look like a water/oil paint. i think it said virtumundo at the top? And so i ran the virtumundo sticky, and did a bunch of searches, and nothing!

    yeah so i dont know? im clueless
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you really use both Windows Messenger and MSN Messenger? It does not seem necessary to me.

    Let's try digging a little deeper.


    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Download this trial version of Ewido Security Suite
    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:

    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report

    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report. And tell me if you are still having any problems.

    After doing the above goto this link:
    How to Protect yourself from malware!

    Complete all the steps! Make sure you get one of the firewalls indicated installed.
     
  7. phatdoughnut

    phatdoughnut Private E-2

    :D now right now, when i clicked the malware link below, to download a firewall, got virus pop ups is that normal? :confused:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Did this occur before or after doing the Ewido scan and have you rebooted since doing the Ewido scan? And what do you mean by "virus popups". Do you mean you have virus detections or advertisements to by virus cleaning programs? What were they for?

    Now answer my question from message # 6.
     
  9. phatdoughnut

    phatdoughnut Private E-2

    I dont know what windows messenger is, but i do use msn messenger, and i also have AIM, thats how i keep in contact with family.

    And the pop ups accured after i rebooted, but they are advertisements for virus cleaning programs.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the below and let me know how things look. Note: Windows Messenger is not the same thing as MSN Messenger so you will not be doing anything to MSN Messenger with this:

    Disable/Remove Windows Messenger
     
  11. phatdoughnut

    phatdoughnut Private E-2

    what exactly does windows messenger do?

    i dl it and i ran it, and i havent had pop ups in like 2 days! i also downloaded sygate firewall, and its been blocking acouple of viruses or something that have been trying to DL themselves.. your the man once again!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Windows Messenger is install on all PCs by default and next to know one uses it because it caused all kinds of security issues like yours with popups. See this for example: http://www.itc.virginia.edu/desktop/docs/messagepopup/

    Tell me exactly what Sygate is blocking (include file and path names if given) also indicate whether it is outgoing or incoming.
     
  13. phatdoughnut

    phatdoughnut Private E-2

    sorry i thought it was sygate that was blocking that, but it was ewido doing the blocking and it keeps blocking this

    C:\WINDOWS\system32\svchost.exe
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is a valid Windows process. Ewido would not be blocking it. You could get popups from Sygate telling you about Generic Host Process requesting access to the network. It is not a problem. You can normally just say no to this and tell it to always say no.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds