Random Popups

sk84zer0sk84zer0 Join Date: 2003-06-18 Member: 17478Members
<div class="IPBDescription">i cant stop them!</div> I just recently got a trojan, which i deleted as fast as possible it was succesfully healed but i kept getting these annoying popups randomly. I then ran Adaware(current version) it found 81 items so i thought that would stop the popups but it didnt. I still get these popups randomly, i probably wouldnt care so much if it didnt come up while playing ns which causes me to lose sound <!--emo&:(--><img src='http://www.unknownworlds.com/forums/html/emoticons/sad.gif' border='0' style='vertical-align:middle' alt='sad.gif'><!--endemo--> . As my virus scanner i use AVG 6.0. Can someone help me get rid of these?

btw: I have also tried this...<a href='http://www.auburn.edu/oit/security/messengerService.html' target='_blank'>http://www.auburn.edu/oit/security/messeng...gerService.html</a>

Comments

  • MulletMullet Join Date: 2003-04-28 Member: 15910Members, Constellation
    <a href='http://www.safer-networking.org/' target='_blank'>Spybot</a> is by far the best program for getting rid of any kind of spyware.... Use this and check for updates, then scan. I'm positive it will work.
  • [WHO]Them[WHO]Them You can call me Dave Join Date: 2002-12-11 Member: 10593Members, Constellation
    When you ran AdAware, did u update the definitions first ? Did you also follow it's instructions for those pesky ones that require a reboot to fix ?

    If all else fails. Try running all these tools while in safe mode from a burned cd (read only coolness).
  • ZelZel Join Date: 2003-01-27 Member: 12861Members
    messenger ones will always look like windows error messages, default colors, etc. to kill them go to controlpanel->administrativetools->services->messenger and change it to manual/stopped. be careful with those services though, dont kill the wrong one!

    adaware and antivirus software doesnt catch some of the newest evilware, a kern32/wowex32 virus. if you see kern32 in your taskmanager, do a search, cuz itll take a while to kill!
  • DragonMechDragonMech Join Date: 2003-09-19 Member: 21023Members, Constellation, Reinforced - Shadow
    I use <a href='http://www.mozilla.org/products/firebird/' target='_blank'>Mozilla Firebird</a> as a browser. I never have any popups, and MF is generally much better than IE.
  • Boy_who_lost_his_wingsBoy_who_lost_his_wings Join Date: 2003-12-03 Member: 23924Banned
    <a href='http://www.unknownworlds.com/forums/index.php?act=ST&f=10&t=25354' target='_blank'>http://www.unknownworlds.com/forums/in...ST&f=10&t=25354</a>

    gg
  • sk84zer0sk84zer0 Join Date: 2003-06-18 Member: 17478Members
    The arent popups from websites, they are <b><i><u><span style='color:red'>RANDOMLY</span></u></i></b>. And i have tried both what [WHO]Them, and Mullet said and neither worked.
  • JimmehJimmeh Join Date: 2003-08-24 Member: 20173Members, Constellation
    Try this which i had to do myself before:

    1) Uninstall IE
    2) Scan using Spybot + Adaware
    3) Reinstall IE

    Should work

    Also, after reinstalling IE, go and use Firebird
  • RellixRellix Join Date: 2003-02-15 Member: 13572Members, Constellation, Reinforced - Shadow
    Try getting the google toolbar from google.com it has worked wonders for me and now I only get the addware ones hidden deep in my cookies nad inner HD.
  • X_StickmanX_Stickman Not good enough for a custom title. Join Date: 2003-04-15 Member: 15533Members, Constellation
    It sounds kinda like a thing i had.... i made a thread about it:

    <a href='http://www.unknownworlds.com/forums/index.php?act=ST&f=10&t=54372&hl=trojan' target='_blank'>http://www.unknownworlds.com/forums/in...54372&hl=trojan</a>

    I remember finding some stuff (from the fact that it ran a dos-prompt thingy every time i switched on, it was on and off really quick, on a faster computer you might not even notice it), and deleting it, then running every virus checker i had, but i ended up moving over to XP anyway.
  • esunaesuna Rock Bottom Join Date: 2003-04-03 Member: 15175Members, Constellation
    Probably not this, but some P2P programs, for example iMesh, have inbuilt popups which have a habit of showing up if the program is minimised. As far as i know it's an intergrated part of the program and not a seperate piece of ad software.
  • ZelZel Join Date: 2003-01-27 Member: 12861Members
    yes esuna, but i was uner the impression that adaware caught those from kazaamediadesktop.

    i had a similar problem a few days ago. a peice of spyware that adaware didnt catch was downloading and installing a new spyware program every hour, and opening popups to sandboxer.com and 2ndthought.com every ten minutes or so. i scanned when i was leaving for work and it found and cleaned 67 spywares, then when i got home six hours later there were three new programs installed and adaware found 96 more! no one had touched any webpage.

    it turned out to be a new spyware called the peper trojan, or wowex32 trojan. i doubt its a real trojan because my up to date virus scanner doesnt see it, and adaware couldnt either, but do a search and youll find lots of info about it, it is a nasty self propagating one. dont kno how it got in, because i am generally very careful about clicking yes on such things...
  • NiteowlNiteowl Join Date: 2002-09-04 Member: 1274Members, NS1 Playtester, Contributor
    what sort of popups? IE popups? or MSN Messenger popups? the latter can be stopped by going into MSN options and not allowing ppl who are not on your contact list from msging you.
  • sk84zer0sk84zer0 Join Date: 2003-06-18 Member: 17478Members
    i just ran the "housecall" virus scan, and it found the virus!(or so i think <!--emo&:0--><img src='http://www.unknownworlds.com/forums/html/emoticons/wow.gif' border='0' style='vertical-align:middle' alt='wow.gif'><!--endemo--> ) but the problem is that i cant delete/clean it. Now i just need help getting rid of it <!--emo&:(--><img src='http://www.unknownworlds.com/forums/html/emoticons/sad.gif' border='0' style='vertical-align:middle' alt='sad.gif'><!--endemo-->

    Here is a screenie i took when housecall tried to clean/delete the virus. I have the Windows Task Bar to the right to show that the file name isnt in the proccess area, and i also tried searching for the virus(bottom right corner) and it showed as nothing <!--emo&:angry:--><img src='http://www.unknownworlds.com/forums/html/emoticons/mad.gif' border='0' style='vertical-align:middle' alt='mad.gif'><!--endemo-->

    And yes i do have aol(gonna get rid of it soon) but please...dont flame me for having the worst internet ever just help me get rid of the virus <!--emo&:(--><img src='http://www.unknownworlds.com/forums/html/emoticons/sad.gif' border='0' style='vertical-align:middle' alt='sad.gif'><!--endemo-->
  • sk84zer0sk84zer0 Join Date: 2003-06-18 Member: 17478Members
    oh and this is where the virus is....

    C:\Documents and Settings\customer\Local Settings\Temporary Internet Files\Content.IE\0HAVG5QR\ClrSchP038[1].exe
  • XiileXiile Join Date: 2003-02-22 Member: 13818Members
    There's this proggie a friend gave me on CD called PestPatrol. It worked wonders, much better then all the other oneseses.

    And you might want to look for RegSupreme.
  • XiileXiile Join Date: 2003-02-22 Member: 13818Members
    <!--QuoteBegin--sk84zer0+Jan 6 2004, 07:35 PM--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (sk84zer0 @ Jan 6 2004, 07:35 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> oh and this is where the virus is....

    C:\Documents and Settings\customer\Local Settings\Temporary Internet Files\Content.IE\0HAVG5QR\ClrSchP038[1].exe <!--QuoteEnd--> </td></tr></table><span class='postcolor'> <!--QuoteEEnd-->
    Sorry for the doublepost.

    That program's called Clear Search. It's a spyware program loaded on your computer from popup ads. I believe Clear Search might have a website you can download an uninstaller from.
  • sk84zer0sk84zer0 Join Date: 2003-06-18 Member: 17478Members
    I have downloaded RegSupreme before but it says it is very dangerious. I asked the guys over at #nspt if they could help me, and they said not to use it if i wasnt very good with working on computers.

    I am a computer nub
  • sk84zer0sk84zer0 Join Date: 2003-06-18 Member: 17478Members
    ^bump^

    please, i need to get rid of these popups <!--emo&:(--><img src='http://www.unknownworlds.com/forums/html/emoticons/sad.gif' border='0' style='vertical-align:middle' alt='sad.gif'><!--endemo-->
  • SkulkBaitSkulkBait Join Date: 2003-02-11 Member: 13423Members
    edited January 2004
    try searching your registry using regedit for that location string. If you can't find it, look for the "Run" "RunOnce" and such entries and delete anything suspicious in them. Also run MSCONFIG (don't know if that is in xp...) and deselect suspicious entries under "startup". And if that doesn't work, since MS never gave you a way of accessing your NTFS files from a DOS floppy, try something like <a href='http://www.knoppix.org' target='_blank'>Knoppix</a> and just delete the file. NTFS write support under linux is still a tad bit buggy IIRC, but it should work for this.
  • ZelZel Join Date: 2003-01-27 Member: 12861Members
    come on people its not that hard.

    reboot to safemode so that nothing loads then empty your internet cache because thats where the file was found. the internet cache of the user named customer.

    windows search didnt find it because it stupidly ignores temp folders. really. its stupid.

    to get to safemode, reboot and hit f8 a bunch of times before windows comes up and itll give you a menu and you just pick safemode. everything will look junky, but thats okay, its supposed to, and your networking wont work in safemode either so dont expect to use trendmicro housecall. just clear the internet cache because thats the only one housecall found, and run whatever spybot or adaware again.
  • SwiftspearSwiftspear Custim tital Join Date: 2003-10-29 Member: 22097Members
    memorize the file location (or wright it down) get a dos boot disk, and delete it from dos. All the crazy windows stuff that windows wont let you delete can be deleted from dos.
Sign In or Register to comment.