ASP Free Lounge
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsOtherASP Free Lounge

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old October 20th, 2005, 12:26 PM
Calldean's Avatar
Calldean Calldean is offline
Semi-Retired Geek
ASP Free Novice (500 - 999 posts)
 
Join Date: Mar 2005
Location: Liverpool
Posts: 681 Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 20 h 46 m
Reputation Power: 6
Bloody popups

Anybody got any experience of Firefox Popup problems?

Think it's some kind of spy/adware.

It was affecting IE as well as FF but I moved a few DLLs which I thought might have been casuing problems and that appears to have stopped the problem in IE but FF still has problems.

Most of the time it's sending me to: http://www.mega-cheap.com/normal/yyy34.html.

Virus/spyware scans show nothing, the PC isn't mine so I'm not sure what might have been installed - I've been told that nothing has been installed (Knowingly).

Have looked as msconfig and HiJack this and the services but nothing.

Nothing looks odd in the task mamnager so I'm a bit stumped.

It fires it up even when FF isn't loaded.

Oh and it also pops up some Flash adverts as well.

Anybody got any idea what it might be or where I could look next?

Cheers,

Dean

Reply With Quote
  #2  
Old October 20th, 2005, 01:33 PM
Doug G Doug G is offline
Grumpier Old Moderator
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Sep 2003
Posts: 10,143 Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 22 h 9 m 49 sec
Reputation Power: 181
Sounds like some virus, trojan, and/or spyware is on the computer. You can look over the task manager processes running and see if there is anything suspicious. Run complete antivirus scan, and multiple antispyware scans (using different antispyware programs). Try scanning in safe mode.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved of it. --Mark Twain

Reply With Quote
  #3  
Old October 20th, 2005, 02:24 PM
Calldean's Avatar
Calldean Calldean is offline
Semi-Retired Geek
ASP Free Novice (500 - 999 posts)
 
Join Date: Mar 2005
Location: Liverpool
Posts: 681 Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 20 h 46 m
Reputation Power: 6
Done all that and still can't find anything.

Tried a few spyware proggys but none of them are finding anything.

It's now trying to install WinFixer 2005

Reply With Quote
  #4  
Old October 20th, 2005, 02:52 PM
ublguy's Avatar
ublguy ublguy is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Jul 2005
Location: Milwaukee, WI
Posts: 483 ublguy User rank is Sergeant (500 - 2000 Reputation Level)ublguy User rank is Sergeant (500 - 2000 Reputation Level)ublguy User rank is Sergeant (500 - 2000 Reputation Level)ublguy User rank is Sergeant (500 - 2000 Reputation Level)ublguy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 5 Days 9 h 52 m 22 sec
Reputation Power: 13
Sounds like a good time to reformat and to start from scratch!
Comments on this post
RadioactiveFrog agrees: always a good solution
Calldean agrees: Looks like it's the way to go. :-(
__________________
Stop complaining about your life! Start making changes to make your life better!

Reply With Quote
  #5  
Old October 20th, 2005, 02:56 PM
jmurrayhead jmurrayhead is offline
Moderator
Click here for more information.
 
Join Date: Feb 2004
Location: Reston, VA, USA
Posts: 13,090 jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)jmurrayhead User rank is General 9th Grade (Above 100000 Reputation Level)  Folding Points: 84354 Folding Title: Advanced FolderFolding Points: 84354 Folding Title: Advanced FolderFolding Points: 84354 Folding Title: Advanced FolderFolding Points: 84354 Folding Title: Advanced FolderFolding Points: 84354 Folding Title: Advanced Folder
Time spent in forums: 3 Months 1 Week 6 h 17 m 27 sec
Reputation Power: 1580
Facebook
Quote:
Originally Posted by Calldean
Done all that and still can't find anything.

Tried a few spyware proggys but none of them are finding anything.

It's now trying to install WinFixer 2005


What programs have you used? I was able to clean up a similar problem using Spybot S& D, CrapCleaner and ZoneAlarm Security Suite.
Comments on this post
RadioactiveFrog agrees: Spybot S&D has always done it for me!
__________________
jmurrayhead

Did I help you out? Make me popular by clicking the icon!

New Members:Proper way to post a question

Powered by ASP.Net

Reply With Quote
  #6  
Old October 20th, 2005, 03:02 PM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
Senior Glowing Wizard
ASP Free God 7th Plane (8000 - 8499 posts)
 
Join Date: May 2005
Location: Sussex
Posts: 8,203 RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 4 Days 39 m 12 sec
Reputation Power: 291
Send a message via MSN to RadioactiveFrog
Facebook
Quote:
Originally Posted by jmurrayhead
What programs have you used? I was able to clean up a similar problem using Spybot S& D, CrapCleaner and ZoneAlarm Security Suite.
Spybot usually picks up most things for me. Have you updated it before running it? Also maybe post a HJT log here and see if anyone else can spot anything. There are some wiseguys on Devshed when it comes to HJT too.
Comments on this post
jmurrayhead agrees: Always good to post HJT where others can see. Might find something you missed

Reply With Quote
  #7  
Old October 20th, 2005, 03:11 PM
elijathegold's Avatar
elijathegold elijathegold is offline
Senior Fire Wizard
Click here for more information
 
Join Date: Feb 2005
Location: Ashford, Kent. England
Posts: 5,651 elijathegold User rank is Captain (20000 - 30000 Reputation Level)elijathegold User rank is Captain (20000 - 30000 Reputation Level)elijathegold User rank is Captain (20000 - 30000 Reputation Level)elijathegold User rank is Captain (20000 - 30000 Reputation Level)elijathegold User rank is Captain (20000 - 30000 Reputation Level)elijathegold User rank is Captain (20000 - 30000 Reputation Level)elijathegold User rank is Captain (20000 - 30000 Reputation Level)elijathegold User rank is Captain (20000 - 30000 Reputation Level)elijathegold User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4Folding Points: 1644464 Folding Title: Super Ultimate Folder - Level 4
Time spent in forums: 2 Months 2 Weeks 2 Days 4 h 7 sec
Reputation Power: 301
It might also be worth looking at rootkit revealer too.
http://www.sysinternals.com/Utiliti...itRevealer.html
Comments on this post
jmurrayhead agrees: Points I owe ya
__________________
And he picked it all up... in his pick-up.





Friends of Shemzilla

Reply With Quote
  #8  
Old October 20th, 2005, 03:41 PM
Calldean's Avatar
Calldean Calldean is offline
Semi-Retired Geek
ASP Free Novice (500 - 999 posts)
 
Join Date: Mar 2005
Location: Liverpool
Posts: 681 Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 20 h 46 m
Reputation Power: 6
Post

Tried SpyBot S&D, ZoneAlarm, Spyware Blaster, AVG Anti-Virus and Lavasoft AdAware plus one or two others that I can't rememeber.

I've checked the Program files for anyting iffy and can't find anything, have uninstalled everything I think shouldn't be there and still it keeps going.

Beginning to think that I do need to format and start again but must admit that I'm just being lazy. Seems a bit OTT for the problem but it is starting to get on my tits a bit to say the least.

I could almost put up with it if it weren't for the resizing of the window everytime it pops up.

Ahhh well; good format could get rid of any other "lingering" problems.

Cheers all,

Dean

Reply With Quote
  #9  
Old October 20th, 2005, 08:24 PM
Doug G Doug G is offline
Grumpier Old Moderator
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Sep 2003
Posts: 10,143 Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 22 h 9 m 49 sec
Reputation Power: 181
You could look at all the bootup processes with msconfig, and disable anything that looks suspicious.

Also turn off system restore and rescan. And if you're using IE try turning off the "allow third party browser extensions" setting.

Reply With Quote
  #10  
Old October 21st, 2005, 04:37 AM
Calldean's Avatar
Calldean Calldean is offline
Semi-Retired Geek
ASP Free Novice (500 - 999 posts)
 
Join Date: Mar 2005
Location: Liverpool
Posts: 681 Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 20 h 46 m
Reputation Power: 6
Already done the MSCOnfig thing.

Will have a look at the IE 3rd party though... didn't think of that.

Turned off Restore an age ago; hate it with a passion. More trouble tha it's worth!

Cheers,

Dean

Reply With Quote
  #11  
Old October 23rd, 2005, 02:44 AM
Shadow Wizard's Avatar
Shadow Wizard Shadow Wizard is offline
Moderator From Beyond
ASP Free God 45th Plane (27000 - 27499 posts)
 
Join Date: Sep 2004
Location: Israel
Posts: 27,230 Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 12nd Grade (Above 100000 Reputation Level)  Folding Points: 354621 Folding Title: Super Ultimate Folder - Level 1Folding Points: 354621 Folding Title: Super Ultimate Folder - Level 1Folding Points: 354621 Folding Title: Super Ultimate Folder - Level 1Folding Points: 354621 Folding Title: Super Ultimate Folder - Level 1Folding Points: 354621 Folding Title: Super Ultimate Folder - Level 1Folding Points: 354621 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 1 Week 6 Days 9 h 3 m 22 sec
Reputation Power: 1777
once virus get control, it can do whatever it want, including replacing real windows dll
files with its own files - usually such thing is not reversible. and anti virus programs won't
recognize it because the files are "real" by all means.

Reply With Quote
  #12  
Old October 23rd, 2005, 03:24 AM
Calldean's Avatar
Calldean Calldean is offline
Semi-Retired Geek
ASP Free Novice (500 - 999 posts)
 
Join Date: Mar 2005
Location: Liverpool
Posts: 681 Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level)Calldean User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 Days 20 h 46 m
Reputation Power: 6
Quote:
Originally Posted by Shadow Wizard
once virus get control, it can do whatever it want, including replacing real windows dll
files with its own files - usually such thing is not reversible. and anti virus programs won't
recognize it because the files are "real" by all means.


See what you mean but would have thought there would be another file which had to do the overwriting in the first place.

Reinstalled FF but that didn't do anything so if it was a virus which was overwriting DLLs I would have expected the reinstall to overwrite them again.... and because the problem has carried on I would have to assume that something has overwritten the DLLs again meaning that there is a detectable exe in there somewhere doing the overwriting. Knew I'd get there in the end.

Looks like I'm just going to have to go with the rebuild option as I've tried another two anti-virus and a few other bits and bobs and nothing is coming up with anything.

Whatever it is is a sneaky little bugger.

Cheers for all your help people.

Dean

Reply With Quote
Reply

Viewing: ASP Free ForumsOtherASP Free Lounge > Bloody popups