Please help!!!

O

Oort Cloud

As soon as I open Firefox or IE I'm getting separate instances of those
browses popping up with all kinds of websites (non-porn). I ran Kaspersky
Antivirus and AdAware a few times. They didn't find anything, and they won't
intercept any of those windows. What do I do? I'm at the end of my wits.
Please help!!!

Serge
 
P

Patrick Keenan

Oort Cloud said:
As soon as I open Firefox or IE I'm getting separate instances of those
browses popping up with all kinds of websites (non-porn). I ran Kaspersky
Antivirus and AdAware a few times. They didn't find anything, and they
won't
intercept any of those windows. What do I do? I'm at the end of my wits.
Please help!!!

Serge

Your system is infected.

There are other things loading that just aren't being found. It can be a
little tricky to find these, and you may need help that sits in the chair.

You will use tools that start with HijackThis and ProcessExplorer and
ccleaner - you want to remove all temp files first with ccleaner, for all
user accounts.

And, it's best if you disconnect the system from the network first, as many
of these things detect the network. So you'll need to have another system
at hand to look at the results.

HTH
-pk
 
P

PA Bear [MS MVP]

Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315

Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/page2.html#Removing_Malware

When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use (in
conjunction with some other utilities). HijackThis will NOT fix anything on
its own, but it will help you to both identify and remove any
hijackware/spyware with assistance from an expert. **Post your log to
http://spywarehammer.com/simplemachinesforum/index.php?board=10.0,
http://forums.spybot.info/forumdisplay.php?f=22,
http://aumha.net/viewforum.php?f=30, or another appropriate forum for review
by an expert in such matters, not here.**

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA or Geek Squad) computer repair shop.
 
K

Kayman

As soon as I open Firefox or IE I'm getting separate instances of those
browses popping up with all kinds of websites (non-porn). I ran Kaspersky
Antivirus and AdAware a few times. They didn't find anything, and they won't
intercept any of those windows. What do I do? I'm at the end of my wits.

1.Clear the (IE) temporary Internet files and the history cache.
Click Start==>Run... then type (or copy/paste) "inetcpl.cpl" (w/out
quotation marks) into the box, then click the 'OK' button.
In Internet Properties panel 'General' tab, under 'Browsing history', click
'Delete...'button, in 'Delete Browsing History' panel, click the 'Delete
all...'button then place a checkmark into the box beside 'Also delete files
and settings stored by add-ons', Click 'Yes' and exit the Internet
Properties panel by clicking the 'OK' button.

2.Clean HDD
Click Start==>Run... then type (or copy/paste) "cleanmgr" (w/out quotation
marks into the box, then click the 'OK' button. Select your drive
(presumably WinXP (C:) and click OK.

3.Download/execute:
Malwarebytes© Corporation - Anti-Malware
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
--and--
Kaspersky® AVPTool
http://avptool.virusinfo.info/en/
Direct:
http://downloads5.kaspersky-labs.com/devbuilds/AVPTool/
--and--
Dr.Web CureIt!® Utility - FREE
http://www.freedrweb.com/cureit/
--and--
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

NOTE:
Kaspersky® Virus Removal Tool, Dr.Web CureIt!® and the free version of
Malwarebytes© and SuperAntispyware are not capable for real-time protection
of your computer.
Kaspersky® AVPTool, Dr.Web CureIt!® have no update feature (so they don't
turn into full blown scanners). As soon as your computer is cleaned you are
supposed to remove these tools from your operating system.
Re: K/AVPTool; To uninstall/move this program 'enable self-defense' must be
unchecked!

The free version of Malwarebytes© and SuperAntispyware have an update
feature, keep them installed in addtion to your resident AV/A-S
applications and scan frequently.

After the software is updated, it is suggested scanning the system in Safe
Mode.
How do you boot to Safe Mode?
By pressing/tabbing F8 (or F5 on some keyboards) during re-boot.
A description of the Safe Mode Boot options in Windows XP
http://support.microsoft.com/default.aspx?scid=315222
Start your computer in safe mode (Vista)
http://windowshelp.microsoft.com/Windows/en-us/help/323ef48f-7b93-4079-a48a-5c58eec904a11033.mspx
http://www.bleepingcomputer.com/tutorials/tutorial61.html

Alternatively:
Click Start==>Run... then type (or copy/paste) "msconfig" (without
quotation marks), click OK. Then click onto BOOT.INI tab and 'check'
/SAFEBOOT then OK and click Restart. To go back to Normal Mode, you must
access the System Configuration utility again and click the General tab
then click/check the radio button 'Normal Startup'- load all device drivers
and services'.

4.Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

Please, do not post HJT logs to this newsgroup.
Fora where you can get expert advice for HiJack This! (HJT) logs.

http://www.thespykiller.co.uk/index.php?board=3.0
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.tomcoyote.org/index.php?showforum=27
http://www.bleepingcomputer.com/forums/forum22.html
http://www.malwarebytes.org/forums/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://www.theeldergeek.com/forum/index.php?s=2e9ea4e19d3289dd877ab75a8220bff6&showforum=29

NOTE:
Registration is required in any of the above mentioned fora before posting
a HJT log and read the 'stickies' (instructions/guidelines) for the
respective HJT forum.

5.Routinely practice Safe-Hex.
http://www.claymania.com/safe-hex.html

Good luck :)
 
O

Oort Cloud

Thanks everybody for your help.

I fixed my prob in a very simple way. I downloaded ComboFix, ran it, and the
little proggie fixed everything in about 20 min. It deleted about 90 files
from my computer that were somehow created bt the malware/virus. It also
fixed the registry, deleting all the bad entries: MS Juan and such. The
funny thing is I scanned my whole puter with latest Kaspersky AV and AdAware
2007, and Elite Trojan Remover. None of these spotted anything. They were
practically useless. I'm very disappointed in Kaspersky especially.
 
P

PA Bear [MS MVP]

[Sure hope you didn't purchase "Anti Trojan Elite"! If you did, you wuz
robbed.]
 
G

Galen Somerville

Oort Cloud said:
As soon as I open Firefox or IE I'm getting separate instances of those
browses popping up with all kinds of websites (non-porn). I ran Kaspersky
Antivirus and AdAware a few times. They didn't find anything, and they
won't
intercept any of those windows. What do I do? I'm at the end of my wits.
Please help!!!

Serge

Just about every message is asking for help. Think how it would look if all
of them used the Subject "Please help"

Galen
 
S

Snidley W.

Galen Somerville said:
Just about every message is asking for help. Think how it would look if all
of them used the Subject "Please help"

They would look a lot like the ones with the Subject "XP"
 
O

Oort Cloud

No. I borrowed it from a friend, since my AdAware and kaspersky were not
able to fix anything.
 
B

Bo

I wouldn't have to recall anything if OP had quoted the post to which (s)he
was replying.

It had only been about six hours since you wrote it. WTF!?

Yeah, I know... I'm getting old too.
Bo said:

You don't recall?...

"[Sure hope you didn't purchase "Anti Trojan Elite"! If you did, you
wuz robbed.]"
Oort Cloud wrote:
No. I borrowed it from a friend, since my AdAware and kaspersky were not
able to fix anything.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top