Popup hell !

P

popup hell

I had been running the google toolbar with the popup blocker with
great results for months. All of a sudden in the last few weeks I
noticed a new breed of popup begin to intrude itself. These new
popups are fullsized windows that someone get past google's popup
blocker. The real kicker is in the last few days they have started
hijacking my browser, redirecting it away from the page I am currently
browsing towards an advertisement page. So in effect I get a full
sized popup window, I get my main browser window redirected, and I
often get yet another popup all at the same time. In the last two or
three days it's gotten much worse, and often I can't even open
legitimate windows at the sites I'm browsing because they immediately
get hijacked and I can't retrieve the information from those sites I
want to use. The moment I try to open a legitimate window some ad
company wants to use it. This is really scary! Help...
 
J

jopa66

You know - the irony of it is: "How can these advertisers even expect to
sell anything to the people that they have thoroughly pissed-off?" I'll quit
right here before I get up on the soap-box about advertising. Anyway, here's
what you do.

First:
I suggest you start by going here:
http://forums.spywareinfo.com/index.php?showtopic=227

The folks there at Spywareinfo have a lot of experience in dealing
Hijackers/Spyware/Malware. There is no charge for the help and information
available but, they do request donations. Read that first page carefully,
and following its instructions you will download a little program called
Hijackthis. Its purpose is simply to scan your computer and generate a log
of everything that is running at that moment. It does not decide what is
Good or Bad. That's what the experts at Spywareinfo will do. So *DO NOT*
just arbitrarily start deleting what it finds.

Next:
Set up a user account at Spywareinfo and post your LOG there, not here.
There are many experts on that forum and someone will analyze it and let you
know if anything is amuck and what you can do to fix it.

You always want to keep your virus definitions up-to-date, as well as use
tools like Spybot and Ad-Aware which also must be kept up-to-date every time
*before* you use them to scan your machine.

Spybot FREE
http://www.safer-networking.org/en/index.html

Ad-Aware FREE & Pro
http://www.lavasoftusa.com/software/adaware/

If you need a good FREE antivirus try AVG at
http://www.grisoft.com/

This may sound like a lot of work and it is. And there's still no guarantee.
But, you'll learn a whole lot in the process and have a much more secure
computer.
 
K

KAS

First, make sure that Messenger Service is turned off on
your system if you are running 2000 or XP. Second, follow
the directions below to rid yourself of any spyware/malware
you may have. Third, use a different browser such as
Firefox or Opera which have built-in pop up blocking
capabilities and are more standard compliant.

Disconnect your compter from the net if you have a
high-speed connection such as cable or dsl.

1) Go to Add/Remove Programs and look for programs that
shouldn't be there. Things such as Hotbar Toolbar, Gator,
etc. These programs should stand out in your mind as ones
that you did not install.

Write down the names of these programs then go ahead and
use Add/Remove to remove them. This WILL NOT completely
remove the program but begins the process.

2) Go onto your hard drive and look for folders which have
the same or similar names to the programs you just wrote
down. Look under C:\Program Files for these folders.

Delete these folders. In some cases you may not be able to
remove the entire folder or parts of their contents. That
is ok. Just be sure that what you are removing is what you
want to remove. If in doubt, leave it in.

3) Go to Start | Run and type in 'regedit' (no quotes).
When your registry comes up do Ctrl-F (Find) and type in
part of the name of one of the programs you are looking
for. For instance, if you have the Hotbar Toolbar you
could simply type in 'hotbar' (no quotes). Click Find Next
and the search begins. When it stops on an entry look at
it closely. Does it have the name of one of the programs
you are looking for? If so, delete that key. Hit F3 to
continue the search.

When you get the message that you are at the end of the
registry do Ctrl-F and repeat the process for the next
piece of spyware/malware. Repeat as necessary.

4) Reboot your machine. When you come back in see if you
can reset your homepage or access the net. Hopefully at
this point you can. If your homepage still won't reset you
need to go back into the registry and search for whatever
page you are being redirected to. Again, just part of the
name is fine. Also recheck your C: to see if there are any
leftover folders which you can remove. If so remove them
and reboot again.
 
J

Jim Byrd

Hi - Sounds like this might be a variant of some malware called
CoolWebSearch (if CWShredder doesn't fix it, then see AdAware, SpyBot, and
HijackThis, below, in that order). Do the following:


#########IMPORTANT#########
Before you try to remove spyware using any of the programs below, download
both a copy of LSPFIX here:

http://www.cexx.org/lspfix.htm

AND a copy of Winsockfix
http://www.tacktech.com/pub/winsockfix/WinsockFix.zip
Directions here: http://www.tacktech.com/display.cfm?ttid=257

The process of removing certain malware may kill your internet connection.
If this should occur, these programs, LSPFIX and WINSOCKFIX, will enable you
to regain your connection.

NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.
#########IMPORTANT#########



#########IMPORTANT#########
All of the following removal tools should be run from Safe mode when
possible.
#########IMPORTANT#########


Download and run Stinger.exe, here:
http://download.nai.com/products/mcafee-avert/stinger.exe or from the link
on this page: http://vil.nai.com/vil/stinger/



Download, UPDATE before running, and run:
http://209.133.47.200/~merijn/files/CWShredder.exe or here:
http://hem.bredband.net/b157129/f/cwshredder.zip or here:
http://www.softpedia.com/public/scripts/downloadhero/10-17-150/ or here:
http://www.zerosrealm.com/downloads/CWShredder.zip
to remove the parasite. Be sure to close all instances of IE and OE.


There's a good tutorial about CWS and using CWShredder here:
http://www.bleepingcomputer.com/forums/index.php?showtutorial=47#domain

BE SURE that you get v.1.59.0.1 or later!

You will need to show Hidden files first and then at the end clear the
malware garbage from your System Restore backups after you've cleaned up.
It's best to perform CWShredder (and most other malware fixers too) from
Safe mode and then reboot. AFTER cleaning things up, then you can disable
and then re-enable System Restore. See ******** below.

The following links give instructions on how to do these various functions:


HOW TO Restart in Safe Mode
<http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406>

HOW TO Enable Hidden Files
<http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2002092715262339>

HOW TO Disable/Flush System Restore (do this at the end AFTER cleaning or
use the suggested procedure for XP at the ******'s)
<http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039>
(WinXP)
<http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239>
(WinME)



Then download and run:
http://www.kellys-korner-xp.com/regs_edits/iegentabs.reg to restore your
tabs and remove any restrictions that the parasite has put in place.

Now download and run:
http://www.kellys-korner-xp.com/regs_edits/RestoreSearch2.REG to restore
your search functions if they've been affected (as they probably will have
been).


Be sure that you also download and install hotfix Q816093, here:

http://support.microsoft.com/?kbid=816093

which blocks the exploit upon which this parasite family depends.



However, this also indicates that you may have acquired some other malware
along the way. If you go to this page at Jim Eshelman's site, here:
http://aumha.org/a/noads.htm and wait a little bit (be patient), an analysis
of a number of possible parasites on your machine will be made to help you
identify and remove them. NOTE: You will need to disable Ad Blocking in Zone
Alarm 3.x, if present or any other Ad Blocking software which interferes
with Java Scripting for this scan to work. You should get a message between
the two lines of **** giving the results of the scan.

Get Ad-Aware SE Personal Edition, here:
http://www.lavasoftusa.com/support/download/. UPDATE, set it up in
accordance with this: http://forum.aumha.org/viewtopic.php?t=5877 and run
this regularly to get rid of most "spyware/hijackware" on your machine. If
it has to fix things, be sure to re-boot and rerun AdAware again and repeat
this cycle until you get a clean scan. The reason is that it may have to
remove things which are currently "in use" before it can then clean up
others.

Another excellent program for this purpose is SpyBot Search and Destroy
available here: http://security.kolla.de/ SpyBot Support Forum here:
http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi. I recommend
using both normally. After UPDATING and fixing ONLY RED things with SpyBot
S&D, be sure to re-boot and rerun SpyBot again and repeat this cycle until
you get a clean "no red" scan. The reason is that SpyBot sometimes has to
remove things which are currently "in use" before it can then clean up
others.

Note that sometimes you need to make a judgement call about what these
programs report as spyware. See here, for example:
http://www.imilly.com/alexa.htm

Both of these programs should normally be UPDATED and run after doing any
other fix such as CWShredder and, as a minimum, normally at least once a
week.



If they don't fix it then start here:

Download HijackThis, free, here:
http://209.133.47.200/~merijn/files/HijackThis.exe (Always download a new
fresh copy of HijackThis [and CWShredder also] - It's UPDATED frequently.)
You may also get it here if that link is blocked:
http://www.majorgeeks.com/downloadget.php?id=3155&file=3&evp=3304750663b552982a8baee6434cfc13
or here: http://www.bleepingcomputer.com/files/spyware/hijackthis.zip

In Windows Explorer, click on Tools|Folder Options|View and check "Show
hidden files and folders" and uncheck "Hide protected operating system
files". (You may want to restore these when you're all finished with
HijackThis.)

Place HijackThis.exe or unzip HijackThis.zip into its own dedicated folder
at the root level such as C:\HijackThis (NOT in a Temp folder or on your
Desktop), reboot to Safe mode, start HT then press Scan. Click on SaveLog
when it's finished which will create hijackthis.log. Now click the Config
button, then Misc Tools and click on Generate StartupList.log which will
create Startuplist.txt

Then go to one of the following forums:

Spyware and Hijackware Removal Support, here:
http://forums.spywareinfo.com/

or Net-Integration here:
http://www.net-integration.net/cgi-...86d536d57b5f65b6e40c55365e;act=ST;f=27;t=6949

or Tom Coyote here: http://forums.tomcoyote.org/index.php?act=idx
or Jim Eshelman's site here: http://forum.aumha.org/
or Bleepingcomputer here: http://www.bleepingcomputer.com/
or Computer Cops here: http://www.computercops.biz/forums.html



Register if necessary, then sign in and READ THE DIRECTIONS at the beginning
of the particular site's HiJackThis forum, then copy and paste both files
into a message asking for assistance, Someone will answer with detailed
instructions for the removal of your parasite(s). Be sure you include at
the beginning of your post a description of "What specific
problem(s)/symptoms you're trying to solve" and "What steps you've already
taken."


*******
ONLY IF you've successfully eliminated the malware, you can now make a new,
clean Restore Point and delete any previously saved (possibly infected)
ones. The following suggested approach is courtesy of Gary Woodruff: For XP
you can run a Disk Cleanup cycle and then look in the More Options tab. The
System Restore option removes all but the latest Restore Point. If there
hasn't been one made since the system was cleaned you should manually create
one before dumping the old possibly infected ones.
*******


Once you get this cleaned up, you might want to consider installing the
SpywareBlaster and SpywareGuard here to help prevent this kind of thing from
happening in the future:

http://www.javacoolsoftware.com/spywareblaster.html (Prevents malware Active
X installs) (BTW, SpyWareBlaster is not memory resident ... no CPU or memory
load - but keep it UPDATED) The latest version as of this writing will
prevent installation or prevent the malware from running if it is already
installed, and it provides information and fixit-links for a variety of
parasites.

http://www.javacoolsoftware.com/spywareguard.html (Monitors for attempts to
install malware) Keep it UPDATED. Both Very Highly Recommended


Finally, go to Windows Update and ensure that ALL Critical updates are
installed.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top