also @ TechSpot: Weekend Open Forum: Have you upgraded to Windows 7 yet?
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Pop-ups Galore in Firefox

Closed Thread
Bookmark Thread Tools
  #1  
Old 12-29-2008
Newcomer, in training
 
Member since: Nov 2006, 32 posts
Earlier today I was struck with numerous pop-ups coming from both Firefox and IE. I ran my AVG and detected a few trojans, as I suspected. Afterwards, I ran through the 8 steps listed on the forum, and have my logs attached. Since running the cleaners, I haven't noticed any pop-ups, and am hopeful all is well again.......

I used my updated AVG A/S, Malaware, and HJT.....

Can anyone review my logs and confirm? As I mentioned, I have had no further pop-ups, but I want to make sure all is well before I write this one off....

Thanks in advance!

As I'm sure everyone is busy - it seems a lot of folks are having similar problems - I just wanted to renew my request to have someone look over my logs......your help is much appreciated.

Thanks again
Attached Files
File Type: txt mbam-log-2008-12-28 (23-12-58).txt (4.5 KB, 5 views)
File Type: txt Report-Scan-20081228-212751.txt (938 Bytes, 2 views)
File Type: log hijackthis12-28-2008.log (12.8 KB, 5 views)

Last edited by kimsland; 01-02-2009 at 02:20 AM.. Reason: merged 3 posts, please use Edit instead of replying to yourself
  #2  
Old 12-29-2008
Newcomer, in training
 
Member since: Dec 2008, 11 posts
hey man...theres a post down the page that will help u out...have a look @ it..n see if it helps...ill grab link for ya

Sagipsul pop up windows

check that

Last edited by kimsland; 01-02-2009 at 02:19 AM.. Reason: merged 2 posts, please use Edit instead of replying to yourself
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 12-29-2008
Newcomer, in training
 
Member since: Nov 2006, 32 posts
Thanks woodsy - I got all that. I've followed the standard directions and am just looking for someone to check my HJT log to make sure it's clean....
  #4  
Old 01-02-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,034 posts
-> No action taken on MBAM scan, for found issues
Quote:
Download and Run Malwarebytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected. <========= Not Done
Please re-run Malwarebytes
Confirm updated (third tab)
Then do the above quoted message, but this time "Remove all found issues"

By the way, you will need to then restart, and run (and attach) a new HJT log
  #5  
Old 01-02-2009
Newcomer, in training
 
Member since: Nov 2006, 32 posts
New logs for your review.......

Last time, I think I saved before and after I removed all the baddies. Don't know why, and don't know why I sent that particular one.....
Attached Files
File Type: txt hijackthis1-2-2009.txt (12.9 KB, 1 views)
File Type: txt mbam-log-2009-01-02 (01-09-02).txt (850 Bytes, 1 views)
  #6  
Old 01-02-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,034 posts
Please un-install AVG Anti-Spyware 7.5 (and any other AVG installed on your computer
Install Avira instead, and run a full scan
  #7  
Old 01-03-2009
Newcomer, in training
 
Member since: Nov 2006, 32 posts
Done.

As it turns out, I got hit again in the meantime. Gotta love it.

Thanks in advance!
  #8  
Old 01-03-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,034 posts
Of the many issues in your HJT log, please run it again, tick this entry and then fix it
Quote:
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
Un-install Window Washer (CCleaner is much better )

Un-install SuperAntiSpyware

Run CCleaner again

Restart

Run the Norton Removal tool

Start up Malwarebytes again
Update it <= notice how this gets its own line
Then run another full scan
You need to run this multiple times, until all hidden Malwares are uncovered and removed
  #9  
Old 01-04-2009
Newcomer, in training
 
Member since: Nov 2006, 32 posts
1. Fixed the last HJT issue
2. Uninstalled Window Washer and SAS
3. Ran Norton Removal Tool
4. Ran CCleaner until no issues found
5. Updated Malawarebytes and ran until no bad guys found (2x)

Latest logs attached.

Thanks!
Attached Files
File Type: log hijackthis1-4-2008.log (9.9 KB, 1 views)
File Type: txt mbam-log-2009-01-04 (00-11-23)2nd run.txt (1.1 KB, 1 views)
File Type: txt mbam-log-2009-01-04 (02-05-33)3rd run.txt (851 Bytes, 1 views)
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 01-04-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,034 posts
Well done

But sadly still issues

Please re-run HJT and place a tick next to the following, then select Fix:
Quote:
O4 - HKCU\..\Policies\Explorer\Run: [{38F59401-06C1-1033-0815-060426060001}] "C:\Program Files\Common Files\{38F59401-06C1-1033-0815-060426060001}\Update.exe" mc-110-12-0000272
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
O24 - Desktop Component 0: (no name) - http://education.yahoo.net/degrees/i..._pay_check.jpg
Before restarting run: the McAfee Removal Tool
Then restart
  #11  
Old 01-04-2009
Newcomer, in training
 
Member since: Nov 2006, 32 posts
Done.

Fixed all issues and used mcafee removal tool.....
Attached Files
File Type: log hijackthis1-4-08 2nd run.log (9.6 KB, 1 views)
  #12  
Old 01-04-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,034 posts
Sorry still issues!

Run HJT, tick and Fix:

Quote:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
Download Combofix from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Save it to somewhere, where you can easily find ie C drive

Restart your computer to Safe Mode (pressing F8 before Windows starts)
Once in Safe Mode, locate and double click on ComboFix.exe
This may take up to 10 mins to finish, ther are some prompts to agree to, and your Desktop may reset a couple of times (all normal)

When finished, restart back to normal mode
Create yet another HJT log, and this time supply a Combofix log too

Edit:

Doh!

Locate C:\Program Files\Vongo folder and delete it
  #13  
Old 01-04-2009
Newcomer, in training
 
Member since: Nov 2006, 32 posts
Done and Done. Logs attached.

Thanks!
Attached Files
File Type: txt cflog1-4-2008.txt (23.5 KB, 1 views)
File Type: log hijackthis1-4-2008 am.log (8.9 KB, 1 views)
  #14  
Old 01-04-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,034 posts
Daaamn!
Quote:
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
Did you also remove the folder C:\Program Files\Vongo as stated above, from Safe mode?
  #15  
Old 01-04-2009
Newcomer, in training
 
Member since: Nov 2006, 32 posts
Yep, got rid of it in safe mode. Still showing up on the latest HJT log.

Vongo came installed with the laptop when I got it. One of those packaged software programs.....
Attached Files
File Type: log hijackthis1-4-20084th try.log (9.2 KB, 1 views)
  #16  
Old 01-04-2009
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,778 posts
I found this reply from HP Support from someone else who wanted to get rid of Vongo:
Quote:
Uninstall VONGO Software:
1. Restart the Notebook and keep Tapping F8.
2. Select Safe Mode and press Enter
3. Click on Start, select Run, type "msconfig" press Enter.
4. Click on Startup tab and uncheck the check box besides "isuspm"
5. Click OK and restart the system for the new settings to take effect.

Note: After you restart the machine you may receive a dialogue box stating 'System is running using Selective Startup', Check 'Don't show this message or launch the system configuration utility when Windows Starts' and click OK.

Now, restart the Notebook again and go into Safe Mode by tapping F8.:
Click on Start -> Control Panel -> Add Remove Programs>
Locate the Vongo Software and click on Remove to uninstall it.
If this does not resolve the issue, you may have to manually delete the files.
To do that:
Quote:
1. Double click on My Computer
2. Double click on C Drive
3. Double click on Program Files
4. Select the Vongo Software folder and press Delete.
5. Close the Window
6. Right click on Recycle Bin folder and select Empty Recycle Bin
This will remove the Software.
Now, run the Windows Installation Cleanup Utility, this will remove the registry entries for the Software.

You can download the Utility here: http://support.microsoft.com/default...b;en-us;290301

The Windows Installer CleanUp Utility does:

• Provide a dialog box where you can select one or more programs that were installed by Windows Installer. You select the programs on the Installed Products list in the Windows Installer CleanUp dialog box. After you make this selection, the utility removes only the Windows Installer configuration information that is related to those programs.

• Remove the files and registry settings that make up the Windows Installer configuration information for programs that you select.
[/QUOTE]
I notice the AskBar is still loading:
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
Have HijackThis remove the entry, the click on FlxChecked and boot into Safe More:
Start> Run> msconfig> enter> Selective Startup> Startup tab> UNCHECK any Ask bar processes> Apply> OK.

Control Panel> Add/Remove Programs> UNINSTALL any Ask related entries.

I suggest you also check and have HijackThis remove the following:
Quote:
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
When rebooting into Normal mode, ignore the nag message, check 'don't show this message again.' Stay in Selective Startup.

Update Java:
Quote:
Your version of Java is now outdated. Java vulnerabilities are commonly exploited by viruses so I strongly recommend you update. Click here to download the latest version of java ( Java Runtime Environment (JRE) 6.0 Update 11 ): http://java.com/en/download/manual.jsp
Please install it and then reboot your computer.

Remove the older versions of Java:
1. Click Start, Control Panel, Add/Remove Programs.
2. Delete all Java updates except J2SE Runtime Environment 6.0 Update 11
Update Adobe:
Quote:
Your Adobe Reader is out of date. Vulnerabilities can be exploited. Click here to download the latest version v9: http://www.adobe.com/products/acrobat/readstep2.html
OR
Install the FoxIt Reader: this does the same thing as Adobe, but doesn’t have the bloat: http://www.foxitsoftware.com/pdf/rd_intro.php
The following will help the Cookie and pop-up problem in Firefox:
1. Open Firefox> Tools> Options> Privacy section> Cookies> UNCHECK 'allow third party Cookies'.
2. Put the following add-ons on Firefox:
AdBlock Plus: https://addons.mozilla.org/en-US/firefox/addon/1865
Easy List: http://easylist.adblockplus.org/
(get all three)
  #17  
Old 01-04-2009
Newcomer, in training
 
Member since: Nov 2006, 32 posts
Alright. Updated Java and Adobe Reader (couldn't get 9, still w/ 8.1.5 or something like that. Firefox crashes when I try to download 9.

Fixed all that was mentioned in HJT. I had already deleted the Program Files/Vongo folder before, uninstalled over a year ago, and still can't find any trace of anything related other than what keeps popping up on FF....

Otherwise, I am having no problems with pop ups. I installed Comodo, so hopefully that'll help keep me from getting hit a third time.

Thanks for all your help,

Eric
Attached Files
File Type: log hijackthis1-4 2pm.log (9.5 KB, 1 views)
  #18  
Old 01-05-2009
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 5,778 posts
Well, we're making progress, but Vongo is still around- we've both had you remove this in HijackThis, but it is still loading:
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')

Did you run the Windows Installer CleanUp Utility? That should allow you to remove the process from the Registry.

This McAfee entry remains:
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab>>McAfee Security Download Control

Since it's an Active X entry, try this:
Open IE> Tools> Manage add-ons> look for any McAfee entry and highlight> disable.

IF the pop-ups return, consider removing the Weather Channel.

Remove the clean up tools:
Quote:
* Download OTCleanIt
http://download.bleepingcomputer.com.../OTCleanIt.exe

* Click the CleanUp! button.
* It will go thorough the list and remove all of the tools it finds and then delete itself (requiring a reboot).
Clear your existing System Restore points and establish a new clean restore point:
[quote]
Quote:
Go to Start > All Programs > Accessories > System Tools > System Restore> Select Create a restore point> OK.
* Next, go to Start > Run and type in cleanmgr
"Ensure the selection is on C:\ and click on OK"-
* Select the *More options* tab
* Choose the option to clean up System Restore and OK it.
* This will remove all restore points except the new one you just created.
Let us know if we can be of help in the future.
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Pop ups galore Virus & Malware removal 26 12-16-2006 01:06 AM
Problems galore Virus & Malware removal 1 05-10-2006 06:02 PM
BSOD Galore .. BSOD Help & Support 1 09-23-2005 11:41 AM
SCO Law Suits Galore! Old Frontpage News & Comments 0 07-26-2004 03:06 PM
Zeitgeist galore Old Frontpage News & Comments 0 12-16-2002 06:00 AM


All times are GMT -4. The time now is 11:14 PM.