Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Pop-ups Galore in Firefox
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Earlier today I was struck with numerous pop-ups coming from both Firefox and IE. I ran my AVG and detected a few trojans, as I suspected. Afterwards, I ran through the 8 steps listed on the forum, and have my logs attached. Since running the cleaners, I haven't noticed any pop-ups, and am hopeful all is well again.......
I used my updated AVG A/S, Malaware, and HJT..... Can anyone review my logs and confirm? As I mentioned, I have had no further pop-ups, but I want to make sure all is well before I write this one off.... Thanks in advance! As I'm sure everyone is busy - it seems a lot of folks are having similar problems - I just wanted to renew my request to have someone look over my logs......your help is much appreciated. Thanks again Last edited by kimsland; 01-02-2009 at 02:20 AM.. Reason: merged 3 posts, please use Edit instead of replying to yourself |
|
#2
|
|||
|
|||
|
hey man...theres a post down the page that will help u out...have a look @ it..n see if it helps...ill grab link for ya
Sagipsul pop up windows check that Last edited by kimsland; 01-02-2009 at 02:19 AM.. Reason: merged 2 posts, please use Edit instead of replying to yourself |
|
|
|
#3
|
|||
|
|||
|
Thanks woodsy - I got all that. I've followed the standard directions and am just looking for someone to check my HJT log to make sure it's clean....
|
|
#4
|
||||
|
||||
|
-> No action taken on MBAM scan, for found issues
Quote:
Confirm updated (third tab) Then do the above quoted message, but this time "Remove all found issues" By the way, you will need to then restart, and run (and attach) a new HJT log |
|
#5
|
|||
|
|||
|
New logs for your review.......
Last time, I think I saved before and after I removed all the baddies. Don't know why, and don't know why I sent that particular one..... |
|
#7
|
|||
|
|||
|
Done.
As it turns out, I got hit again in the meantime. Gotta love it. Thanks in advance! |
|
#8
|
||||
|
||||
|
Of the many issues in your HJT log, please run it again, tick this entry and then fix it
Quote:
)Un-install SuperAntiSpyware Run CCleaner again Restart Run the Norton Removal tool Start up Malwarebytes again Update it <= notice how this gets its own line ![]() Then run another full scan You need to run this multiple times, until all hidden Malwares are uncovered and removed |
|
#9
|
|||
|
|||
|
1. Fixed the last HJT issue
2. Uninstalled Window Washer and SAS 3. Ran Norton Removal Tool 4. Ran CCleaner until no issues found 5. Updated Malawarebytes and ran until no bad guys found (2x) Latest logs attached. Thanks! |
|
|
|
#10
|
||||
|
||||
|
Well done
![]() But sadly still issues ![]() Please re-run HJT and place a tick next to the following, then select Fix: Quote:
Then restart ![]() |
|
#11
|
|||
|
|||
|
Done.
Fixed all issues and used mcafee removal tool..... |
|
#12
|
||||
|
||||
|
Sorry still issues!
Run HJT, tick and Fix: Quote:
Save it to somewhere, where you can easily find ie C drive Restart your computer to Safe Mode (pressing F8 before Windows starts) Once in Safe Mode, locate and double click on ComboFix.exe This may take up to 10 mins to finish, ther are some prompts to agree to, and your Desktop may reset a couple of times (all normal) When finished, restart back to normal mode Create yet another HJT log, and this time supply a Combofix log too Edit: Doh! Locate C:\Program Files\Vongo folder and delete it |
|
#13
|
|||
|
|||
|
Done and Done. Logs attached.
Thanks! |
|
#14
|
||||
|
||||
|
Daaamn!
Quote:
|
|
#15
|
|||
|
|||
|
Yep, got rid of it in safe mode. Still showing up on the latest HJT log.
Vongo came installed with the laptop when I got it. One of those packaged software programs..... |
|
#16
|
|||||
|
|||||
|
I found this reply from HP Support from someone else who wanted to get rid of Vongo:
Quote:
To do that: Quote:
You can download the Utility here: http://support.microsoft.com/default...b;en-us;290301 The Windows Installer CleanUp Utility does: • Provide a dialog box where you can select one or more programs that were installed by Windows Installer. You select the programs on the Installed Products list in the Windows Installer CleanUp dialog box. After you make this selection, the utility removes only the Windows Installer configuration information that is related to those programs. • Remove the files and registry settings that make up the Windows Installer configuration information for programs that you select. [/QUOTE] I notice the AskBar is still loading: O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL Have HijackThis remove the entry, the click on FlxChecked and boot into Safe More: Start> Run> msconfig> enter> Selective Startup> Startup tab> UNCHECK any Ask bar processes> Apply> OK. Control Panel> Add/Remove Programs> UNINSTALL any Ask related entries. I suggest you also check and have HijackThis remove the following: Quote:
Update Java: Quote:
Quote:
1. Open Firefox> Tools> Options> Privacy section> Cookies> UNCHECK 'allow third party Cookies'. 2. Put the following add-ons on Firefox: AdBlock Plus: https://addons.mozilla.org/en-US/firefox/addon/1865 Easy List: http://easylist.adblockplus.org/ (get all three) |
|
#17
|
|||
|
|||
|
Alright. Updated Java and Adobe Reader (couldn't get 9, still w/ 8.1.5 or something like that. Firefox crashes when I try to download 9.
Fixed all that was mentioned in HJT. I had already deleted the Program Files/Vongo folder before, uninstalled over a year ago, and still can't find any trace of anything related other than what keeps popping up on FF.... Otherwise, I am having no problems with pop ups. I installed Comodo, so hopefully that'll help keep me from getting hit a third time. Thanks for all your help, Eric |
|
#18
|
||||
|
||||
|
Well, we're making progress, but Vongo is still around- we've both had you remove this in HijackThis, but it is still loading:
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user') Did you run the Windows Installer CleanUp Utility? That should allow you to remove the process from the Registry. This McAfee entry remains: O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab>>McAfee Security Download Control Since it's an Active X entry, try this: Open IE> Tools> Manage add-ons> look for any McAfee entry and highlight> disable. IF the pop-ups return, consider removing the Weather Channel. Remove the clean up tools: Quote:
[quote] Quote:
|
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Pop ups galore | Virus & Malware removal | 26 | 12-16-2006 01:06 AM | |
| Problems galore | Virus & Malware removal | 1 | 05-10-2006 06:02 PM | |
| BSOD Galore .. | BSOD Help & Support | 1 | 09-23-2005 11:41 AM | |
| SCO Law Suits Galore! | Old Frontpage News & Comments | 0 | 07-26-2004 03:06 PM | |
| Zeitgeist galore | Old Frontpage News & Comments | 0 | 12-16-2002 06:00 AM | |
All times are GMT -4. The time now is 11:14 PM.



)
