Slickdeals.net - The best deals, lowest prices and hot coupons.
Register Search Today's Posts Mark Forums Read
Go Back   SlickDeals.net Forums > General Discussion > Tech Support

Old 08-23-2008, 09:29 AM #1
Dr. J is offline Dr. J
L10: Grand Master
Dr. J's Avatar
Nov 2005
12,030
1434 Dr. J has much to be proud of
Trojan or something....

I have a very annoying issue on my PC

Every now and then with IE open, a random window will popup and direct me to some bogus security site wanting to install sw to "secure" my PC. There is no pattern to the popups AFAIK, and I have run AVG, SpyBot and Hijack this and can't find anything!

AVG will *sometimes* intercept the browser spawns and warn of visiting "dangerous" sites but doesn't prevent the popups in the first place.

Any more ideas?
__________________
Want to save money just by clicking through the right site when you make purchases?
Try my comparison thread of 6 different cash back programs, comprising
1556 DIFFERENT retailers and 3716 separate offers!
Compendium of Click-Throughs and Cash Back (CCTCB)
 
08-23-2008, 09:29 AM

 
Guests, join the SlickDeals.net Community to remove this ad.

Old 08-23-2008, 09:39 AM #2
trunkwontopen is offline trunkwontopen
Metroids b suckin ma hed
trunkwontopen's Avatar
Sep 2005
Saginaw, MI
1,073
356 trunkwontopen is just really nice
post your hijackthis log.
theres a new strain of the Vundo virus out there.
__________________
digital home [trunkwontopen.com] | SE/SW MI LAN Gaming [theboxheads.net]

[MCR] as of: 03.13.09 - 11,109 pts..
[SpeedyRewards] as of: 03.13.09 - 17,082 pts.


Quote from BlooQKazoo View Post :
I would quote myself. Because quoting yourself is cool.
 
Old 08-23-2008, 12:56 PM #3
laalaa99stl is offline laalaa99stl
6 & 12
laalaa99stl's Avatar
Jan 2008
378
268 laalaa99stl is a jewel in the rough
Use sysinternals autoruns to manually identify and disarm any BHO's that look suspicious.
 
Old 08-23-2008, 02:48 PM #4
Dandrop is offline Dandrop
L5: Journeyman
Dandrop's Avatar
Oct 2006
893
233 Dandrop has a spectacular aura about
Lately, these trojans/spyware/malware have been pretty aggressive and sometimes harder to catch.

Aside from the programs you used, i suggest downloading Malwarebyte's Anti Malware [download.com] and SuperAntiSpyware [superantispyware.com].

I've gotten a lot of stuff out that the other programs you mentioned failed to eliminate.
 
Old 08-23-2008, 02:58 PM #5
acr is online now acr
L6: Expert
acr's Avatar
Jul 2007
1,806
1981 acr has a brilliant future
Quote from Dandrop View Post :
Lately, these trojans/spyware/malware have been pretty aggressive and sometimes harder to catch.

Aside from the programs you used, i suggest downloading Malwarebyte's Anti Malware [download.com] and SuperAntiSpyware [superantispyware.com].

I've gotten a lot of stuff out that the other programs you mentioned failed to eliminate.
The above two are real good. Also try Dr. Web's Cure-it as it is good at detection and pretty good at removal. Also it does not need installed. Search this forum for a link to it. I would post it but am dealing with computer issues myself.
 
Old 08-23-2008, 05:37 PM #6
JoyceTee is offline JoyceTee
Tech Junkie
JoyceTee's Avatar
Jul 2008
Houston
19
14 JoyceTee is finding his bearings
Quote from Dr. J View Post :
I have a very annoying issue on my PC

Every now and then with IE open, a random window will popup and direct me to some bogus security site wanting to install sw to "secure" my PC. There is no pattern to the popups AFAIK, and I have run AVG, SpyBot and Hijack this and can't find anything!

AVG will *sometimes* intercept the browser spawns and warn of visiting "dangerous" sites but doesn't prevent the popups in the first place.

Any more ideas?
In IE set Privacy options to NOT accept 3rd party cookies. Also, install a customs host file
http://www.abelhadigital.com/ in settings set it to overwrite the hosts file when it does updates. Also use IE Spyads with Zoned Out, you can find all this information at http://www.spywarewarrior.com/uiuc/resource.htm Also d/l and install Spyware Blaster and update it weekly or if u want auto update then make a donation. All these programs are FREE and will keep you squeaky clean, but 1st you need to get rid of the spyware you have on there, run the Malwarebyes as recommended but also run Ad Aware and SpyBot in SAFE mode. This type of spyware is known to hide from these programs so if you run in safe mode it's not running and can't hide. Always when trying to remove spyware/trojans etc. run programs in safe mode if possible. Also look in your add/remove programs see if you have anything installed that says "browser redirect". Turn on windows pop up blocker or else use google toolbar and enable pop up blocker.
The programs listed above for protection will not get rid of spyware you already have on there, you must get rid of the spyware 1st then install, hostsman, ie spyads/zoned out and spyware blaster, enable pop up blocker and set privacy options to not allow 3rd part cookies. You shouldn't have any more problems after you do the above. You can PM me or email me if you need help.

Good luck!!!
__________________

Last edited by JoyceTee; 08-23-2008 at 05:43 PM.. Reason: additional info
 
Old 08-23-2008, 06:00 PM #7
acr is online now acr
L6: Expert
acr's Avatar
Jul 2007
1,806
1981 acr has a brilliant future
Quote from JoyceTee View Post :
In IE set Privacy options to NOT accept 3rd party cookies. Also, install a customs host file
http://www.abelhadigital.com/ in settings set it to overwrite the hosts file when it does updates. Also use IE Spyads with Zoned Out, you can find all this information at http://www.spywarewarrior.com/uiuc/resource.htm Also d/l and install Spyware Blaster and update it weekly or if u want auto update then make a donation. All these programs are FREE and will keep you squeaky clean, but 1st you need to get rid of the spyware you have on there, run the Malwarebyes as recommended but also run Ad Aware and SpyBot in SAFE mode. This type of spyware is known to hide from these programs so if you run in safe mode it's not running and can't hide. Always when trying to remove spyware/trojans etc. run programs in safe mode if possible. Also look in your add/remove programs see if you have anything installed that says "browser redirect". Turn on windows pop up blocker or else use google toolbar and enable pop up blocker.
The programs listed above for protection will not get rid of spyware you already have on there, you must get rid of the spyware 1st then install, hostsman, ie spyads/zoned out and spyware blaster, enable pop up blocker and set privacy options to not allow 3rd part cookies. You shouldn't have any more problems after you do the above. You can PM me or email me if you need help.

Good luck!!!
I agree with adding SpywareBlaster- http://www.javacoolsoftware.com/s...aster.html

I have tried the host file stuff before and did not like it. I just use Ad Muncher and everything works fine- no manual updates or an ever enlarging host file. It's not freeware but is one of the best programs I have ever purchased. It also is avialable via trial pay or whatever the name is. Using a browser such as Opera with the Fanboy ad block list or Firefox with Ad Block Plus (and Easylist and its other components) also do pretty well. But that is just my 2 cents worth.
 
Old 08-23-2008, 06:21 PM #8
Lvcian is offline Lvcian
L3: Novice
Aug 2006
129
32 Lvcian is finding his bearings
IE = bad =[

You can also try Spybot S&D. I've used this program for years now and have not had any spyware/malware at all. Granted that I use a more secure web browser.

http://www.safer-networking.org/e...index.html
__________________
----------------------------------------------------------------------------------------------
OD Brand Harrington High Leather Chair - $90 - reg. 209
500GB WD MyBook Essential ED - $89.99 - reg. $149
Logitech G5 Laser Gaming Mouse - $25 - reg.$70
Schick Quattro Titanium -Free - reg. $15
EpsonŽ Stylus All-In-One Printer - Free - reg. $60
HP LaserJet 1018 -$20 - reg. $130
 
Old 08-23-2008, 09:04 PM #9
JoyceTee is offline JoyceTee
Tech Junkie
JoyceTee's Avatar
Jul 2008
Houston
19
14 JoyceTee is finding his bearings
Quote from acr View Post :
I agree with adding SpywareBlaster- http://www.javacoolsoftware.com/s...aster.html

I have tried the host file stuff before and did not like it. I just use Ad Muncher and everything works fine- no manual updates or an ever enlarging host file. It's not freeware but is one of the best programs I have ever purchased. It also is avialable via trial pay or whatever the name is. Using a browser such as Opera with the Fanboy ad block list or Firefox with Ad Block Plus (and Easylist and its other components) also do pretty well. But that is just my 2 cents worth.
I don't know how long ago you tried the customs host file, but if it''s been a while try the new hostsman.exe, it's really great and so is Zoned Out. I found the old customs hosts program awkward and quit using it, but the new one is great and yes it does make a large host file, but as you know there are ever increasing sites that put all that nasty stuff on your PC and this will stop most of it.
 
Old 08-23-2008, 10:11 PM #10
radford is offline radford
L9: Master
Aug 2006
4,809
677 radford is a splendid one to behold
Quote from Dandrop View Post :
Lately, these trojans/spyware/malware have been pretty aggressive and sometimes harder to catch.

Aside from the programs you used, i suggest downloading Malwarebyte's Anti Malware [download.com] and SuperAntiSpyware [superantispyware.com].

I've gotten a lot of stuff out that the other programs you mentioned failed to eliminate.
I havent had that problem in eons but a few years ago I had some terrible problems. As long as you avoid various sites it rarely happens.

If you go to questionable sites usually using sex or cracks, cracked software as bait its high risk. However those are the obvious ones. I never fall for those. The ones I fell for is when you do a casual search for music for trojan fighters or AVG etc there used to be some bogus sites. I went to one and it trashed my PC. It installed so many ads and crud that it was obviously meant to screw up your PC as a prank.

I also got a few hijack type crap too which were impossible to fix without a complete reformat.
 
Old 08-24-2008, 12:00 AM #11
M0T49 is offline M0T49
parachutiste d'or
M0T49's Avatar
Jul 2008
1,174
262 M0T49 is a jewel in the rough
Still using IE7?

I made the switch to Firefox 3.0 You might want to consider Firefox as well. It's lightyears ahead of IE7.
 
Old 08-24-2008, 01:07 AM #12
acr is online now acr
L6: Expert
acr's Avatar
Jul 2007
1,806
1981 acr has a brilliant future
Quote from JoyceTee View Post :
I don't know how long ago you tried the customs host file, but if it''s been a while try the new hostsman.exe, it's really great and so is Zoned Out. I found the old customs hosts program awkward and quit using it, but the new one is great and yes it does make a large host file, but as you know there are ever increasing sites that put all that nasty stuff on your PC and this will stop most of it.
If I didn't have the set up I currently have I might give it a whirl. Or just use shoot it up a notch and go for proxomitron.
 
Old 08-24-2008, 07:26 PM #13
Dr. J is offline Dr. J
L10: Grand Master
Dr. J's Avatar
Nov 2005
12,030
1434 Dr. J has much to be proud of
Thanks for the very constructive help.

I found it was "Trojan horse Adload_r.AQ"

AVG picked it up when it tried to spawn a new IE window. I did some searching, rebooted in safe mode, ran a full scan and ran some other utlities - AVG deleted a few things so we'll see if it worked.
 
  • ReplyPost Reply


  • Thread Tools Search this Thread
    Search this Thread:

    Advanced Search

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off

     

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    Is it my PSU or mobo? (or something else?) Sgaterboy Tech Support 3 07-23-2008 03:28 PM


    All times are GMT -7. The time now is 09:07 PM.

    Close
    E-mail It