Computing.Net > Forums > Security and Virus > Annoying pop ups!

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Annoying pop ups!

Reply to Message Icon

Original Message
Name: tobacco_slammers
Date: June 4, 2007 at 02:02:02 Pacific
Subject: Annoying pop ups!
OS: Windows Vista Basic
CPU/Ram: 512MB DDRII
Model/Manufacturer: acer Aspire
Comment:

For a few weeks now i've had numerous pop ups appear on my pc and can't get rid off the cause. I am using firefox 2 as my browser but my pc trys to open up the pop ups through Internet Explorer.

I have tried a variety of different ways to remove this virus but have come to a dead end.

Whilst doing a search with Spybot S&D I get the following file which I cannot remove:

"Smitfraud-C. Coreservice" which has 4 other files contained within it. When I try to remove it, one of the files can be deleted and the other 3 can't. It then asks if I want to do another scan on boot and i've tried this aswell but still can't remove these files.

I have the following antivirus/spyware programs on my pc:

Spybot S&D, Pop Gun, Kill box, F-Secure(Beta version for Vista).

I have also had AVG Antivirus on my pc and tried to remove it with this but this didn't work either, this is when I actually caught the virus.

Could someone kindly assist me in removing this from my pc?

I've posted in another couple of forums but had no reply.

Thanks, Bryan.

www.myspace.com/tobaccoslammers


Report Offensive Message For Removal


Response Number 1
Name: Razor2.3
Date: June 4, 2007 at 02:07:41 Pacific
Reply: (edit)

Have you tried them in safe mode?


Report Offensive Follow Up For Removal

Response Number 2
Name: Johnw
Date: June 4, 2007 at 05:22:46 Pacific
Reply: (edit)

Here is all the the info needed to empower yourself, anything you are not sure of, put into a search engine like Google.
Read this link 1st, it has step by step.
http://www.wilderssecurity.com/show...
Important: Create a specific folder on your hard drive called HijackThis to keep its backups.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HijackThis. Download and unzip HijackThis.exe into this folder.
http://www.merijn.org/downloads.html Or, http://tomcoyote.com/hjt/ Or, http://www.spywareinfo.com/~merijn/...
If possible run HJT in Normal mode ( not Safe ) with all your normal startup's working.
HijackThis Tutorial - How to Analyse your own log.
http://spywarewarrior.com/viewtopic...
http://hometown.aol.co.uk/jrmc137/h...
http://www.bleepingcomputer.com/tut...
http://www.malwarehelp.org/understa...
HijackThis log file analysis ( online )
http://hijackthis.de/index.php?lang...
Or,
http://startup.networktechs.com/pag...
http://hjt.iamnotageek.com
Malware Prevention: Prevent Re-infection
http://wiki.castlecops.com/Malware_...
http://www.offroaders.com/ralphtheg...


Report Offensive Follow Up For Removal

Response Number 3
Name: tobacco_slammers
Date: June 4, 2007 at 10:30:40 Pacific
Reply: (edit)

Hi thanks for your replies.

Razor2.3: Yes I have tried to remove them in safe mode but it didn't work.

JohnW: I've had a look through the info you gave me but I honestly don't understand it. I have managed to create a specific folder on my hard drive for HJT as you suggested but other than that i'm lost!

Any other advice?

www.myspace.com/tobaccoslammers


Report Offensive Follow Up For Removal

Response Number 4
Name: Derek
Date: June 4, 2007 at 13:58:50 Pacific
Reply: (edit)

It would be worth jacking up IE security to Max until this problem is resolved.

As regards #2 then unfortunately it does take quite a bit of effort to get shot of these nasties yourself. Take it step by step, mostly the groupings are different aspects of the same thing. For example there are several auto-analyzers given because somtimes one will give additional useful information compared to another.

DerekW


Report Offensive Follow Up For Removal

Response Number 5
Name: XpUser4Real
Date: June 4, 2007 at 21:23:54 Pacific
Reply: (edit)

what I would do is D/L avast free http://www.avast.com/eng/programs.html to your desktop. Then disable AVG and F-Secure, install avast and let it do a bootscan on reboot. Remove all it finds and move it to the chest. That's how I got rid of the Smitfraud problem on 4 PC's in the past week.
Also run a free online scan http://www.spywareinfo.com/xscan.php and remove all it finds.
You may also want to put Spyware Blaster http://majorgeeks.com/download2859.... in your arsenal.

If your problem still persists, you may have to disable system restore and rescan again.

Hopefully my advice will help you...Please post back with your results....thanks


Report Offensive Follow Up For Removal


Response Number 6
Name: XpUser4Real
Date: June 4, 2007 at 21:25:43 Pacific
Reply: (edit)

Somehow, this was double posted...sorry...I really don't know how it happened?


Hopefully my advice will help you...Please post back with your results....thanks


Report Offensive Follow Up For Removal

Response Number 7
Name: Derek
Date: June 5, 2007 at 11:40:19 Pacific
Reply: (edit)

I too recommend SpywareBlaster as it is an excellent program (although exactly the same idea as SpyBot's Immunize feature if you use that).

Note that neither of these cure anything after it has got in. They prevent them from taking hold in the first place.

DerekW


Report Offensive Follow Up For Removal

Response Number 8
Name: tobacco_slammers
Date: June 8, 2007 at 07:12:15 Pacific
Reply: (edit)

Ok, So I downloaded Avast antivirus as requested by "XpUser4Real" and disabled F-Secure, ran a boot scan to which nothing appeared to have happened???

So I restarted my pc and did a thorough scan with Avast. After the scan finished I had a list off 157 files. I clicked on all of these files and chose to move them to the chest, many of these couldn't be moved as it stated that they were password protected.

In the Avast chest I now have the following:

Infected files - 32
User Files - 0
System Files - 3


All of the infected files contain the following info:

Name - SmitfraudCCoreService(different no's here).zip

Original Location - C:\ProgramData\Spybot - Search & Destroy\Recovery

Do I simply delete these files from the chest or do I need to do something else?

If I have to delete these what would you reccomend that I do next?

Also can I remove Avast now and enable F-Secure?

At present I am still getting these pop ups.

www.myspace.com/tobaccoslammers


Report Offensive Follow Up For Removal

Response Number 9
Name: XpUser4Real
Date: June 8, 2007 at 08:19:38 Pacific
Reply: (edit)

once in the chest they are in quarantine so you can leave them in there. What are the ACTUAL pop-ups you are getting?
Also, yes, just disable Avast and you can use F-Secure again.

Hopefully my advice will help you...Please post back with your results....thanks


Report Offensive Follow Up For Removal

Response Number 10
Name: tobacco_slammers
Date: June 8, 2007 at 16:37:17 Pacific
Reply: (edit)

I'm getting random pop ups to various sites and ones to nowhere???

I'm using firefox 2 as my browset but get pop ups trying to open Internet Explorer.

www.myspace.com/tobaccoslammers


Report Offensive Follow Up For Removal

Response Number 11
Name: Johnw
Date: June 8, 2007 at 16:54:01 Pacific
Reply: (edit)

"I have managed to create a specific folder on my hard drive for HJT as you suggested but other than that i'm lost!"

That was the last step in a logical process.

Did you try Step by Step?

Read this link 1st, it has step by step.
http://www.wilderssecurity.com/show...


Report Offensive Follow Up For Removal

Response Number 12
Name: tobacco_slammers
Date: June 9, 2007 at 02:58:27 Pacific
Reply: (edit)

Hi Johnw. I've looked through the step by step notes but most of the stuff on there is for Windows XP users, i'm on Windows Vista. Any of the programs mentioned on it are beta versions for Vista.

Currently I have Avast Antivirus running on my PC and it is upto date. I tried turning F-Secure back on aswell but when any off these programs are running I still get the pop ups. I done another search with Spybot and it's still finding the Smitfraud bug but wont remove it.

I really don't know what to do next here. I've tried loads off different things and downloaded tons off stuff for weeks now and can't remove this fault.

Here is a list off all the protection programs I have the now and none of them will remove the bug:

1. F-Secure Internet Security Technology(Beta version for Windows Vista)
2. Avast Antivirus
3. Spybot S&D
4. Killbot
5. Popgun

www.myspace.com/tobaccoslammers


Report Offensive Follow Up For Removal

Response Number 13
Name: XpUser4Real
Date: June 9, 2007 at 07:33:48 Pacific
Reply: (edit)

do the errors say where the infections are located? Could it be they are in the restore?
If so, turn off system restore and rescan.
Did you do the online scan I suggested earlier?
Also, I would suggest Spyware Blaster

I didn't see any mention of cleaners. Use CCleaner and ATF Cleaner to clean out all the junk from your PC.

Hopefully my advice will help you...Please post back with your results....thanks


Report Offensive Follow Up For Removal

Response Number 14
Name: Johnw
Date: June 9, 2007 at 17:38:36 Pacific
Reply: (edit)

"Any of the programs mentioned on it are beta versions for Vista"
Everything is in Beta tobacco_slammers, that is why there is a constant stream of upgrades, hotfixes, bug fixes etc.

Another important part of my 1st post.
"anything you are not sure of, put into a search engine like Google"

As you have a trojan, try these online scans, may have to use all.
Free online Trojan scan.
http://www.webroot.com/services/spy...
http://www.trojanscan.com/
http://www.pcflank.com/
http://www.spywareinfo.com/xscan.php
http://www.windowsecurity.com/troja...

Disabling Windows Vista System Restore
http://www.bleepingcomputer.com/tut...

This is a very good trojan remover. Make sure you update it after installing.
http://free.grisoft.com/doc/avg-ant...


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software