Click here to get back home

Help... Mystery Popup Virus?? (0/1)

 HomeNewsGroups | Search | About
 microsoft.public.security.virus    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Help... Mystery Popup Virus?? (0/1) SS 04-30-2008
Posted by SS on April 30, 2008, 10:03 am
Please log in for more thread options
Hi...

Running:

WinXP Pro 5.1.2600 SP2 build 2600 with all of the
automatic updates.

IE6 6.0.2900.2180.xpsp_sp2_gdr.070227-2254IC
also with the automatic updates.

(Noite...this also happens with Firefox.)

This does NOT happen when viewing htm files on my
hard drive...only online websites (and not every
site...for instance, Sun's Java site seemed
immune.)

Popups occur randomly...sometimes as straight ads,
sometimes as shown in the attached images. (These
are shrunk or cropped to keep them small ... and
the forst one has red ovals that I added to show
the non-full-screen popups.)

Sometimes they open an full-screen
window...sometimes smaller windows.

Here's what I have tried already:

I have uninstalled Java 4 and 5 and installed Java
6 (This was suggested in an earlier response to
someone else's post).

I went into my porcess list and deleted everything
that seemed nonessential.

Using Tuneup Utilities 2008, I disabled all the
unidentifiable start-up files...BUT...the
following one kept coming back, so it is high on
my suspect list: VDSKEKTH.exe

An internet search for VDSKEKTH.exe came up empty.

I have scanned my entire computer with McAfee AV
and AdAware to no avail.

I am open to all suggestions.

I will check this newsgroup religiously, but I can
also be reached at info@sanderhome.com

Thanks.
SS

Posted by Malke on April 30, 2008, 10:27 am
Please log in for more thread options
SS wrote:

> Hi...
>
> Running:
>
> WinXP Pro 5.1.2600 SP2 build 2600 with all of the
> automatic updates.
>
> IE6 6.0.2900.2180.xpsp_sp2_gdr.070227-2254IC
> also with the automatic updates.
>
> (Noite...this also happens with Firefox.)
>
> This does NOT happen when viewing htm files on my
> hard drive...only online websites (and not every
> site...for instance, Sun's Java site seemed
> immune.)
>
> Popups occur randomly...sometimes as straight ads,
> sometimes as shown in the attached images. (These
> are shrunk or cropped to keep them small ... and
> the forst one has red ovals that I added to show
> the non-full-screen popups.)

(snippage)

Thank you for being thorough but:

1. It would have been simpler to just tell us "AntiSpyware Master" and leave
off all the screenshots.

2. Also, next time don't make 4 separate posts about the same subject.

AntiSpyware Master is just another rogue antispyware program and your
computer is infested. Here is a thread showing how to remove it but if your
computer skills are not high (and I'm not saying they aren't - I have no
way of knowing whether you have MadSkilz or not) I strongly suggest that
you register at BleepingComputer or one of the other specialty forums
listed below and get guided help. DO NOT POST HIJACK THIS LOGS IN THE MS
NEWSGROUPS.

http://www.bleepingcomputer.com/forums/topic143309.html

Other specialty malware removal forums:

http://aumha.org/downloads/hijackthis.zip
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 - another
tutorial
http://aumha.net/ - Click on the HijackThis forum. Read the announcement and
the stickies *first*.
http://www.atribune.org/forums/index.php?showforum=9
http://aumha.net/viewforum.php?f=30
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://spywarewarrior.com/viewforum.php?f=5

Choose one, register and read its posting FAQ. You will generally be asked
to:

1. Download and execute HiJack This! (HJT) -
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

2. Disable Notepad's word wrap - In Notepad.exe; Format --> uncheck; "Word
wrap"

3. Download/run Deckard's System Scanner -
http://www.techsupportforum.com/sectools/Deckard/dss.exe

4. Save the scan results (Main.txt and Extra.txt)

5. And then post the contents of Main.txt and Extra.txt in your post at the
forum you chose. DO NOT POST LOGS IN THE MS NEWSGROUPS.

Standard disclaimer: I can't see and test your computer myself, so these are
just suggestions based on many years of being a professional computer tech;
suggestions based on what you've written. You should not take my
suggestions as a definitive diagnosis. If you can't do the work yourself
(and there is no shame in admitting this isn't your cup of tea), take the
machine to a professional computer repair shop (not your local equivalent
of BigComputerStore/GeekSquad). Please be aware that not all local shops
are skilled at removing malware and even if they are, your computer may be
so infested that Windows will need to be clean-installed. If possible, have
all your data backed up before you take the machine into a shop.

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!

Posted by SS on May 1, 2008, 4:31 pm
Please log in for more thread options
On Wed, 30 Apr 2008 07:27:21 -0700, Malke


>
>http://www.bleepingcomputer.com/forums/topic143309.html
>

The above seems to have worked!

It was actually quite easy -- though the full scan
by SuperAntiSpyware took hours and hours.

Thank you so much...and sorry about the image
posts...I'll try to remember that in the future.

SS

Posted by David H. Lipman on May 1, 2008, 8:51 pm
Please log in for more thread options

| On Wed, 30 Apr 2008 07:27:21 -0700, Malke



>>http://www.bleepingcomputer.com/forums/topic143309.html


| The above seems to have worked!

| It was actually quite easy -- though the full scan
| by SuperAntiSpyware took hours and hours.

| Thank you so much...and sorry about the image
| posts...I'll try to remember that in the future.

| SS

There was nothing wrong with the "image posts".

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Malke on May 2, 2008, 7:10 am
Please log in for more thread options
SS wrote:

> On Wed, 30 Apr 2008 07:27:21 -0700, Malke
>
>
>>
>>http://www.bleepingcomputer.com/forums/topic143309.html
>>
>
> The above seems to have worked!
>
> It was actually quite easy -- though the full scan
> by SuperAntiSpyware took hours and hours.
>
> Thank you so much...and sorry about the image
> posts...I'll try to remember that in the future.

I'm very glad that worked for you. As David Lipman said, there was nothing
wrong with posting a link to an image; it was the three separate posts I
wasn't crazy about. But no harm, no foul. ;-)

Thanks for taking the time to let us know everything is resolved.

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!

Similar ThreadsPosted
Help... Mystery Popup Virus?? (another try) April 30, 2008, 10:15 am
Re: Help...Mystery Popup Virus??? (another try to send screen images) (1/3) April 30, 2008, 10:23 am
Re: Help...Mystery Popup Virus??? (another try to send screen images) (2/3) April 30, 2008, 5:32 pm
Popup before login November 9, 2005, 12:59 pm
Unwanted popup January 10, 2007, 5:03 pm
mp3 files cause popup in WMP after 10sec June 19, 2008, 12:15 pm
first time internet exp 7 user - drive cleaner popup warning January 13, 2007, 12:09 am
Unicode Popup Window prior to CTL-ALT-DEL window June 10, 2005, 1:55 pm
HELP: Virus is preventing me from installing anti virus software!! January 11, 2007, 2:17 am
I have a virus that uses "anti virus software" downloads as a cover up March 24, 2007, 1:40 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap