Results 1 to 12 of 12

Thread: Popup ads are killing me, Malicous Urls **RESOVLED**

  1. #1

    Thread Starter
    Hyperactive Member
    Join Date
    Jun 2002
    Posts
    352

    Angry Popup ads are killing me, Malicous Urls **RESOVLED**

    I had somehow visted a website that planted some type of virus or malicous url on my PC. I call it malicous because it randomly pops up ads (including porn) whenever I am on the Internet. As far as I can tell, it does not delete files or settings. I finally downloaded a popup manager and added many of the bad urls to the hosts file as 127.0.0.1 so that they would not display. But it is still a problem, sometimes my popup manager WILL CLOSE UP TO 50 WINDOWS IN ONE SECOND.

    I have tried clearing my cache, my history, and cookies but the popups still occur.

    One of the urls that routinely come up is

    traffic4sure

    How can I clear this crap...please help!!!
    Last edited by easymoney; Nov 4th, 2002 at 07:09 PM.

  2. #2
    So Unbanned DiGiTaIErRoR's Avatar
    Join Date
    Apr 1999
    Location
    /dev/null
    Posts
    4,111
    You may have gain, or some other spyware installed, check your processes.

  3. #3

    Thread Starter
    Hyperactive Member
    Join Date
    Jun 2002
    Posts
    352
    I checked the task manager, there is only one process I cannot account for...

    pdie.exe

    That maybe a win32 process, I am not sure.


    This is the url that caused started the problem.

    Please DO NOT USE THIS URL, I am not sure if it is still active:

    http://www.traffic4sure.xxx/tmcpro/g...id=netfavorite

    I replaced the .com with .xxx so that you will not reach the server.

    Once I visited this url, a bunch of popup ads occured, and now they are the same ads everytime now, just random frequencies, etc....
    Last edited by easymoney; Oct 15th, 2002 at 02:13 AM.

  4. #4
    Lively Member
    Join Date
    May 2002
    Posts
    94
    The only thing i can offer you is to visit lavasoft and download Ad Aware. This should tell you if you have any Spyware on your machine... and also lets you remove it

    http://www.lavasoftusa.com/downloads.html

    Post back if it works.

    Gav

  5. #5
    Black Cat JoshT's Avatar
    Join Date
    Nov 2000
    Location
    WNY, USA
    Posts
    4,032
    I would advise running Ad-aware as well. You may also consider using a web browser other than IE if you are not already doing so.
    Josh
    Get these: Mozilla Opera OpenBSD
    I have books for sale: "MCSD in a Nutshell" and "VB Distributed Exam Cram" - PM me for details. Will also trade for a decent ATX Pentium 2 MB/CPU/RAM combo.

  6. #6
    Addicted Member Celest's Avatar
    Join Date
    Jun 2001
    Posts
    134
    I would also advise getting a Virus Scanner as most have remote script blocking as standard now.

  7. #7
    PowerPoster MidgetsBro's Avatar
    Join Date
    Oct 2000
    Location
    Apparently, Internet.com
    Posts
    3,125
    You make sure you don't have anything like KaZaA running in the background? That thing always pops up ads when it's open.
    <removed by admin>

  8. #8
    PowerPoster techgnome's Avatar
    Join Date
    May 2002
    Posts
    34,687
    Originally posted by JoshT
    I would advise running Ad-aware as well. You may also consider using a web browser other than IE if you are not already doing so.
    I recommend Ad-Aware too....
    I also recommend Mozilla browser... it has a checkbox in its prefs area that allows you to block popup windows, unless you specifically click a link. IT works great! I had no idea how many ads I was "missing" until one day I used IE and visited some of the same sites..... What a difference!
    * I don't respond to private (PM) requests for help. It's not conducive to the general learning of others.*
    * I also don't respond to friend requests. Save a few bits and don't bother. I'll just end up rejecting anyways.*
    * How to get EFFECTIVE help: The Hitchhiker's Guide to Getting Help at VBF - Removing eels from your hovercraft *
    * How to Use Parameters * Create Disconnected ADO Recordset Clones * Set your VB6 ActiveX Compatibility * Get rid of those pesky VB Line Numbers * I swear I saved my data, where'd it run off to??? *

  9. #9

    Thread Starter
    Hyperactive Member
    Join Date
    Jun 2002
    Posts
    352
    Thanks everyone. I will it out and post back when I find a solution.

  10. #10
    Fanatic Member sbasak's Avatar
    Join Date
    Aug 2001
    Location
    Globe Trotter
    Posts
    524
    You may like using crazy browser (www.crazybrowser.com). It can block pop-up ads and also opens webpages in multiple document interface format.
    Life is a one way journey, not a destination. Travel it with a smile and never regret anything.
    Yesterday is history, tomorrow is a mystery, today is gift - that's why we call it present.

  11. #11
    ^:^...ANGEL...^:^ wrack's Avatar
    Join Date
    Mar 2002
    Location
    Melbourne, AUSTRALIA
    Posts
    2,695
    also get a popup stopper and ad aware...also if you are using XP or ME then go to start->run and type in msconfig and it will comeup with a screen which will let you configure your startup programs.

    About that p***.exe file you were talking about...search on that file and right click on it and property and then see summary and see which compnay it belongs to...and see what u can do with it...

    Cheers...

  12. #12

    Thread Starter
    Hyperactive Member
    Join Date
    Jun 2002
    Posts
    352
    Description
    An Internet Explorer toolbar offering a search feature and possibly also link buttons. When used, the user is sent to the targeting web site, which is one of the very similar sites tinybar.com, allcybersearch.com, gocybersearch.com, topsearcher.com or znext.com.

    More recently the script also seems to be used by 'Traffic Redirection' to do the same with their sites traffic4sure.com and errorpage404.com.

    When it is installed it also sets the IE search settings to point to the site.

    Variants
    All these sites have also operated home-page hijackers, so you may have a program installed that resets your home page and search bar settings to point to one of these sites as well as, or instead of, TinyBar.

    Also known as
    JS_TRAFFICHBAR.A by Trend Micro anti-virus.

    Distribution
    Installed by exploitation of an security hole in the Microsoft Java Virtual Machine through Internet Explorer, when visiting one of the named sites or perhaps through pop-up advertisements from them. May also be included in some releases of Zero Popup (zeropopup.com; not the similarly-named product from 'Tooto technologies') and Internet Eraser (internet-eraser.com), both products sold by the same author.

    What it does
    Advertising
    No.

    Privacy violation
    No.

    Security issues
    No. (Not to do with the toolbar itself, but if it has managed to install itself your browser is vulnerable and should be patched.)

    Stability problems
    Yes. May cause startup to be slow. The installation exploit itself may also cause IE to crash.

    Removal
    Spybot S&D can remove TinyBar.

    Manual removal
    The toolbar is implemented as a page 'tinybar.html' or 'hb.html' inside the Windows System (or System32 in Windows NT/2000/XP) folder. Delete this file along with the registry file 'br.reg', 'br.dll' or 'hb.reg'.

    Then to stop IE trying to load the page as a toolbar, open the registry (Start->Run->regedit) and delete the following keys:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\{69555BE2-9A78-11d2-BA91-00600827878D}
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\{69555BE2-9A78-11d2-BA91-00600827878D}
    HKEY_CLASSES_ROOT\CLSID\{69555BE2-9A78-11d2-BA91-00600827878D}
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\>>> Search The Web <<<
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ITBarLayout
    (In some variants of TinyBar, the classid starts with '69550BE2-...' instead of '69555BE2-...'.)

    Finally use Internet Options->Programs->Reset Web Settings to remove its search page.

    Hijacker removal
    Before the settings can be restored you must remove the hijacker that is run on every restart. In the registry (Start->Run->regedit), find the key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    and remove any entries of the form 'regedit /s C:\Windows\System\sp.dll'. Then delete sp.dll (or sp.reg) in the System folder. Then use Reset Web Settings to get the normal search page back.

    Links
    Asher Nahmias is the antisocial coder behind these sites; he sells deliberately deceptive web scripts for absurd prices at trixscripts, including customised versions of TinyBar.

    The security hole being exploited to install TinyBar is described by Microsoft here. You can get a patched JVM through Windows Update, or alternatively you can disable Java or install Sun's JVM instead (which is a bit more up-to-date and not vulnerable).


    and.doxdesk.com

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width