PDA

View Full Version : Browser Hijack/Pop-up Problems


Logan
06-22-2004, 08:40 PM
Let me first start by saying that I did a quick search of people's past computer problems, tried some of the recommendations, and I'm still stuck...so here we go...

A few months ago I started getting really annoyed about pop-ups. Got pointed in the direction of Spybot and it helped to an extent. But once I got introduced to Google toolbar, the pop-ups completely stopped. Wonderful!

Until yesterday. I fired up IE, and it looked like my browser was hijacked to some kind of a bargain shopping/travel/medicine site. Pop-ups started flying. Quickly closed everything, changed my home page back, and was able to restart IE and go directly to ESPN.

I ran both Spybot and Ad-aware, which found problems and removed them. It didn't actually fix anything unfortunately.

Thought I would re-install Google toolbar. I did that, and it does block certain pop-ups (37 today), but the ones advertising vacations/pills/bargains are still coming through. Also, I will get about 6 or 7 of those gray boxes at once, asking if I would like to download and install some type of program. Obviously, I'll click no, and it then tells me that "this a one time pop up. If you click OK, it will no longer continue;" to which I Ctrl-Alt-Del to get away from.

Also, every time I restart, I know have three new icons on my desktop: "STC.exe," "myPCsearch", and "Free Travel Voucher Coupon." By looking at the properties of the first two, I see they are coming from C:\Program Files\STC. I tried deleting that entire folder, along with the icons, but it returned once I rebooted (and that directory is now back in place).

If anyone has any advice, or can point me anywhere for guidance, it would be greatly appreciated.

SirFozzie
06-22-2004, 08:43 PM
Mozilla. FireFox.

Adaware
HijackThis

Ajaxab
06-22-2004, 09:42 PM
Let me first start by saying that I did a quick search of people's past computer problems, tried some of the recommendations, and I'm still stuck...so here we go...

A few months ago I started getting really annoyed about pop-ups. Got pointed in the direction of Spybot and it helped to an extent. But once I got introduced to Google toolbar, the pop-ups completely stopped. Wonderful!

Until yesterday. I fired up IE, and it looked like my browser was hijacked to some kind of a bargain shopping/travel/medicine site. Pop-ups started flying. Quickly closed everything, changed my home page back, and was able to restart IE and go directly to ESPN.

I ran both Spybot and Ad-aware, which found problems and removed them. It didn't actually fix anything unfortunately.

Thought I would re-install Google toolbar. I did that, and it does block certain pop-ups (37 today), but the ones advertising vacations/pills/bargains are still coming through. Also, I will get about 6 or 7 of those gray boxes at once, asking if I would like to download and install some type of program. Obviously, I'll click no, and it then tells me that "this a one time pop up. If you click OK, it will no longer continue;" to which I Ctrl-Alt-Del to get away from.

Also, every time I restart, I know have three new icons on my desktop: "STC.exe," "myPCsearch", and "Free Travel Voucher Coupon." By looking at the properties of the first two, I see they are coming from C:\Program Files\STC. I tried deleting that entire folder, along with the icons, but it returned once I rebooted (and that directory is now back in place).

If anyone has any advice, or can point me anywhere for guidance, it would be greatly appreciated.


I, too, would love the help. The "STC.exe", "myPCsearch" and "Free Travel Voucher Coupon" have appeared recently on my machine as well. I've tried Adaware and the latest version of Symantec to no avail. They get rid of the icons on my desktop, but I still have the viruses at startup. I have also run Avast and it finds a trojan virus named "optimize.exe" and another one I can't remember at the moment. But it just won't deal with them. I'm still getting an avalanche of popups when I attempt to use explorer.

I have started using Firefox and find that the popups have been greatly reduced, but they still appear occassionally as Explorer popups for reasons I don't understand.

I still have the problem where my computer wants to constantly connect to the internet when I'm offline. I'm wondering if one of these seemingly unstoppable viruses constantly tries to push you online in order to generate popups. If it can't find an online connection, it tells me I need to connect to get Internet content (the popup). If anyone has any ideas, I would greatly appreciate it.

Rizon
06-22-2004, 10:15 PM
1) Run an up-to-date virus scan. AVG is free online.

2) Do the typical Adaware/Spybot/Hijackthis thing

3) Download Tracks Eraser Pro, and use the 'free 15 day trial' to clear it off

4) Search Google for a manual delete. This is usally a major pain in the ass, cause these things typically keep renaming themselves in your registry as hard to find names like CXM2343SDM233dmn, and finds ways to keep reinstalling itself if you delete it.

Rizon
06-22-2004, 10:16 PM
5) Check Start/Run/MSconfig, and go through your startup list. I think some of these things add themselves to startup. At least this way you can see what directory its coming from and can delete some of the files. But you're still 95% screwed.

Rizon
06-22-2004, 10:18 PM
Manual delete for myPCsearch (http://forums.techguy.org/showthread.php?p=1689087)

Rizon
06-22-2004, 10:19 PM
Manual delete for STC.exe (http://www.kephyr.com/spywarescanner/library/2ndthoughtadware/index.phtml)

Rizon
06-22-2004, 10:23 PM
More help (http://www.securemost.com/articles/trou_3_remove_2nd-thought.htm) for STC.exe

And more (http://www.2-spyware.com/parasite-2nd-thought.html)

I see Pestpatrol (http://www.pestpatrol.com/) recommended. I've never used it, so I don't know how good it is, or if there is a free version.

Cuckoo
06-22-2004, 11:00 PM
I know this won't make you happy for me to say, but I try to keep my machine fairly lean for situations such as this. Format and reinstall. And remember what you might have done to get this crap. Get a good firewall and hope it helps in the future.

I spent about four days trying to figure out what a problem was a few weeks ago. Although I finally figured it out, it would have been easier for me to format and reinstall everything.

Just my $.02.

Logan
06-22-2004, 11:22 PM
Thanks a ton Rizon. I'm going to get to all of that stuff you posted when I get home from work/class tomorrow night. I'll post how it goes.

Also, when I rebooted before reading this, something new popped up. It was an auto-install for something called WebRebates. Didn't ask me if I wanted to do it, but it automatically came up: WebRebates has been successfully installed.

Ran MSConfig and found it listed. Disabled it so hopefully that will take care of that piece.

bbor
06-22-2004, 11:35 PM
These browser hijackings are getting out of hand.

Logan
06-23-2004, 03:45 PM
These browser hijackings are getting out of hand.

Anyone who is responsible for these really should be taken out back and shot.

And no, I'm not kidding.

Logan
06-23-2004, 09:40 PM
Manual delete for myPCsearch (http://forums.techguy.org/showthread.php?p=1689087)

Well, this is where I started...unfortunately, I have very little clue as to what I'm doing. Since my log file doesn't match up exactly with the one posted, I'm unsure as to what to check. I think I might just be better off posting my log file and seeing if someone can give me some direct guidance.

Have you used this before? What are the rates of response/success?

Ajaxab
06-23-2004, 09:57 PM
I posted my Hijack This logfile this morning and got a reply before lunch. I followed their instructions and have since posted the log file my responder asked me to post after working through their advice. So we'll see what happens, but at least they responded quickly. Hopefully, you'll have a similar experience. I'm impressed so far. But I won't know if they've provided a solution just yet.

JPhillips
06-23-2004, 09:59 PM
For anyone who gets the first search page of Google hijacked get CWShredder. It took me a while to find it, but it beats the shit out of those annoying Cool Web Search hijackings.