Massassi Forums Logo

This is the static archive of the Massassi Forums. The forums are closed indefinitely. Thanks for all the memories!

You can also download Super Old Archived Message Boards from when Massassi first started.

"View" counts are as of the day the forums were archived, and will no longer increase.

ForumsDiscussion Forum → need a popup blocker for i.e.
12
need a popup blocker for i.e.
2005-04-10, 4:16 PM #1
that stupid spyware program that has taken a strangle-hold is selecting the key words on certain pages (I know it is spyware because in non-hotlink urls on a search page will also show up as a link, i used amino acid) has gotten worse.

in imdb, one Thomas Ian Griffith is listed as being in the movie xXx in his profile page. the problem is that going into that page brought up an ad for a porn site (and worse, it was uncenored with no warning, can you say illegal). I have used both spybot and ad-aware, to no avail.

I will slap around with a large anyone who suggests getting a new browser. I am not that desperate yet.

however, if the problem of a program searching for key words changeing them into a hotlink for advertising, please tell me what it might be and how I could fix it.
Snail racing: (500 posts per line)------@%
2005-04-10, 4:21 PM #2
A popup blocker for IE? They call it firefox. Seriously, have you tried it? It's not a level to which you resort, it's a light to which you turn on.

JediKirby
ᵗʰᵉᵇˢᵍ๒ᵍᵐᵃᶥᶫ∙ᶜᵒᵐ
ᴸᶥᵛᵉ ᴼᵑ ᴬᵈᵃᵐ
2005-04-10, 4:24 PM #3
Quote:
Originally posted by jEDIkIRBY
A popup blocker for IE? They call it firefox. Seriously, have you tried it? It's not a level to which you resort, it's a light to which you turn on.

JediKirby



Pretty much.
"Jayne, this is something the Captain has to do for himself"

"N-No it's not!"

"Oh."
2005-04-10, 4:24 PM #4
I agree with the other 2, trust us just try it. I was just as stubborn and foolhardy as you are now until I gave it a try.
America, home of the free gift with purchase.
2005-04-10, 4:25 PM #5
Quote:
Originally posted by jEDIkIRBY
A popup blocker for IE? They call it firefox. Seriously, have you tried it? It's not a level to which you resort, it's a light to which you turn on.

JediKirby


He wasnt asking for an alternative to IE. Seriously, posts like this are obnoxious, and I wish people wouldnt make them.

Alpha1, I suggest you try google's toolbar, available at http://toolbar.google.com if I recall correctly. It's got a popup blocker built into it.
2005-04-10, 4:28 PM #6
Back when I was using IE, the Google toolbar did a great job of blocking popups.
2005-04-10, 4:28 PM #7
I agree with the other 3, trust us just try it. I was just as stubborn and foolhardy as you are now until I gave it a try.
Think while it's still legal.
2005-04-10, 4:29 PM #8
/me goes on a trout slapping rampage.

again, the popup blocker just gets rig of the nasty things like that pr0n ad that appeared because an actor's biography page listed them as having been in the movie xXx. the real problem is the program that scans the text of the page and turns normal words that match buisnesses that are probably their clients and turns the word into a hotlink. that means it is intefering with the actual display of the webpage.

also, how big is fire-fox, because I am on 56k, so I will not do a very big download unless it is abolutely nessecary or it is something that I want.
Snail racing: (500 posts per line)------@%
2005-04-10, 4:30 PM #9
About 5MB (4.7)
Think while it's still legal.
2005-04-10, 4:31 PM #10
Quote:
Originally posted by Shintock
Back when I was using IE, the Google toolbar did a great job of blocking popups.


I dont want to use more stuff that could invite spyware.
Snail racing: (500 posts per line)------@%
2005-04-10, 4:32 PM #11
Link
Think while it's still legal.
2005-04-10, 4:32 PM #12
As a dedicated IE user, here's my advice:

For popup and ad blocking, I recommend using the ZoneAlarm firewall's popup and ad blocking. This will also help protect you if you still manage to get malware.

To remove the malware on your system, download
HijackThis and restart in Window's safe mode. Run HijackThis and eliminate the nasty BHOs and malware that are running when you start your computer. As long as you kill anything malicious from starting up, it'll be safe to restart into normal Windows. After restarting go ahead and run AdAware/SpyBot to clean up whatever's left over (HijackThis doesn't delete the malware, it just stops it from starting up).

I'd say don't give up on IE, FireFox is the cowards way out and is meant for internet newbies. ^_~

QM
2005-04-10, 4:32 PM #13
Google Toolbar doesnt "invite spyware" at all.
2005-04-10, 4:34 PM #14
ok, I have had bad experiance with toolbars in the past so I have just decided not to use them.
Snail racing: (500 posts per line)------@%
2005-04-10, 4:36 PM #15
The Google toolbar isn't malicious and would provide minor protection from malware (by blocking popups that may link to malware or prompt you to download malware).

QM
2005-04-10, 4:38 PM #16
I have the Google toolbar on IE..but I use Firefox anyway. 5mb really isn't that bad on dialup...I did it.. :p
woot!
2005-04-10, 4:54 PM #17
i think I may have found something, it found a process that I never noticed, "surfsidekick 2". it seems that this program is adware. has anyone else ever had this program?
Snail racing: (500 posts per line)------@%
2005-04-10, 4:55 PM #18
The newest version of IE has a pop-up blocker, as I recall.
Pissed Off?
2005-04-10, 5:14 PM #19
surfsidekick is nasty. If you want to post a screenshot of what HijackThis displays, I could tell you which are bad.

If you didn't download HijackThis, a screenshot of your process list would be helpful to help you to a lesser extent.

Or if uploading is too slow because of your bandwidth, you could retype the contents of either of the above stated paragraphs.

QM
2005-04-10, 5:18 PM #20
The Service Pack 2 popup blocker works better than anything else I've used, sans Firefox.
Bassoon, n. A brazen instrument into which a fool blows out his brains.
2005-04-10, 5:21 PM #21
Logfile of HijackThis v1.99.1
Scan saved at 10:15:25 AM, on 11/04/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\mxolqj.exe
C:\Program Files\Windows AdControl\WinAdCtl.exe
C:\WINDOWS\System32\qttask.exe
C:\WINDOWS\Xhrmy.exe
C:\Program Files\Windows AdControl\WinAdAlt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\BOINC\boinc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\System32\macromed\flash\GetFlash.exe
C:\WINDOWS\System32\filmspsv.exe
C:\WINDOWS\System32\fld_b5_mvssk9.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BOINC\projects\setiathome.berkeley.edu\setiathome_4.09_windows_intelx86.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.abc.net.au/
R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - C:\Program Files\SurfSideKick 2\SskBho.dll
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\dlmax.dll
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: LinkTracker Class - {6A6E50DC-BFA8-4B40-AB1B-159E03E829FD} - C:\WINDOWS\System32\lmf32v.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [yflsxlydl] C:\WINDOWS\System32\mxolqj.exe
O4 - HKLM\..\Run: [Windows AdControl] C:\Program Files\Windows AdControl\WinAdCtl.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [xhrmy] C:\WINDOWS\Xhrmy.exe
O4 - HKLM\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [xs3U3FV] fld_b5_mvssk9.exe
O4 - HKLM\..\RunOnce: [SpyBotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [gBs8RPZ3j] filmspsv.exe
O4 - HKCU\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.truearth.com/prod_1km/roamer_content.htm
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=f8bb819d39a452568f2050f9dd60df500bbfac215562a95f4b74c96018ebde55a21cf13ec31fae647236815860e98320e60f5e:4eeef86d2c2dc7ba33e11a32ab8e2e83
O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) - http://www.skylinesoft.com/interactive/terraexplorer/install/TEInstallPlugIn.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4CFB425E-F509-403E-880B-C4087658CAF0}: NameServer = 210.80.58.42 210.80.58.34
O18 - Filter: text/html - {DFAA31C8-A356-4313-9D95-5EDAB46C5070} - C:\WINDOWS\System32\lmf32v.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

that is the loglist that hijackthis displays.
Snail racing: (500 posts per line)------@%
2005-04-10, 5:24 PM #22
Not even the Firefox popup blocker gets everything.

Anywho.

Get XP Service Pack 2, it vastly improves the security in windows.

Get Microsoft AntiSpyware it is far better than Spybot and Adaware. I'm a regular IE user and I haven't had any spyware problems since installing it.
Detty. Professional Expert.
Flickr Twitter
2005-04-10, 5:27 PM #23
i think i have found the source of that annoying advertising, "farmmext". haven't done anything about it, but i did a search and it has a description of one of my problems.
Snail racing: (500 posts per line)------@%
2005-04-10, 5:30 PM #24
I don't have any spyware problems with Firefox.
2005-04-10, 5:32 PM #25
My advice:

1. Use Firefox, a wonderful browser. It blocks some pop-ups on its own.

2. Get ad-aware.

3. Do some hunting in Windows Explorer and the Registry. Look for peculiar or unfamiliar file folders (usually in the Windows or Program Files folder) or blatantly obvious elements that should be removed . . .

Yeah, it will take time but take up the fight against ***** like adware.
2005-04-10, 5:34 PM #26
IE now comes standard with a popup blocker.

and yeah do what everyone told you to
一个大西瓜
2005-04-10, 5:34 PM #27
in fact, there seems to be a number of nasty programs on this computer. :(
Snail racing: (500 posts per line)------@%
2005-04-10, 5:36 PM #28
Ok, alpha1, the following are likely malicious:
C:\Program Files\Windows AdControl\WinAdCtl.exe
C:\Program Files\Windows AdControl\WinAdAlt.exe

O4 - HKLM\..\Run: [Windows AdControl] C:\Program Files\Windows AdControl\WinAdCtl.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe

The following are DEFINATELY malicious:
C:\WINDOWS\System32\mxolqj.exe
C:\WINDOWS\Xhrmy.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\System32\filmspsv.exe
C:\WINDOWS\System32\fld_b5_mvssk9.exe
C:\Program Files\CxtPls\CxtPls.exe

R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - C:\Program Files\SurfSideKick 2\SskBho.dll
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\dlmax.dll
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: LinkTracker Class - {6A6E50DC-BFA8-4B40-AB1B-159E03E829FD} - C:\WINDOWS\System32\lmf32v.dll
O4 - HKLM\..\Run: [xhrmy] C:\WINDOWS\Xhrmy.exe
O4 - HKLM\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [xs3U3FV] fld_b5_mvssk9.exe
O4 - HKCU\..\Run: [gBs8RPZ3j] filmspsv.exe
O4 - HKCU\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O18 - Filter: text/html - {DFAA31C8-A356-4313-9D95-5EDAB46C5070} - C:\WINDOWS\System32\lmf32v.dll

The following may or may not be malicious, and can be gotten rid of with no ill effects:
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MT...mer_content.htm
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...3e11a32ab8e2e83
O16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) - http://www.skylinesoft.com/interact...stallPlugIn.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/c...DC_1_0_0_44.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab

I do not know what the following is:
O17 - HKLM\System\CCS\Services\Tcpip\..\{4CFB425E-F509-403E-880B-C4087658CAF0}: NameServer = 210.80.58.42 210.80.58.34

The following isn't malicious, but getting rid of it wouldn't be bad:
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe

---

That should be everything. You have quite a bit of nasty stuff on your computer.

QM
2005-04-10, 5:37 PM #29
Quote:
Originally posted by alpha1
in fact, there seems to be a number of nasty programs on this computer. :(


so follow the link in my post, download the program, install it, run it, PURGE SYSTEM OF EVIL.
Detty. Professional Expert.
Flickr Twitter
2005-04-10, 5:37 PM #30
Quote:
Originally posted by JDKNITE188
My advice:

1. Use Firefox, a wonderful browser. It blocks some pop-ups on its own.

2. Get ad-aware.

3. Do some hunting in Windows Explorer and the Registry. Look for peculiar or unfamiliar file folders (usually in the Windows or Program Files folder) or blatantly obvious elements that should be removed . . .

Yeah, it will take time but take up the fight against ***** like adware.


read first post, already have adaware and have run it.

hijack this has found about five things that upon googleing the name of, have turned out to be adware. and the processes are suposedly running according to hijackthis, but they dont appear in the windows task manager.
Snail racing: (500 posts per line)------@%
2005-04-10, 5:38 PM #31
Quote:
Originally posted by DeTRiTiC-iQ
so follow the link in my post, download the program, install it, run it, PURGE SYSTEM OF EVIL.


already downloading.
Snail racing: (500 posts per line)------@%
2005-04-10, 5:39 PM #32
Quote:
and the processes are suposedly running according to hijackthis, but they dont appear in the windows task manager.
There are ways of hiding programs from showing up on the task manager.

QM
2005-04-10, 5:43 PM #33
how do I make them appear?
Snail racing: (500 posts per line)------@%
2005-04-10, 5:45 PM #34
You can't, you need to restart in safe mode (where they won't be running at all) then delete them and remove them from starting up.

QM
2005-04-10, 5:49 PM #35
Quote:
Originally posted by Shintock
I don't have any spyware problems with Firefox.


Me niether. Firefox if by far superior to I.E.
2005-04-10, 5:53 PM #36
nothing to see here >.>
[01:52] <~Nikumubeki> Because it's MBEGGAR BEGS LIKE A BEGONI.
2005-04-10, 5:58 PM #37
Btw -- I'm on dialup, and Firefox seems at least 3x faster than IE when it comes to page loading..it's worth the d/l.
woot!
2005-04-10, 6:03 PM #38
Firefox wins. Seriously, if you don't want it, it's either because of ignorance, or you frequent way too many horribly made sites (i.e. sites that only work in IE)
D E A T H
2005-04-10, 6:19 PM #39
HOLY MOTHER OF GOD!!!

I am running microsoft anti spywarre and it has found some real nasties.

it has found the link replace though, yay.

but still :eek: is all I have to say.
Snail racing: (500 posts per line)------@%
2005-04-10, 7:12 PM #40
TGIF - Thank God it's Firefox! :)
My JK Level Design | 2005 JK Hub Level Pack (Plexus) | Massassi Levels
12

↑ Up to the top!