Board logo

Ad pop up
Surrey Dave - 18/3/04 at 12:39 AM

Help Please Boffins!!!

I have an annoying little pest in my computer that opens a pop up window when i open and close internet explorer, also some times changes home page to a gambling site.

I've run something called Ad Aware and it find all sorts of scary things but the pop up keeps coming .

got any ideas, last time i had something like this it was an active x thing!!

Is there any decent FREE software for sorting this , 'cos i'm tight that 's why i built a 'LOCOST'


greggors84 - 18/3/04 at 12:50 AM

ive got the google toolbar, i havent seen a pop up in ages. If you need pop ups on a certain page u can disable it for that page by a click of the button. It also has the advantage if being able to search things quickly. Go to google, and tools at the bottom.

sgraber - 18/3/04 at 03:57 AM

There are a number of resident 'Spy-style' programs that attempt to pop-up windows like that. You may have inadvertently installed it when you installed a program like Kazaa or AudioGalaxy.

All hope is not lost however. Install and run a program named 'SpyBot Search and Destroy'. It is amazing. On top of finding all of those nasty programs that cause pop-ups, spy on you, log your keystrokes, it has a feature called 'Immunize' which will aslo block all sorts of 'tracking cookies'.

Almost 14 million downloads from - DOIT!!!

I find that the use of AdAware, SpybotS&D and Evidence Eliminator together keep my system running well. The Google toolbar is an amazing Must-Have tool that blocks pop-ups as well as any other I have tried and is free to boot.

Don't forget Antivirus - AVG Antivirus is world-class and it's free too!


pbura - 18/3/04 at 05:59 AM

Another product that I recommend highly is Pest Patrol, which detects, cleans, and prevents worms and hijacking trojans, along with the spyware and adware. Well worth $40, IMO. They have a free online scan that identifies problems but does not fix them, which would be interesting to run after cleaning your computer with the free programs:

I also use Spybot, AdAware, and (free) Trend Micro virus scanner:

Norton is overrated, IMO. I've seen some machines that were clogged with adware and hijacker junk, all the while running Norton.


Staple balls - 18/3/04 at 06:10 AM

i wouldn't expect norton to keep spyware out, it's a virus scanner, not an antispyware app.

secondly, in my opionion AVG anti-virus isn't all that good, friends have got viruses while using it that it just hasn't picked up.

to some level, a software firewall may help, that way you can see and stop any traffic going to any dodgy apps/viruses....

but as i'm sure chrisW will appear and mention, most software firewalls make a fuss about a lot of unimportant stuff so you feel like they're doing a job

blueshift - 18/3/04 at 07:59 AM

Originally posted by Staple balls
but as i'm sure chrisW will appear and mention, most software firewalls make a fuss about a lot of unimportant stuff so you feel like they're doing a job

I know you may be intententionally simplifying, but with software firewalls it's more the case that they aren't smart enough to tell what is an attack and what's harmless / a mistake / something you intended, so they tend to veer on the side of paranoia (and so they should).

The problem is that software firewalls don't include an intelligent human network administrator in the box, and if the user doesn't take the time to understand how it works and how to set it up (which to understand completely means learning beyond degree-level computer networking theory and experience) you're always going to have this kind of problem.

Many people install them and forget about them as some kind of placebo.

Dunno why I felt the need to go on a ramble about software firewalls there.. ho hum.

For those interested, I'm a FreeBSD (UNIX) administrator and do my firewalling on that.

[Edited on 18/3/04 by blueshift]

Staple balls - 18/3/04 at 08:09 AM

i'm simplifying quite a lot.

as for the *nix firewall box, i think in 90% of locosters cases, that'd be a leedle overkill, myself, i just don't get on with *nix, i have basic understanding, but not a fan

but something like sygate personal firewall is free, and i've found it to be very good for a free software firewall (this box is sitting out in the DMZ for ease of stuff)

David Jenkins - 18/3/04 at 09:13 AM

You could try a different browser, as non-MicroSnot ones usually allow you to control pop-ups.

For a start, you could try Opera or Mozilla - both are free (the free Opera has ads in a little window in the top banner, but you can ignore them). Both work in a similar way to IE, but are often faster in operation.

I use Mozilla exclusively now, mostly because I use Win 2000 at work and Linux at home, and Mozilla works identically on both. I only use IE to access sites where the authors are too lazy to write for all browsers (not that many cases).



JoelP - 18/3/04 at 10:36 AM

Originally posted by Staple balls
secondly, in my opionion AVG anti-virus isn't all that good, friends have got viruses while using it that it just hasn't picked up.

i agree there, though its a nice free program its never found anything on my computer - literally, nothing at all! StopScan seems good at finding adware and spywares but doesnt help you remove them unless you subscribe. just gives a list of files, which can be hard to find sometimes.

Peteff - 18/3/04 at 10:48 AM

What OS are you using and have you got all your updates installed? There is a program called Shoot the Messenger that closes a port left open by MSN for their own purposes which is used to open popups. Google it, it might help. I use AVG and it picked up 3 infections last week. If you update it regularly it is good. I have received several updates in one day sometimes.

Staple balls - 18/3/04 at 10:49 AM

don't install sh!te on your puter

believe it or not, it tends to work quite well, adaware only tends to pick up cookies.

pbura - 18/3/04 at 01:13 PM

Originally posted by Staple balls
i wouldn't expect norton to keep spyware out, it's a virus scanner, not an antispyware app.

Didn't say that it was, but I should have qualified my statement better. I meant that you can have your computer hijacked, or at least your browser, right under Norton's nose and have your computer seriously degraded.

To be fair to Symantec, they have other applications for computer security, adware, malicious scripts, etc., that I am sure are excellent if a bit pricey.

Speaking of free tools, they have a system security check that is tops. I ran it and found I had an open port on my machine:

As you said, not installing crap is best. Not opening e-mail attachments automatically, displaying file name extensions, closing popups from the task bar (not clicking anywhere on the popup), etc.

flak monkey - 18/3/04 at 01:55 PM

I run McAfee Internet Security and it blocks all my pop ups (sometimes too well) it allows you to block indirect cookies, it kills web bugs yadd yadder. All the stuff others claim to do but dont. I havent had any trouble at all. It always picks up viruses, trojans and worms no problem. And will usually delete them. If it wont it will help you delete them manually.

On top of that it automatically clears all the temporary internet files from non bookmarked internet sites when i close IE. And it has a handy file shredder to securly delete personal files.

It'll cost you £50 ish and something like £10 a year to get unlimited updates. IN all i think its well worth investing in.

As for the problem Surrey Dave has, i had that for a while, it was a trojan from the exploitbyte-verify family. There are loads of them. But your virus scanner should pick it up. McAfee did, but you will have to manually reset you homepage, and may need some manual removal. See;

Im not saying that is the problem, but thats what it was when my computer did that.


The pic below is the 2 views of my Browser Buddie which is part of McAfee Net Security, allows you to quickly allow or disallow popups and cookes.... Rescued attachment browser bud.jpg
Rescued attachment browser bud.jpg

JoelP - 18/3/04 at 01:58 PM

cheers pete, i ran that check and apparently i have more open backdoors then a gay bar on friday night (their words not mine).

anyone know about a good personal fire wall? i though i had my windows one sorted but musta got confused...

flak monkey - 18/3/04 at 02:08 PM

McAfee is a great firewall....its part of the Internet Security package. It sits there and only makes a fuss when it need to. it automatically blocks certain communications, and lets you add programs to a safe list. It also logs firewall violations.

I am on a network of approaching 6000 computers and have a permanent internet connection at about 2mb/sec and have had so few attempted hacks, all of which have failed. Which is reassuring

If you really care loads the best thing is a hardware firewall, so much better than a software one.

I have heard little positive about Norton (Symantec is the same complany) infact i tried it and it was totally shyte, not a patch on McAfee. IMHO.

BTW the windows firewall is crap....


Staple balls - 18/3/04 at 02:52 PM

i swear by sygate personal fire

Surrey Dave - 18/3/04 at 07:20 PM

Have Run AdAware, Search and Destroy, deleted cookies, blocked cookie from the site i suspect ( something to do with Underground Games.

The window still opens after closing I.E. , is it a Trojan ? , whats good for finding these?
I'm getting Obsessed now!!!

Boffins Alert..................

Staple balls - 18/3/04 at 07:22 PM

when you open IE?

and have you tried a virus scan?

[Edited on 18/3/04 by Staple balls]

stephen_gusterson - 18/3/04 at 07:41 PM

I tried the anti spyware thing suggested in the first post. It found soem cookies and stuff.

However, it didnt fix a problem I have on a pc at work.

About once a day, the homepage gets changed to some bloody search engine called ccsearch or summat.

Anyone got a clue how I stop whatever it is from changing my IE homepage to this sodding thing?



Peteff - 18/3/04 at 08:42 PM

That is a malware symptom. The item puts an entry into your registry to trigger the page change. You can run a registy check if you change the settings in adaware to do so. It does a registry scan and a deep scan, but watch what you delete as you can cause problems. I use Spybot as well, another good free program which doesn't concentrate so much on cookies.

JoelP - 18/3/04 at 10:00 PM

Originally posted by flak monkey
And it has a handy file shredder to securly delete personal files.

my brothers mad about all that sort of stuff, he has stupidly complex encription programs and stuff that overrights deleted stuff 20 times to prevent it being seen be experts....

makes me wonder what he's up to!!

stephen_gusterson - 18/3/04 at 10:28 PM

Originally posted by Peteff
That is a malware symptom. The item puts an entry into your registry to trigger the page change. You can run a registy check if you change the settings in adaware to do so. It does a registry scan and a deep scan, but watch what you delete as you can cause problems. I use Spybot as well, another good free program which doesn't concentrate so much on cookies.


will take a look at that tomorrow!

Surrey Dave - 19/3/04 at 12:02 AM

My homepage is: freeserve.

And no I haven't tried an antivirus yet.

But I can delete files in Adaware or Spybot and the ad window still opens when I close I.E.

Could it be I need one of these programs that changes my id numbers to stop the ad site locking on to me?

Failing that a ****ing great mallet would do the trick.

The Internet is fantastic , but like most things we have twats outs there!!!!!!

Hellfire - 19/3/04 at 01:05 AM

as an auto install or overwriter don't these STUPID people realise that you actually use the hijacking pop-up LESS. Then you try your damnedest to be rid of it - vowing nver again to darken your door (even your back one!)

I am considering re-formatting my drive simly to be rid of all the SH*TE!

pbura - 19/3/04 at 01:08 AM

A nice little utility for killing off the type of hijackers reported by Steve G. and Surrey Dave is HijackThis, a free program available here:

Warning: This program lists ALL your start-up process, good and bad, so if in doubt as to what to delete, DON'T.

The malware usually appears as a BHO (browser helper object). Sometimes the BHO will be reinstalled at each system startup with a 'Run' command. These programs can be hard to spot, with names resembling Windows utilities.

If you guys would like, you can save the log and paste it here. Surely someone will be able to help.


Surrey Dave - 19/3/04 at 01:30 AM

trend antivirus found this little pest in the windows system folder.

had to start in 'safe' mode ,rename and delete.

this is a trojan bookmark that adds to your favourites and changes your homepage.

could be some of my prob...........

pbura - 19/3/04 at 01:40 AM

Originally posted by JoelP
i ran that check and apparently i have more open backdoors then a gay bar on friday night (their words not mine).

Surrey Dave - 19/3/04 at 01:47 AM

Still not cured

The url displayed in popup is:

This popup opens about 3 seconds after you close I.E.

Any more ideas welcome...........

sgraber - 19/3/04 at 01:59 AM

Read the last post in the thread. It explains in detail what is happening and how to remove it from your system. It's a real DOOZY of a problem!


Edit - sorry - NOT last post in thread.. But you'll find it just after the long paragraph written in CAPS...

[Edited on 3/19/04 by sgraber]

Surrey Dave - 19/3/04 at 02:07 AM

Thanks ,
I just found that too but i'm not clear how to do it yet , I'm tired , ( 2.00am in UK)I'll do it tomorrow..................

Thanks All............

What the frick is a 'DOOZY'................

sgraber - 19/3/04 at 02:11 AM

Originally posted by Surrey Dave
What the frick is a 'DOOZY'................

Hellfire - 19/3/04 at 02:25 AM

something new everyday...

Alan B - 19/3/04 at 02:42 AM

This was the definition I knew of...


doo·zy [ dzee ] (plural doo·zies)


something wonderful: a remarkable or excellent thing ( slang )

[Early 20th century. Origin uncertain: perhaps an alteration of daisy (perhaps blended with Duesenberg (a type of luxury car).]

not quite the same definition is it?....

pbura - 19/3/04 at 02:52 AM

(referring to solution posted by Steve Graber)

You must kill a running process so that HijackThis can remove the related file and registry entry. If you are running Windows 98 or Me (and maybe others), Task Manager won't show all the processes that are running on your computer.

Here's another favorite FREE utility, PrcView, that shows all running processes (along with a bunch of other crap I don't understand but Staple Balls would). With this, you can kill a process so that HijackThis can remove it.

Some may be reading this thread casually, thinking it doesn't apply to them, but the average user has acquired a ton of sludge on their computer.

I bought a year-old computer on eBay that was just clogged with crap. So bad, in fact, that the old owner hadn't used it in six months. But after applying these fixes, it runs like a top now.


P.S. Doozy=Corker

[Edited on 19/3/04 by pbura]

David Jenkins - 19/3/04 at 07:35 AM

There is plan B, if you're feeling adventurous... run Linux! (ducks behind parapet!)

I use it for almost all my home PC work, and if the Quicken accounting package came on Linux I would be 100% off Windows - that program is the only reason I have dual-boot on my machine. (Don't mention WINE - I've never got it working well enough to give up Windows)

I have set up my Windows with no access to the modem (it doesn't know the machine has one), it has a firewall that blocks every attempt to make a network connection, and so on... only Linux can see the real world.

The down-side is that even the easiest Linux distribution (Mandrake) requires a reasonable amount of technical knowledge, whereas Windows will run after a fashion, even if it's not set up right.



M@Triton - 19/3/04 at 07:44 AM

Not just me then...thats a relief.

I keep getting a pop up banner saying come and have a look at my webcam......description with it is kinda indicating a porn site but then i have been hit with so many virus things too paranoid to go and look.

Staple balls - 19/3/04 at 09:02 AM

Originally posted by David Jenkins
The down-side is that even the easiest Linux distribution (Mandrake) requires a reasonable amount of technical knowledge, whereas Windows will run after a fashion, even if it's not set up right.

i've not played with linux much, but i found fedora really easy to get set up, working and talking to the internet and all the other puters here (given that it's a usb adsl modem, and one of the computers is an xbox that thinks it's a pc...)

Surrey Dave - 19/3/04 at 10:42 AM

Thanks Pbura, I was wondering how to stop processes in Win98 as the tab they refer to in the fix is not there.

This forum got some knowledgable bods on it !!!!!

Staple balls - 19/3/04 at 10:50 AM

98 could be interesting, very different to me/2k/xp.

Staple balls - 19/3/04 at 10:53 AM

had a looksee, and i think (not used 98 for a long time)

you wanna hit ctrl + alt + delete which should bring up a window like

which may have the process you're looking for in it.

JoelP - 19/3/04 at 11:04 AM

when i do cnt alt del it says i have around 30 processes running, several of them called svchost.exe, which sounds a bit ominous....

off to google methinks.

apparently harmless...

[Edited on 19/3/04 by JoelP]

Staple balls - 19/3/04 at 11:14 AM

svchost.exe is harmless, part of windows, controls stuff

scvhost.exe and explore.exe (NOT explorer.exe) however are parts of viruses

Surrey Dave - 19/3/04 at 11:18 AM

Yehbut this Window doesn't give the option to kill a process , so i'll have to download the suggested utility later , when i'm at home.................

Staple balls - 19/3/04 at 11:23 AM

if you're pretty competent (and the machine's fast enough), i can sort you out with a copy of windows 2000 which'll fix a few problems, and be a bit shinier around the edges

Surrey Dave - 19/3/04 at 11:30 AM

Can I upgrade ( install over the top) my Win 98 to 2000?

And will it run with all my 98 applications?

Is it based on NT so do i need to reformat the HD to install?

I'd love a job in I.T. I'm ONLY 49 and willing to learn!!!!

Desperate of Surrey!

Peteff - 19/3/04 at 11:31 AM

Highlight the process in the window and click on end task to kill it (stop it running) in Windows 98. That's all it means. If you put 2000 on it gives you the choice of updating or dual booting with 98.

[Edited on 19/3/04 by Peteff]

Staple balls - 19/3/04 at 11:35 AM

Originally posted by Surrey Dave
Can I upgrade ( install over the top) my Win 98 to 2000?


And will it run with all my 98 applications?

should do, drivers etc will need updating to better versions though

Is it based on NT so do i need to reformat the HD to install?

Sort of, it uses a different (NTFS) filesystem which is more stable and less likey to lose data, but it'll convert it during the install

I'd love a job in I.T. I'm ONLY 49 and willing to learn!!!!

I would too, only 18 and don't care
enough to learn

Surrey Dave - 19/3/04 at 11:41 AM

Are ther any REAL advantages , I 've found Win98Se generally reliable/stable I dont do upgrading for the sake of it I'm too cynical for that , it seems that with every incarnation of Windows you actually NEED a faster computer just to run all the extra bells and whistles they put on it.

Or if you keep the same old (750 Athlon) everything just takes longer...........

[Edited on 19/3/04 by Surrey Dave]

pbura - 19/3/04 at 11:44 AM

Some "system" tasks don't show in Windows 98, hence the prob.

I really like Win 98SE, is very compact and controllable compared to some later versions. It runs well on my older machine.

Staple balls - 19/3/04 at 11:50 AM

it depends what you're after really, this thing is always on (and downloading crap) and had no problems whatsoever. also win2000 is still supported by microsoft, so updates are still very much available.

i'd say it'd probably run ok on your machine, i have a 2k box with a 1ghz duron and 256meg ram in the other room

GO - 19/3/04 at 12:03 PM

It'll run fine with win2k.

Machine at home is a P2 266 running win2k advanced server!! little bit on slow side but its not too bad, memory is more important, half gig ram (512Mb) is essential for w2k, the more the better though.

Staple balls - 19/3/04 at 12:05 PM

Originally posted by GO
half gig ram (512Mb) is essential for w2k, the more the better though.

really, you're very wrong on that, my other box is running on 256meg, and thet includes an FTP server and a gaming server (normally has 40-80 cpu players on it)

GO - 19/3/04 at 04:01 PM

when I say essential, what I mean is, if its your only machine and you want to use the machine directly for everyday stuff, browsing, spreadsheets etc, as I imagine is probably Surrey's situation, you wouldnt wanna be using it with much less than 512.

for running as a games server cpu speed is more critical.

Peteff - 19/3/04 at 04:15 PM

Due to demand, windows 98se support has been extended by microsoft till 2006 and has not been stopped as was previously planned in January of this year. We are still downloading updates for it from MSN on my wifes computer. I have 2000pro on a PII 333 with 192 meg and it runs well, no crashes yet and fast enough for web use.

Staple balls - 19/3/04 at 04:42 PM

GO, i'd still say 512 was overstating things a little. 256 is the ideal minimum, 128 the real minimum.

given that the other machine i mention is used to do a lot of normal home use as well.

i also have a 3rd box, being a 233 cyrix with 32 meg of ram on windows Me, that does bloody big spreadsheets (a business working at ~£250k turnover)

peteff, didn't realise about 98Se, what's the story on plain 98?

GO - 19/3/04 at 05:08 PM

only my experience, with 256 it was pretty horendous, 512 made a huge difference, but I am running w2kAS so its going to be most intensive on resources than standard. However, I have disabled most of the extra services so I wouldn't expect AS to make that much difference.

but equally, I'm not a network admin so its probably a long way from the most efficient setup.

Staple balls - 19/3/04 at 05:34 PM

true on both points, i'm really giving the minimum needed for basic use.

i find 1.5gig to be a little limiting for what i do, but then it i do quite a bit of video/photoshop work

Surrey Dave - 19/3/04 at 05:48 PM

Meanwhile back at my I.E./ popup problem, I do not appear to be finding the .exe files they talk about in the system32 folder.............

Surrey Dave - 19/3/04 at 06:34 PM

I think I found it in the System folder not system32.

64k exe file by TMAX.

deleted it and the registry key for it , so far so good.

i'm scared to close I.E now, in case it's lurking..........

Staple balls - 19/3/04 at 06:38 PM

first thing worth doing will be searching for a file called HOSTS on your computer

what you wanna do is edit the hosts file to contain the url for the the site the popup is loading (follow the same style as the other entries) and enter an ip address of so it appears as

this won't fix the popup, but it wll stop the page loading.

Peteff - 19/3/04 at 08:13 PM

Windows 98 and Windows 98 Second Edition support was scheduled to end on January 16, 2004. However, continual evaluation of the Support Lifecycle policy revealed that customers in the smaller and the emerging markets needed additional time to upgrade their product. Therefore, Windows 98, Windows 98 Second Edition, and Windows Me will continue to be supported after January 16, 2004.;[LN];LifeAn1 tells more about it

Staple balls - 19/3/04 at 08:16 PM


shame about M.E though, should never have been made or released