1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

[Solved] pop up to fix Vista error?

Discussion in 'Malware Removal Help' started by CarolsSis, Feb 22, 2014.

  1. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Yes please, what is the url?
     
  2. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    //pckeeperapp.com.zeobit.com. This is not the same as other times I've seen it. I wrote down zedo one time, so I guess it was in place of zeobit on this one. I tried to find it on Microsoft website, as it claims to be written by a tech, but was not able to find out anything.
     
  3. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    When are you getting this popup?
    Is it just with IE or is coming up on other browsers as well?
    Have you installed anything prior to this happening?
     
  4. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    The only browser I use is IE. Strange thing is, it doesn't always come up. It's been on here for a few months I think, so I don't recall if I installed anything. I don't usually install things. My recent installs have been: Malwarebytes, RevoUninstaller, Avast. Have you seen the pop up? It looks like a fake. Since I don't have any errors from my machine to tell me something is wrong, I would not have chosen to hit the download button on the pop up. I tried to put it in "restricted" on my browser, didn't do anything. It's odd that it pops up so infrequently
     
  5. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Try resetting IE back to the defaults.
    • Close any Internet Explorer or Windows Explorer windows that are currently open.
    • Open Internet Explorer by clicking the Start button, and then clicking Internet Explorer.
    • Click the Tools button, and then click Internet Options.
    • Click the Advanced tab, and then click Reset.
    • Select the Delete personal settings check box if you would like to remove browsing history, search providers, Accelerators, home pages, and InPrivate Filtering data.
    • In the Reset Internet Explorer Settings dialog box, click Reset.
    • When Internet Explorer finishes applying default settings, click Close, and then click OK.
    • Close Internet Explorer.
    • Your changes will take effect the next time you open Internet Explorer.
     
  6. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I reset the browser
    Also took off one of my news tabs. I have a space below my browser window, and noticed that when I clicked on a link on the news page, it came up. It comes up under the browser window. I assume it's some kind of malware.
    Were you able to find out what it is? Thanks again for your help.
     
  7. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Can you post a screenshot of this, it will help me to understand this a bit better.

    This link will explain how to do this if you are unsure.
    http://askville.amazon.com/screenshot-Vista/AnswerViewer.do?requestId=9786478

    It not classed as malware and the site doesn't distribute malware:
    http://www.google.com/safebrowsing/diagnostic?site=pckeeperapp.zeobit.com

    But we do need to find out why it's coming up.
     
  8. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    as soon as I see it again, I'll try to screen shot it and post. Thanks.
     
  9. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I opened the news web site and clicked on a link. Sure enough, the pop up showed up. I tried using shift-prtscr. Did not work. Tried "function" and prtcr, also did not work. Those were the directions on the page I was directed to.
     
  10. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Are you sure that it's not because of the links you are clicking?
    If/when it happens again, let me know what the link was that you clicked on.

    Just try the PrtScn button on it's own?
    That's how it works on my keyboard.
     
  11. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    After my last post, I ran Avast, no issues. Ran malwarebytes, 117 PuPs, most were c/programfiles/searchprotect etc. Search protect is what Spybot removed before I uninstalled it. Also ran RevoUninstaller, it removed 2 left over files of Chrome and 2 others. After all this, I went to site that I was on when pop up came up, and it did not. Local news site, www.tucsonnewsnow.com, and I have not had any more pop ups. I hope we can consider this done. I have an Acer laptop, no idea why I can't get print screen to work, but no matter what I try, it doesn't. Guess that's another issue with this machine, it has quite a few which I suspect are because of all the crapware installed by manufacturer. thanks so much for your time, expertise and patience. I think you've gone above and beyond with this old girl. :)
     
  12. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    That's odd, as this was one of the things that JRT removed earlier.
    Had anything been installed since running JRT?

    Actually there is a tool for dealing with this.
    If you want to give it a go......

    The PC Decrapifier will uninstall many of the common trialware and annoyances found on many of the PCs from big name OEMs.

    Download Pc-decrapifier
    Save it to your Desktop.
    Click on the desktop icon to run the program (there's no installer)
    Follow the prompts.
    You will have the choice to pick and choose what you want to remove.
    It will not begin removing anything without prompting you first!


    Note:
    Your anti-virus software may complain about this program because it is written with a scripting language. These warnings can be safely ignored.

    It really is no problem at all.
     
  13. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Although my white hair gives me away, I'm not that old and out of it. I did not install anything. You checked out the url for this pop up, and say it's not malware. Great, I did not post orginally in malware, a moderator moved it. The links I clicked on, on www.tucsonnewsnow.com were headline links so you can read the story. I was able to make it (the popup) come back on the news page, before I re-ran malware bytes. Now, when I go to the tucsonnewsnow page, I can't make it pop up. I checked my help and support, it says to just push the prtscr button OR use alt-prtscr. Neither of these works, I have no idea how to fix it. As we saw, this machine was saving downloads to the c drive and not the desktop. This o.s. is Vista Longhorn, the very first one, presumably with all the mistakes. So who knows why this key works on your machine and not mine. Granted, I don't think I've ever had occasion to use prtscr. But still, it should work. I tried the link for decrapifier, it locked up. I waited for 15 minutes for it to remove Acer eAudio, and got no light showing that my hard drive was in use. Odd, don't you think? It also wouldn't cancel. So, I went to shut down. I have RevoUninstaller on my machine, may decide to try to move these Acer crapware that way. I hope I've adressed all the issues and questions. Thanks, so much, again.
     
  14. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi CarolsSis,

    I had to ask though.
    Search Protect comes bundled with 'Free' programs and gets installed along the program you wanted.
    There was no sign of it in the FRST report (which was run after Jrt ) so it's odd that it just appeared.
    Is there only yourself that uses this system?
    It's not uncommon for other family members and friends to add this rubbish if they have access to your system.

    It was me that moved it.

    Now's here's something strange........
    I checked the download page and it says:
    For some strange reason it doesn't say Vista....... which you would have thought it would.
    I will have to check this.

    The system does have the required Service Packs..... Windows Vistaâ„¢ Home Premium Service Pack 2
    So it should have the bugs ironed out.

    Yes, it should.
    But then again this is 'Windows' so anything may go wrong. :)

    If the popups are no longer bothering you, we can start to finish off the cleaning process now.
     
  15. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I have to apologize. I left my laptop on, on this page while I went to answer the phone. My nephew decided to click on some link and downloaded something while I was out of the room. I just found this out yesterday. And I have since downloaded Adobe Digital Editions 3.0 recommended by my library. On their site I downloaded "Overdrive" which is some kind of e-reader. Since then I've been plagued with Something called "surftastic" which I think may have been removed by Revo. I'm also getting a message from Avast that there is an infection it is blocking. Message reads: Url: http:// utf16.localrte.com/apps/dist/Select-N-Go_2010 infection: Win32:Evo-gen [susp] and infection is blocked by Avast.
    Another thing, my key for "PrtScr" also has "SysRq" below it. On other keys with 2 labels, one is black and one is blue. According to manual, I use "Fn" key to use the blue ones. Odd that the PrtScr and SysRq are both black. Don't find anything to tell me how to use one of the black ones. Thank you again for your expert help and endless patience.
     
  16. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    JRT and AdwCleaner should both be able to clean out 'Surftastic' and 'Select-N-Go'
    If you still have JRT and AdwCleaner on your system, give them a run.
     
  17. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I checked thru my owners manual. Explanation given for all but 3 keys on top row. All are printed in black, one is prtscr-sysrq, and no mention of how to use them. I checked entire manual, in case they were mentioned elsewhere.
    Ran JRT have file on desktop. Ran and cleaned AdwCleaner. saved file. For some reason unknown to me, they downloaded to my downloads folder, not the desktop. I made no changes to location. JRT file will not upload. may have saved it wrong. Will review previous posts on this thread to find save to desktop instructions.
    Am over run with pop ups. I almost hit my nephew for messing with my laptop.
     

    Attached Files:

    • JRT.txt
      File size:
      1.8 KB
      Views:
      13
    • JRT.txt
      File size:
      1.8 KB
      Views:
      13
  18. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    After last post I did short scan with Avast, no threats. also ran malwarebytes, 14 threats detected, all removed successfully. One really concerned me- Pum bad proxy- registry value- HKCU\software\Microsoft\Windows\current value Internet settings proxy server Data-HTTP:// 127.0.0.1.13828
    Have no more popups. :)
    I didn't download software from local library until after 15 March, I checked my downloads folder, that is date I downloaded Adobe Digital Editions, downloaded Overdrive on library site day or two later. Will be more careful in future, watch for check boxes in agreements on websites. And close down computer when nephew drops in.
    Thanks again for all your expert help. Have signed on to Bleeping Computer, looks like a good knowledge base for me. Still have much to learn.
     
  19. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi CarolsSis,

    Sorry, but i did try to post earlier but couldn't log in to the site.

    I can imagine, especially after the time you spent cleaning it up.
    Sometimes you need eyes in the back of your head when kids are around.

    PUM.bad.proxy is a form of malware known as a "registry hack" (Potentially Unwanted Modification )
    This hack alters the proxy server address settings to redirect web access requests back to the computer's own internal LAN address, 127.0.0.1, effectively cutting the computer off from access to the internet.
    Only Internet Explorer is effected though, so if you use Firefox the system would still connect to the internet as usual.
    MBAM will have reset this for you.

    That's good. :)

    As for the print screen button, i have no idea why it doesn't work for you.
    It's a complete mystery.

    If everything is running ok now, you should remove the programs we've used and cleanup.

    Step 1
    Restart MBAM.
    Click on the Quarantine tab

    b98d8f9bf07306db6b7853c64ae04fae.png

    If there are items in quarantine.....
    Make sure everything is selected and then click Delete All.
    Close MBAM.


    Step 2
    Double click on AdwCleaner.exe to run the tool again.
    • Click on the Uninstall button.
    • Click Yes when asked are you sure you want to uninstall.
    • Both AdwCleaner.exe, its folder and all logs will be removed.

    JRT and FRST can now be removed also. ( right click on the icons/folders and select delete)

    You can also remove TFC this way..... or keep it.
    It's a very handy program to have.
    I keep it on my systems and run it once a week just to keep all the temp files and rubbish down.


    Step 3
    Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the adware/malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools may not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

    The easiest and safest way to do this is:
    • Go to Start > Programs > Accessories > System Tools and click "System Restore".
    • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Then go to Start > Run and type: Cleanmgr
    • Click "OK".
    • Select the drive for cleaning then click OK (usually 'C' drive)
    • Click the "More Options" Tab.
    • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

    Glad I was able to help.

    Safe surfing. 200636f9a90a19cb85ecf0ba93831af6.gif
     
  20. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I still had pop ups, Select N Go was quite elusive. I ran JRT and AdwareCleaner, again. No issues. Ran malwarebytes, it removed 1, bad proxy. Still had select n go plagueing me. Ran Decrapifier on 23 March, it removed Select N Go. Yeah! I could not find it in my programs list, but decrapifier did. No more problems, and Decrapifier created a restore point. Thanks doesn't seem enough for all your time and help that you have given me. I feel like there is no way to thank you completely. It's been a long and winding road, but with all your patience, I was able to get my machine in usable condition again. Can't thank you enough! Will attempt safe surfing, thanks to your advise.
     

Share This Page