MSFN Forum: unwanted porn site popup automatically - MSFN Forum

Jump to content


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

unwanted porn site popup automatically In network Rate Topic: -----

#1 User is offline   rickytheanuj 

  • Member
  • PipPip
  • Group: Members
  • Posts: 264
  • Joined: 09-April 07

Posted 17 December 2009 - 12:39 AM

in my office network 2-3 computer had a problem, it automatically popup some unwanted porn site.
Nod32 antivirus is installed in that computer and i checked my computer with mcafee stringer virus remover but nothing is there.. there is nothing like that in startup and even schedule so what's the problem.. i also cleaned my web browsers' history and cookies too.. but nothing is gonna work..

help me.. or i have only way to solve is format


#2 User is offline   -X- 

  • Member
  • Group: Patrons
  • Posts: 2,046
  • Joined: 08-January 04
  • OS:XP Pro x86
  • Country: Country Flag

Posted 17 December 2009 - 02:17 AM

Sounds like malware. Post a hijackthis log or something.

#3 User is offline   rickytheanuj 

  • Member
  • PipPip
  • Group: Members
  • Posts: 264
  • Joined: 09-April 07

Posted 05 January 2010 - 12:26 PM

so.. wat's the sol??

#4 User is offline   submix8c 

  • Inconceivable!
  • Group: Patrons
  • Posts: 3,241
  • Joined: 14-September 05
  • OS:none specified
  • Country: Country Flag

Posted 05 January 2010 - 12:36 PM

View Post-X-, on Dec 17 2009, 03:17 AM, said:

Sounds like malware. Post a hijackthis log or something.
Uhhh...

#5 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 05 January 2010 - 05:17 PM

The solution is gonna involve some investigative work by you to help us, because the MSFN crystal ball is in the shop currently. Please start by running hijackthis on the affected machine and attach the log to your next post here, for starters.

We're really bad even with the crystal ball at guessing, but pretty good once we have data ;).

#6 User is offline   herbalist 

  • paranoid independent
  • PipPipPipPipPip
  • Group: Members
  • Posts: 726
  • Joined: 15-December 06
  • OS:98
  • Country: Country Flag

Posted 05 January 2010 - 05:26 PM

Hijack this and instructions regarding its use are available here.

#7 User is offline   MrJinje 

  • Tool™ Developer
  • Group: Developers
  • Posts: 942
  • Joined: 14-October 09
  • OS:none specified
  • Country: Country Flag

  Posted 07 January 2010 - 04:55 PM

To be honest, any corporate problem that takes longer to solve than the time it takes to provision a new machine, does not need to be solved.

You have to weigh how many hours you have worked this problem against how long it would have taken you to reformat/reinstall.

#8 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 07 January 2010 - 05:06 PM

...until it happens twice. Then, might as well fix it and find root cause, otherwise it'll just keep re-appearing.

#9 User is offline   MrJinje 

  • Tool™ Developer
  • Group: Developers
  • Posts: 942
  • Joined: 14-October 09
  • OS:none specified
  • Country: Country Flag

  Posted 07 January 2010 - 05:30 PM

If it turns out to be an employee surfing for pr0n, the HR reps will have a lunch of him. We have fired many employees for violating that little policy, very embarrassing way to go.

Another way to go might be to configure that website (pr0n address) into the "Restricted Zone" via group policy, or better yet configure the DNS/gateway/router to bar access to that site. That would help prevent a future infection.

This post has been edited by MrJinje: 07 January 2010 - 05:33 PM


#10 User is offline   herbalist 

  • paranoid independent
  • PipPipPipPipPip
  • Group: Members
  • Posts: 726
  • Joined: 15-December 06
  • OS:98
  • Country: Country Flag

Posted 07 January 2010 - 08:45 PM

At a place of employment, office and workstation computers should only get internet access if it's necessary for them to perform their jobs.

Reformatting might be the fastest way to fix the problem (assuming your office has all the data on these PCs backed up, but finding and fixing the actual problem could show who is the source of this problem.

#11 User is offline   MrJinje 

  • Tool™ Developer
  • Group: Developers
  • Posts: 942
  • Joined: 14-October 09
  • OS:none specified
  • Country: Country Flag

  Posted 09 January 2010 - 02:27 PM

Has the OP already ruled out a browser helper object. These would be beyond all the measures the OP employed (not found in start up, clear cookies, history).

Dig around in the Manage Add-on console (IE Options) and see if there are any randomly named, unsigned, unknown BHO's and react accordingly. Disable them one by one until the pop-up stops.

Posted Image

Then after you are 100% sure you know which add-on is causing trouble, create a group policy setting that prevents usage/installation of that particular add-on.

The settings are controlled from here, via group policy.

Windows Components\Internet Explorer\Security Features\Add-on Management

This post has been edited by MrJinje: 09 January 2010 - 02:28 PM


#12 Guest_stefan2078_*

  • Group: Guests

Posted 26 February 2010 - 06:39 AM

Try Malwarebytes' Anti-Malware which can remove trojans, worms, adware, malware from the computer it's really a good antivirus software that has a high detection rate, consumes low system resources and is fast.

#13 User is offline   rwycuff 

  • Newbie
  • Group: Members
  • Posts: 17
  • Joined: 07-February 08

Posted 13 March 2010 - 05:40 PM

Mr Jingie has the right idea its either a BHO or Could be Hosts file.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy