Jump to content

Popup-generating program not findable by MBAM


Recommended Posts

Hi, recently (last night) I was infected by both Antivirus Vista and Support Tools. Using MBAM, along with some other tools (Spybot, Spyware Doctor), I was able to disinfect my computer of these programs, re-enable System Restore and roll back to an earlier date. However, I still have some sort of malware that is generating popups, and attempting to access malicious IPs.

In firefox, some of the sites that will open include chatfree.org, blackcard.com, christianchildrenfund.org (or something like that), some casino site, etc.

MBAM then has notifications that tell me traffic to the following malicious IPs have been blocked:

213.163.89.104

213.163.89.105

213.163.89.106

At times, these notifications would occur approx every 10 seconds, but have since subsided to once every 10+ minutes (actually, it seems to have picked up a little bit since I started this post). The only issue is that MBAM is unable to locate the cause during scans, with even a full scan returning only one item (which was a false positive probably, but I deleted it anyway), and it still persists.

The protection log shows what IP was blocked, but is it possible at all to find the source process that's attempting to generate this traffic? Looking around, I suspected it may be Virut, but after downloading a virut utility from symantec it claims it's not Virut.

Link to post
Share on other sites

Hello, and welcome to malwarebytes.org

malwarebytes.org has a team of experts who will give you free help with any malware problems.

But we can only work on malware in the Malware Removal - HijackThis Logs forum, not in the general forums.

If you would like a malware removal expert to give you personal assistance, please print out, read and follow the directions here, skipping any steps you are unable to complete. Then post a NEW topic here.

One of the expert helpers there will give you one-on-one assistance when one becomes available.

After posting your new post make sure under options that you select Track this topic and choose one of the Email options so that you're alerted when someone has replied to your post.

Alternatively, as a paying customer, you can contact the help desk at support@malwarebytes.org

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.