Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Aggressive Firefox Pop Ups


  • Please log in to reply
18 replies to this topic

#1 XiahWolf

XiahWolf

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:08:02 PM

Posted 06 September 2013 - 10:05 AM

Hi guys.

 

As of a few days ago, random tabs keep opening in my Firefox. I'm currently running v23.0.1 on Windows 7. So far I've gotten:

 

  • hxxp://www.thefreecamsecret.com/ap/?DF=0&AFNO=1-0-634091-341541&UHNSMTY=303&jntp=np&stno=1-721-776-2966-1973-1919&sanp=wmedia
  • hxxp://www.casino.com/au/media/games_package/?b=tan&SID=187011&p=1&PX=tankafetast&DP=319235

  • hxxp://vube.com/SHIBAN/u2QvJwDVmw/L/vote?t=s     and a whole bunch of other vube popups

I've noticed that in my history, 7.rotator.wigetmedia.com always opens before the tab does e.g. hxxp://7.rotator.wigetmedia.com/servlet/ajrotator/319235/0/vh?z=wiget&dim=79059&kw=&click=

 

Only one tab will open at any time. It only happens if I leave my computer alone. So far it hasn't affected my other browsers. I have Adblock Plus and Ghostery already installed if that makes any difference. SUPERAntiSpyware doesn't seem to be picking anything up, nor my nod32.

 

Hope someone can help.

Cheers!

 



BC AdBot (Login to Remove)

 


#2 TwinHeadedEagle

TwinHeadedEagle

  • Members
  • 171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgrade, Serbia
  • Local time:11:02 AM

Posted 06 September 2013 - 10:50 AM

wogs.png Download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

thisisujrt.gif Download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop.
 
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
 
Be sure to restart the computer.
 
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt



#3 buddy215

buddy215

  • BC Advisor
  • 6,420 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:02 AM

Posted 06 September 2013 - 10:52 AM

If you haven't done so, click on the Adblock Plus icon and choose preferences. Then uncheck Allow some non-intrusive ads.

 

Run these two adware scans:

AdwCleaner Download

Junkware Removal Tool Download

 

In your next post include the logs from those two scans.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”
Lawrence M. Krauss


#4 XiahWolf

XiahWolf
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:08:02 PM

Posted 07 September 2013 - 07:43 AM

AdwCleaner

 

# AdwCleaner v3.002 - Report created 07/09/2013 at 22:21:15
# Updated 01/09/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Nikki - APOLLO
# Running from : C:\Users\Nikki\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\Users\Nikki\AppData\Roaming\Mozilla\Firefox\Profiles\jmrbgz8k.default\jetpack
File Deleted : C:\Users\Nikki\AppData\Roaming\Mozilla\Firefox\Profiles\jmrbgz8k.default\.autoreg

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16660


-\\ Mozilla Firefox v23.0.1 (en-US)

[ File : C:\Users\Nikki\AppData\Roaming\Mozilla\Firefox\Profiles\jmrbgz8k.default\prefs.js ]

Line Deleted : user_pref("extensions.noredirect.list", "^hxxps?://(?:[^/]+\\.)?mozilla\\.(?:org|com)::13:::^hxxps?://(?:[^/]+\\.)?google\\.com::13:::^hxxp://agoga\\.com::3:::^hxxp://(?:[^/]+\\.)?websearch\\.verizon\[...]
Line Deleted : user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir)/.*|hxxp://.*depositfiles.com/(([a-z]{2})/files/|auth-).*|hxxp://(www.)*digg.com/(.{5}|.{6})$|hxxp:[...]

-\\ Google Chrome v

[ File : C:\Users\Nikki\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1850 octets] - [07/09/2013 17:36:40]
AdwCleaner[R1].txt - [1910 octets] - [07/09/2013 22:20:22]
AdwCleaner[S0].txt - [1853 octets] - [07/09/2013 22:21:15]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1913 octets] ##########
 

 

 

JRT

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.8 (09.05.2013:1)
OS: Windows 7 Ultimate x64
Ran by Nikki on Sat 07/09/2013 at 22:30:27.43
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ FireFox

Emptied folder: C:\Users\Nikki\AppData\Roaming\mozilla\firefox\profiles\jmrbgz8k.default\minidumps [38 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 07/09/2013 at 22:35:30.12
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

MBAM

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.09.07.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
Nikki :: APOLLO [administrator]

7/09/2013 10:36:52 PM
mbam-log-2013-09-07 (22-36-52).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 249499
Time elapsed: 2 minute(s), 14 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
 



#5 XiahWolf

XiahWolf
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:08:02 PM

Posted 07 September 2013 - 08:12 AM

hxxp://vube.com/LIVIN+PARADIES/RwamkLjLLo/L/vote?t=s just popped up and I was still at my computer, albeit playing a game while it appeared.



#6 buddy215

buddy215

  • BC Advisor
  • 6,420 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:02 AM

Posted 07 September 2013 - 08:35 AM

You may have something a bit more sinister than just adware. Scan with the programs listed below.

RKill...RKill Download

RogueKiller...RogueKiller Download

 

Post the logs of those programs back here.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”
Lawrence M. Krauss


#7 Sawny

Sawny

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:02 PM

Posted 07 September 2013 - 09:22 AM

I have the exact same problem, but I use Chrome.

I did a quick scan with Avast but it didn't found anything.

 

I have got one popup per day since 3 September. Always this link:

http://7.rotator.wigetmedia.com/servlet/ajrotator/319235/0/vh?z=wiget&dim=79059&kw=&click=

 

 

 



#8 XiahWolf

XiahWolf
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:08:02 PM

Posted 07 September 2013 - 09:55 AM

RKill

 

Rkill 2.6.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 09/08/2013 12:06:02 AM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * Explorer Policy Removed:  NoActiveDesktopChanges [HKLM]

Backup Registry file created at:
 C:\Users\Nikki\Desktop\rkill\rkill-09-08-2013-12-06-14.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * No issues found.

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  216.98.48.53 127.0.0.1
  216.98.48.18 127.0.0.1
  216.98.48.57 127.0.0.1
  216.98.48.133 127.0.0.1
  216.98.48.134 127.0.0.1
  127.0.0.1 static3.cdn.ubi.com
  127.0.0.1 ubisoft-orbit.s3.amazonaws.com
  127.0.0.1 onlineconfigservice.ubi.com
  127.0.0.1 ubisoft-orbit-savegames.s3.amazonaws.com
  127.0.0.1 uat-onlineconfigservice.ubi.com
  127.0.0.1 wsuplay.ubi.com
  127.0.0.1 static8.cdn.ubi.com
  127.0.0.1 gconnect.ubi.com
  127.0.0.1 activation.acronis.com

Program finished at: 09/08/2013 12:06:58 AM
Execution time: 0 hours(s), 0 minute(s), and 55 seconds(s)
 

 

RogueKiller

 

RogueKiller V8.6.9 _x64_ [Sep  3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Nikki [Admin rights]
Mode : Scan -- Date : 09/08/2013 00:38:54
| ARK || FAK || MBR |

¤¤¤ Bad processes : 6 ¤¤¤
[SUSP PATH] garli-2.0_x64.exe -- D:\ProgramData\BOINC\projects\boinc.umiacs.umd.edu\garli-2.0_x64.exe [-] -> KILLED [TermProc]
[SUSP PATH] wilsont_0.10_windows_x86_64.exe -- D:\ProgramData\BOINC\projects\registro.ibercivis.es\wilsont_0.10_windows_x86_64.exe [-] -> KILLED [TermProc]
[SUSP PATH] milkyway_separation__modified_fit_1.26_windows_x86_64__opencl_nvidia.exe -- D:\ProgramData\BOINC\projects\milkyway.cs.rpi.edu_milkyway\milkyway_separation__modified_fit_1.26_windows_x86_64__opencl_nvidia.exe [-] -> KILLED [TermThr]
[SUSP PATH] abc_sieve_2.10_windows_x86_64.exe -- D:\ProgramData\BOINC\projects\abcathome.com\abc_sieve_2.10_windows_x86_64.exe [-] -> KILLED [TermProc]
[SUSP PATH] hadcm3n_6.07_windows_intelx86.exe -- D:\ProgramData\BOINC\projects\climateprediction.net\hadcm3n_6.07_windows_intelx86.exe [-] -> KILLED [TermProc]
[SUSP PATH] hadcm3n_um_6.07_windows_intelx86.exe -- D:\ProgramData\BOINC\projects\climateprediction.net\hadcm3n_um_6.07_windows_intelx86.exe [-] -> KILLED [TermProc]

¤¤¤ Registry Entries : 8 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Google Update ("C:\Users\Nikki\AppData\Local\Google\Update\GoogleUpdate.exe" /c [7]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-3799808729-3734747893-477303883-1002\[...]\Run : Google Update ("C:\Users\Nikki\AppData\Local\Google\Update\GoogleUpdate.exe" /c [7]) -> FOUND
[HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_TrackProgs (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 8 ¤¤¤
[V1][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-3799808729-3734747893-477303883-1002UA.job : C:\Users\Nikki\AppData\Local\Google\Update\GoogleUpdate.exe - /ua /installsource scheduler [7][x] -> FOUND
[V1][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-3799808729-3734747893-477303883-1002Core.job : C:\Users\Nikki\AppData\Local\Google\Update\GoogleUpdate.exe - /c [7] -> FOUND
[V1][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-3799808729-3734747893-477303883-1000UA.job : C:\Users\Com29\AppData\Local\Google\Update\GoogleUpdate.exe - /ua /installsource scheduler [x][x] -> FOUND
[V1][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-3799808729-3734747893-477303883-1000Core.job : C:\Users\Com29\AppData\Local\Google\Update\GoogleUpdate.exe - /c [x] -> FOUND
[V2][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-3799808729-3734747893-477303883-1000Core : C:\Users\Com29\AppData\Local\Google\Update\GoogleUpdate.exe - /c [x] -> FOUND
[V2][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-3799808729-3734747893-477303883-1000UA : C:\Users\Com29\AppData\Local\Google\Update\GoogleUpdate.exe - /ua /installsource scheduler [x][x] -> FOUND
[V2][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-3799808729-3734747893-477303883-1002Core : C:\Users\Nikki\AppData\Local\Google\Update\GoogleUpdate.exe - /c [7] -> FOUND
[V2][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-3799808729-3734747893-477303883-1002UA : C:\Users\Nikki\AppData\Local\Google\Update\GoogleUpdate.exe - /ua /installsource scheduler [7][x] -> FOUND

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[FF][PROXY] jmrbgz8k.default : user_pref("network.proxy.type", 2); -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection :  ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


216.98.48.53 127.0.0.1
216.98.48.18 127.0.0.1
216.98.48.57 127.0.0.1
216.98.48.133 127.0.0.1
216.98.48.134 127.0.0.1
127.0.0.1 static3.cdn.ubi.com
127.0.0.1 ubisoft-orbit.s3.amazonaws.com
127.0.0.1 onlineconfigservice.ubi.com
127.0.0.1 ubisoft-orbit-savegames.s3.amazonaws.com
127.0.0.1 uat-onlineconfigservice.ubi.com
127.0.0.1 wsuplay.ubi.com
127.0.0.1 static8.cdn.ubi.com
127.0.0.1 gconnect.ubi.com
127.0.0.1 activation.acronis.com


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: M4-CT128M4SSD2 +++++
--- User ---
[MBR] 81375619da145c308e41a16256a589c4
[BSP] d3486e05d75cd07f77a7cc8481b3d6f2 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 122001 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: M4-CT128M4SSD2 +++++
--- User ---
[MBR] c2cc6a4c45ddd9bc921d899778569cfe
[BSP] 24290535879e378e8eb8aba3d1c27995 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 1907726 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_09082013_003854.txt >>
RKreport[0]_S_09082013_002617.txt


 



#9 buddy215

buddy215

  • BC Advisor
  • 6,420 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:02 AM

Posted 07 September 2013 - 10:22 AM

So, are you still seeing the ads?

 

Clean up the temp files, etc. using Ccleaner. Do not use the Registry cleaner tool. During install you will be offered

the Yahoo Toolbar or other. Be sure to UNcheck if not wanted.

CCleaner - PC Optimization and Cleaning - Free Download


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”
Lawrence M. Krauss


#10 UnoxRookworst

UnoxRookworst

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:02 PM

Posted 07 September 2013 - 12:46 PM

Hey guys.

I have the same problem. I've been getting popups from thefreecamsecret and Vube. It's been going on for about a week now. I know this because the moment I saw the first one, I installed Ad-Aware to try to get rid of it - to no avail.

The odd thing is, I receive the popups on both my laptop and my computer, though I don't remember installing the same application on them. So far, on both, I've tried MalwareBytes, Ad-Aware, NOD32, Spybot S&D, SuperAntiSpyware, but it's still there. I just tried CCleaner, I hope that fixed it.

Also, I'm pretty sure I only get the popup once a day, either around the same time (18:00/6pm) or after six hours of uptime.


Edited by UnoxRookworst, 07 September 2013 - 12:53 PM.


#11 Sawny

Sawny

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:02 PM

Posted 07 September 2013 - 01:55 PM

Hey guys.

I have the same problem. I've been getting popups from thefreecamsecret and Vube. It's been going on for about a week now. I know this because the moment I saw the first one, I installed Ad-Aware to try to get rid of it - to no avail.

The odd thing is, I receive the popups on both my laptop and my computer, though I don't remember installing the same application on them. So far, on both, I've tried MalwareBytes, Ad-Aware, NOD32, Spybot S&D, SuperAntiSpyware, but it's still there. I just tried CCleaner, I hope that fixed it.

Also, I'm pretty sure I only get the popup once a day, either around the same time (18:00/6pm) or after six hours of uptime.

 

+1

 

I haven't installed any programs since 08/28. And I got my first popup 09/03.

 

 

 

 

I find this very strange. It feels like someone have found an exploit in some common software.



#12 Gideon020

Gideon020

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:09:02 PM

Posted 07 September 2013 - 08:04 PM

Yeah, it just happened to me as well even after running MBAM, JRT and AdwCleaner.

 

EDIT: Ran the CCleaner. With any luck, it'll be gone when I start up tomorrow.


Edited by Gideon020, 07 September 2013 - 08:46 PM.


#13 Morning Glory

Morning Glory

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:12:02 PM

Posted 08 September 2013 - 04:23 AM

Hi! I had the same problem, same pop-ups opened on firefox. Searching a solution I found this thread.

Now, I think I solved it: pop-ups were caused by Messenger Plus for skype. In effect, they started to appear after an update of this program. So, I removed it immediately and pop-ups disappeared. XiahWolf and UnoxRookworst, you can try to unistall MSN+ for Skype and see if problem will solve.

Sorry for my poor english, I hope that this information will be of use.



#14 Gideon020

Gideon020

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:09:02 PM

Posted 08 September 2013 - 04:41 AM

Hi! I had the same problem, same pop-ups opened on firefox. Searching a solution I found this thread.

Now, I think I solved it: pop-ups were caused by Messenger Plus for skype. In effect, they started to appear after an update of this program. So, I removed it immediately and pop-ups disappeared. XiahWolf and UnoxRookworst, you can try to unistall MSN+ for Skype and see if problem will solve.

Sorry for my poor english, I hope that this information will be of use.

 

If it works, you'll have my thanks.



#15 UnoxRookworst

UnoxRookworst

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:02 PM

Posted 08 September 2013 - 06:52 AM

Hi! I had the same problem, same pop-ups opened on firefox. Searching a solution I found this thread.

Now, I think I solved it: pop-ups were caused by Messenger Plus for skype. In effect, they started to appear after an update of this program. So, I removed it immediately and pop-ups disappeared. XiahWolf and UnoxRookworst, you can try to unistall MSN+ for Skype and see if problem will solve.

Sorry for my poor english, I hope that this information will be of use.

Huh, I have that same program. Just deleted it. If this works, you're a lifesaver! :)






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users