Popup advert on startup - spyware?

It could have been there seemingly idle before doing anything.

First step of removing malware is to disable system restore :)
 
got it, found a "windows user blah blah" entry in startup in msconfig that executed from a winlogon.exe file that had a path in program files which i thought was a bit odd. I disabled it and rebooted and the popup didnt appear.

So I went to that folder which had a bunch of text files and this winlogon.exe. Worringly one of the text files was called "clipboard" and had everything that i have ctrl+c'd for months back, there was another with my system details, IP's, MAC's etc and a few others that just looked like junk.

So i've deleted that folder and am swiftly on to change all my passwords etc.

Thanks for the help (mostly) :P
 
1. Click the Windows "Start" button and click "Internet Explorer" to launch your Web browser. Locate the "Tools" menu on the top of your browser, select "Pop-up Blocker" and click "Pop-up Blocker Settings." This launches a new window that allows you to configure your IE pop-up blocker.
2. Select the blocking level that you want to use. In general, it is advisable to select the "Medium" blocking level, so that you do not interfere with the normal functioning of some websites. If you select the "High" blocking level, you will not be able to view some websites. If you select the "Low" blocking level, you will likely see a number of pop-up advertisements.
3. Select the option to play a sound if you want a notification when IE blocks pop-ups. Click "Close" when you finish selecting the options that you want to use. Click the "Tools" menu again, select "Pop-up Blocker" and then click "Turn on Pop-up Blocker" to enable the pop-up blocker.
 
I know its not elegant, time saving or efficient but in situations like this (which very rarely happen to me as I'm very careful about what sites I visit online and what I download) I backup all my important files...then low level format the entire drive and re-install windows then scan my important files to death before putting them back on my main drive. I'm just super paranoid and don't trust any security program to fully protect me or that the infection wont recur. (Currently using Microsoft security essentials, spybot and malwarebytes)
 
system restore is really useful, best to disable it if you ahve had an infection (to clear it out) then re-enable it straight away.

The only part of it that I use is driver rollback, which is still accessible when it's disabled.
 
Back
Top Bottom