Friend Of Mine's Daughter's Laptop Full Of Pop Ups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mondola, Nov 6, 2016.

  1. mondola

    mondola Specialist

    Hello.

    A friend of mine has had issues with his laptop for a while.

    I had kept telling him to go through the steps here but he decided to just install different AntiVirus.

    So eventually he has passed the laptop to me for me to run through the steps.

    Given that MalwareBytes found 1,350 infections, I'm expecting some work here.

    I did run the various removal tools for the anti virus programs he had run and so it's just left with Windows Defender at the moment.

    Apparently whenever they go on line they get some sort of nude pop up. I haven't opened up a browser myself and only connected to allow HitmanPro and MGTools to run.

    Thanks in advance... Logs attached.
     

    Attached Files:

  2. mondola

    mondola Specialist

    Remaining files
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, mondola

    Please re-run HitmanPro, activate the 30-day Trial License, then fix all detections
    After the re-boot, please run another scan and upload the new log.

    Also re-run TDSSKiller and select to disinfect. Upload a new log.

    Now download Malwarebytes Anti-Rootkit 1.09.3.1001 Beta to a new folder on your Desktop.
    • Then open the folder, extract its contents and double-click on the mbar.exe to start the program.
      • If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.
    • Follow the prompts and be sure to update the definitions when it asks. When the update has finished, click on the Next button.
    • Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
    • Allow the program to remove any infections and reboot your computer when prompted.
    • Upload any log the program produced showing detections afterwards.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.

    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
    • Do NOT fix/repair anything yet! Please upload that logfile with your next reply.
    Then download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
     
    mondola likes this.
  4. mondola

    mondola Specialist

    It didn't find anything after Hitman Pro had done it's thing.

    All other logs attached. Sorry, took me a while to run through that lot !

    :D
     

    Attached Files:

  5. mondola

    mondola Specialist

    Last lot...
     

    Attached Files:

  6. mondola

    mondola Specialist

    By the way, Windows decided to install some updates and reboot when I allowed it to connect for the Farbar Recover Scan Tool.

    I hope it didn't mess anything up.
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I normally view that activity in a good light... checking the logs. ;)
     
    mondola likes this.
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Using AdwCleaner.exe previously downloaded:
    • Right-click on AdwCleaner.exe and "Run As Administrator".
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.

    Please tell me how the PC is running now.
     

    Attached Files:

  9. mondola

    mondola Specialist

    Here ya go. Logs as promised.

    PC is starting and stopping a lot faster than before and I've just tried browsing and I see no pop ups or nude images.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Sounds good! Ready for the final steps?
     
  11. mondola

    mondola Specialist

    Serious ?

    Oh man that's awesome ! Thanks so much !

    I'm doing the we're not worthy worship.

    Thankyouthankyouthankyouthankyou!!!!
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) Yep - we're done and you're welcome!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
    mondola likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds