Persistent malware/pop up ads/redirection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by swimmy711, Dec 3, 2013.

  1. swimmy711

    swimmy711 Private E-2

    Hello,
    I definitely have something going on. I had a bit of a bonehead move, and apparently did not have my AVG active, but thought I did, which is how this happened. It is now active. My system is super slow and bogged down. The main symptoms of the virus/malware are: when a website loads and I click on any part of the page for the first time, another page pops up (beginning of the site name ad-advertise). This happens almost every time I load a new website. Also if I go to any sites which have shopping capability, a magnifying glass pops up in the corner of the picture and if you roll over it, an ad pops up and prevents me from clicking on anything else.

    I've run all the procedures - READ ME FIRST, Pc cleaning procedure, google redirect procedure. Still having issues. I've attached my logs.

    Oh, and something similar happened before, so I had bought Hitman pro because it fixed it. Prior to running the procedures, I ran Hitman in the hopes it would do the trick, and I deleted something it found. I've attached that log from a few days ago. Then i read your instructions not to delete... sorry about that, hope it didn't make anything worse. :/

    Thank you so much for any help.
     

    Attached Files:

  2. swimmy711

    swimmy711 Private E-2

    It doesn't want to attach my log for TDSS Killer, so i'll rerun and keep trying.
    thanks.
     
    Last edited: Dec 3, 2013
  3. swimmy711

    swimmy711 Private E-2

    TDSS Killer log
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :)

    Do you have the MGLogs.zip from running MGTools.exe?
     
  5. swimmy711

    swimmy711 Private E-2

    Yes, I do. What do you need from it?
     
  6. swimmy711

    swimmy711 Private E-2

    hopefully this is what you need
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you purposely set up to use a proxy?

    Did you pay for this?

    • SparkTrust PC Cleaner Plus


    Delete this:
    • C:\Users\Steph\AppData\Roaming\Microsoft\Windows\Templates\750h467dy6x781mj7rxy101
     
  8. swimmy711

    swimmy711 Private E-2

    Well, I don't know what a proxy is, but I did buy spark trust. It was on the major geeks site and in a moment of panic I got it thinkin it was a new recommended malware removal program. I take it that was not a good move? Please advise!
     
  9. swimmy711

    swimmy711 Private E-2

    And I will delete what you suggested as soon as I'm near my computer. Thanks.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can just uninstall SparkTrust, yes. :)

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;192.168.*.*

    After clicking Fix exit HJT.

    How are things running?
     
  11. swimmy711

    swimmy711 Private E-2

    Did everything, I still have pop up windows (pathopen.com appears to be the most frequent, if that means anything). I also have the pop up magnifying glasses with ads that pop up from them when you roll over them with the mouse. :/
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So which browser is this occurring in please?
     
  13. swimmy711

    swimmy711 Private E-2

    I only use Firefox. I haven't checked Internet Explorer to see if it's infected too...
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except I want you to use Revo Uninstaller rather than the standard uninstaller) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    -----------------------

    Any better at all?
     
  15. swimmy711

    swimmy711 Private E-2

    Hello,
    I uninstalled firefox using the Revo installer, and i wasn't sure which scan to run so i ran the moderate one. It found a bunch of registry items, and I am wondering if I am supposed to delete all of them to complete the uninstall? The folder in question, where most of the items seem to be, is in a folder entitled HKEY_CLASSES_ROOT.

    Or maybe I was only supposed to do the lowest level scan...?
    Thanks.
     
  16. swimmy711

    swimmy711 Private E-2

    I went ahead and reran the Revo uninstaller and chose the safe level, and deleted everything related to firefox that it showed was safe to delete. i then went to delete the two folders you suggested. THe first was deleted successfully. In the case of the 2nd folder (C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox), there were 2 Mozilla folders. I deleted one, then the 2nd one I got into the Mozilla/Firefox one, then it told me i needed permission from myself to delete it. I will attempt to reinstall firefox again to see if this did the trick, and get back to you.

    Thanks!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, let me know how you are getting on. :)
     
  18. swimmy711

    swimmy711 Private E-2

    So far things seem to be running great. I think the problem may be fixed. Thank you so much.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds