Still having trouble

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HisAngel, Jul 23, 2015.

  1. HisAngel

    HisAngel Private First Class

    I have been having trouble since Saturday 07/18/2015 when my grandkids were playing on my pc and it has been slowly getting worse and worse. It started out with having some words would be green and double underlined and when you get near them an ad would pop up. Then it went to an ad for Java script would pop up with no possible way out of it other then task manager to end process then an ad for me to buy the Microsoft defense program (sorry I don't remember the name but it is the one with a castle.) but it just did not look like it was from MS. and ads would pop up every where in my browser when I opened it or I would click something and an ad would open instead of what I had clicked on. It seems that most is gone except for the green underlined words and the fact of when I click something an ad pops up instead of what I clicked on. Thank y'all so much for all your help. Y'all are awesome. I tell everyone "if you need help with your pc just go to Major Geeks. They can help you with anything.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    Re run Malware Bytes and this time let it remove everything. The log shows nothing was quarantined. Attach a new log.

    Re run Hitman Pro and let it remove all what it finds.

    Please attach a proper log for Roguekiller. If you haven't got one, re run it again please.


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. HisAngel

    HisAngel Private First Class

    Thank you so much for your time to help me. I ran the scans and such as directed and here are the logs.
     

    Attached Files:

  4. HisAngel

    HisAngel Private First Class

    Sorry I missed a couple scans you requested but I saw them when I went back and reread your post I saw them and I ran them and here are the logs from them.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Malware Bytes is not showing that you have quarantined anything. Rescan with it, does it still detect items??
     
  6. HisAngel

    HisAngel Private First Class

    I ran it again and it found nothing. I ran it and it just closed after it was done.
     
  7. HisAngel

    HisAngel Private First Class

    Ok it has started something new. I just clicked to look at my post here and it opened in a new tab and the tab that I was on was taken over by an ad. Will I ever get this junk out of my pc???????? :cry :confused
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    .

    What browser?


    [​IMG] Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the tasks tab and locate this detection:

    • [Suspicious.Path] \Anhiibom -- "C:\ProgramData\Anhiibom\1.0.4.1\ehnufsal.exe" ("/e=L3A9MjEwODAxXi91PTJiZmQxNDY1MTkzZjQwNmRiYjI4NWZjMDQ2YzYyMTk0Xi9kPXRyYWNrYnJlYWtpbmduZXdzLmNvbV4vbj1ORVdTXi9hPUJyZWFraW5nTmV3c0FsZXJ0Xi90") -> Found
    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    What is inside of this folder?

    C:\Program Files (x86)\e37a1599-8f40-4941-b5bd-cc9d9ee4a30f


    Delete these. Let me know if you have problems...

    • C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Templates\ZLB29EC.tmp
    • C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Templates\ZLB5927.tmp
    • C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Templates\ZLBC792.tmp
    • C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Templates\ZLBF4E8.tmp

    Run Ccleaner (not the registry scanner, just the cleaner itself to be rid of a chunk of temp files)

    Re run Malware Bytes yet again and attach a fresh log for me.
    Re run Hitman Pro and attach a log from that too.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  9. HisAngel

    HisAngel Private First Class

    Ok I am using Google Chrome most of the time because firefox is argumentative most of the time and IE has to many ads.

    File removed and I rebooted.

    Nothing is in the folder you were asking about.

    Deleted the files requested.

    Ran Scans and attached logs but I can't find the Malware Bytes log to attach.

    Still have the green underlined ads and the redirected links. :(
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Instructions are all here.
     
  11. HisAngel

    HisAngel Private First Class

    Yes but it does not give me the option to save one. As soon as it is done scanning it shuts down and I can't save any logs.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm... run it in safe mode please.
     
  13. HisAngel

    HisAngel Private First Class

    Same thing. Could the program be corrupted? Maybe remove and re-install?
     
    Last edited: Jul 24, 2015
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did it find anything the last time you scanned?
    Reinstall it and see if it runs properly.
     
  15. HisAngel

    HisAngel Private First Class

    That worked.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can delete it then in that case.

    Not a malware problem. These are just mouse over ads that popup when your mouse moves over various underlined keywords. Many websites, including Major Geeks, use these as a source of revenue to help offset costs of running a free website and forums like this.

    What issues remain, if any?
     
  17. HisAngel

    HisAngel Private First Class

    Deleted File as requested.

    Only problem that remains is sometimes I click on a link and it opens a new tab and the old tab goes to an ad. I can go back to the old tab and click back once and it will return to the page I was on.

    Also earlier I was on a this thread and I was trying to copy the name of the folder you wanted me to remove (no green underlined words or links around it) and when I tried to select it, it went to an ad. Then I closed the ad page and went back and copied it and used it to delete the folder requested. I have had it do this when I click on a totally blank spot also.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And all this has been happening in Google Chrome?
     
  19. HisAngel

    HisAngel Private First Class

    Yes ma'am.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  21. HisAngel

    HisAngel Private First Class

    Ok let me try this out a bit. I think it might have it fixed. ;)
     
  22. HisAngel

    HisAngel Private First Class

    :heartI think that has done it. Thank you so much for all your help. :) You are awesome!!!!! :heart :heart :heart
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am very glad to hear all is well again. :) Final steps below..

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds