Java Update Pop-Up & Probs with MWB

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Imanya, Aug 17, 2014.

  1. Imanya

    Imanya Private E-2

    Hello everyone,

    I've noticed on two different websites a popup tab which appears in poorly written English prompting me to update Java.

    From a quick google search today, I realised that this is due to malware (when I saw it on the first site I thought it was a problem on THEIR site) on my machine.

    I've followed all the steps in the read & run me first except for Malwarebytes.

    I had Malwarebytes installed on this computer prior to following the instructions today, but it suddenly stopped running properly, despite various attempts to remove and reinstall it. Today's attempt at a reinstall also flopped. I got these messages:


    Internal error: Expression error 'Runtime error (at 79:177)
    External exception E06D7363.'

    Runtime Error (at 69:252):
    External exception E06D7363.

    I've attached the logs for the other programs to this message. Thank you all for your help, I really appreciate it.


    - Imanya C.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] \\SomotoUpdateCheckerAutoStart -- C:\Users\xamayca\AppData\Local\FilesFrog Update Checker\update_checker.exe (/auto) -> FOUND
    • [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3638451154-3866334349-2893476779-1002\Software\Microsoft\Windows\CurrentVersion\Run | FLV Player : C:\Users\xamayca\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe -> FOUND
    • [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3638451154-3866334349-2893476779-1002\Software\Microsoft\Windows\CurrentVersion\Run | FLV Player : C:\Users\xamayca\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe -> FOUND
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
    • Which browser(s) do the pop ups occur in?
    • Are they still happening after following my fix?
     
  3. Imanya

    Imanya Private E-2

    Hi Kestrel13!

    Thank you for your reply. I've attached the log as requested.

    I got the success message after submitting the file to the registry but unfortunately the popups still appear.

    They seem to happen only in Firefox (also use IE and no problems there) and only when I click on links in certain sites.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. Imanya

    Imanya Private E-2

    Hi Kestrel13!

    I reset Firefox, then went back to the site and clicked on the links which were causing the redirects and they're not happening now. Thanks so much!

    I'm a little bit worried still that Malwarebytes wasn't able to run - might something have been missed without it?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall it and then run the Malware Bytes clean up Tool to be rid of all traces before you attempt reinstall.

    (Topic for the software forum really)

    Are there any other remaining issues to be dealt with in this forum, or is all well? :)
     
  7. Imanya

    Imanya Private E-2

    Hi Kestrel13!

    Thanks for the info. And no, as long as the Malwarebytes scan isn't necessary, it seems like everything is running fine.

    Thank you so much once again for your help!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. But you ought to get to the bottom of MBAM not running. Try what I said and if that doesn't work, post about it in the software forum if you like.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  9. Imanya

    Imanya Private E-2

    Thanks for your help Kestrel13!

    Sorry for the late reply; I was away. I'll carry out the steps recommended including trying to solve this problem with Malwarebytes.

    Many thanks again to you and the rest of the Major Geeks team!


    Imanya
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds