Malvertising/trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jokerjan, Nov 13, 2021.

  1. jokerjan

    jokerjan Private E-2

    While online using Google Chrome, i started getting a pop-up saying McAfee found a problem and I should click Scan. Knowing better (I do not use McAfee I use Malwarebytes).

    I have tried to clear this off but as soon as I open the browser, the same web page pops up. I did a deep root scan for over 3 hours and the attached is what was done my Malwarebytes.

    Could you please help me find a way to stop this?

    Thank you.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow the Read and Run instructions at the top of this forum. Attach those logs when you are ready.
     
  3. jokerjan

    jokerjan Private E-2

    Hi Tim

    I have created the logs as per the Read and Run file. Yes I am still having troubles. It started yesterday while I was playing an online puzzle game (which I have played many times before). A new tab popped up with "McAfee has found a problem" click SCAN button to continue. I closed the incognito browser (which I use all the time) and cleared any browser cash, cookies, etc on the advanced tab of google chrome. I then went online looking for why this was happening as I do not use McAfee I have purchased Malwarebytes. The few items I found did not solve the problem. So I did a deep scan with Malwarebytes which included the rootkit. It took over 3 hours to complete. Those are the files I upload with my first message. Then I did a disk clean hoping if it was in the temp folder it would be deleted.

    Today, while trying to download some of the programs requested in your Read file, it happened again. So I went through and created the attached logs.

    Thank you for taking the time to look into this issue.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why are you running Bomgar_Cleanup? (I am not familiar with this. )

    Not finding any malware. If you are only using Edge, you should probably clean up the cache. You also need to remove temp files. To do so, go to start/ right click and choose RUN/ type in %temp% and remove all you can.

    Have you tried a different browser?
     
  5. jokerjan

    jokerjan Private E-2

    Thank you for taking a look at this but I am still having problems. I have attached a screen shop of the pop-up that showed up this morning while I tested the puzzle game to see if the problem went away. I am also attaching the initial Malwarebyte threats from the 13th.

    I do not know "Bomgar_Cleanup" where do you see this?

    I am using a local user account. I do all my browsing in incognito mode.

    A couple of things regarding your "Read and Run" file. When you click on "Using Malwarebytes AntiMalware" it comes back with "requested thread could not be found". Some of the other links showed differently than what is said in the Read file. I did my best to get all that was requested.

    Do you think I should run these programs through my microsoft account and not the local account?

    This problem is stopping me from continuing my online work. I work with QuickBooks Online with sensitive data for my clients. I need to know if I am going to infect them and whether I can safely do my job.

    I appreciate any help you can give me to clear up what is happening.

    Thank you.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you ever have McAfee installed?

    You can find those files in the RunKeys.txt log (Bomgar_Cleanup)

    Do you know how to clean your browsers?

    Have you run CCleaner - both cleaner and registry?
     
  7. jokerjan

    jokerjan Private E-2

    New computer as of August 2021. Never used McAfee - trial version on system when received but removed prior to install programs.

    What I think Bomgar was used for was a VPN setup by my clients tech company so I could remotely access their system. I no longer access client files via remote access via a VPN as one client let me go when covid hit and the other client went to online books and a VPN wasn't necessary.

    I have not run CCleaner. I just followed the instructions in the Read and Run thread,

    I will run it now - do you want to see the results prior to any cleaning?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not necessary. You may also consider installing a popup blocker to your browsers.
     
  9. jokerjan

    jokerjan Private E-2

    I have Malwarebytes extension on Google Chrome and Edge shouldn't that stop popups?

    So far haven't found the problem on Microsoft Edge.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. On your computer, open Chrome [​IMG].
    2. At the top right, click More [​IMG] [​IMG] Settings.
    3. Under "Privacy and security," click Site settings.
    4. Click Pop-ups and redirects.
    5. Choose the option you want as your default setting.
     
  11. jokerjan

    jokerjan Private E-2

    Thanks Tim, it was already set. Will do another test run on Chrome. Edge work (so far) I will keep my fingers crossed and hope the problem is solved.

    CC Cleaner found quite a few things but will have to learn the proper way to remove these so as to not cause more problems.

    Thanks again.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds