Monster Marketplace virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by juliefabian5, Oct 15, 2013.

  1. juliefabian5

    juliefabian5 Private E-2

    Hello,

    I noticed recently that I have hyperlinks all over my internet pages and they pop up to a Monster Marketplace ad. I've been trying to get rid of the virus for 2 days but it has only gotten worse, to the point that my Avira is locked up now (I can't turn it off and it is giving bogus messages). Most malware searches I do don't pick up anything and I am starting to understand that this virus isn't allowing the malware checkers to work properly. Any suggestions?

    Many thanks!!

    Julie
     
    Last edited: Oct 15, 2013
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. juliefabian5

    juliefabian5 Private E-2

    Tim,

    Thanks for your quick reply. I neglected to mention that that was the first thing I did and I went through the list twice even. I have since consulted many other sites and tried several other fixes, but I just can't get rid of it. I have lots of result files but perhaps there are too many now and they will just confuse. I will go through the protocol again and paste the logs to my next mail.

    Thanks again.

    Julie
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then you did not follow the instructions properly, because:
    1) They instruct you to only run it once and you should not be running them a third time now.
    2) They instruct you to attach the 5 requested logs from our procedures ( only the ones we ask for ) if you are still having problems

    So from our perspective, you have not completed the instructions properly. ;)
     
  5. juliefabian5

    juliefabian5 Private E-2

    Tim,

    I saved the logs with the intention of posting them but I couldn't figure out how to post (I know, pretty lame). The thread I was getting the instructions from had a closed sign. I even posted a message on the Major Geeks fb page (from my daughter's account) asking how to post. I was stressed and thought you had stopped accepting new threads/posts. :cry

    What should I do?

    Julie
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. juliefabian5

    juliefabian5 Private E-2

    Tim,

    Thank you. I followed the directions very carefully. I'm attaching the logs plus some print screens that might be useful.

    I've had to delete Avira from my computer because the virus prevented it from functioning properly and it pretty much seized up on me. I'll wait to reload it.

    Thanks in advance for any help you can give.

    Julie
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only reference I can find to Monster is the file on your desktop. Is this happening in all browsers and if so, which are you using?
     
  9. juliefabian5

    juliefabian5 Private E-2

    Tim,

    Thanks. I am attaching a doc I made a few days ago that shows two print screens of my home page with the hyperlinking and the monster marketplace pop-up as well as some Avira error messages (I have since deleted Avira and am waiting to reinstall). It is on Google Chrome which is the only browser I use on this computer. Today I noticed that I have shadow copies of a lot of my files all over my desktop and in my file folders.

    Thanks, Tim.

    Julie
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try uninstalling Chrome, run CCleaner and then reinstall.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FYI: If the below folders are not deleted after uninstalling Chrome, the same problem may still exist. So they should be deleted before a reinstall.
     
  12. juliefabian5

    juliefabian5 Private E-2

    Thanks, but I didn't see the "below folders". Also, I didn't see your post until after I did the reinstall. So far so good but please let me know those folder names. Or were you referring to those thread names related to your post?

    Thanks again.

    Julie
     
  13. juliefabian5

    juliefabian5 Private E-2

    Tim, Thank you so much. I did it and I think that took care of the problem.

    Thanks for being patient with me.

    Julie
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:




    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that, I meant to post the below folders

    C:\Users\Julie\AppData\Local\Google\Chrome
    C:\Program Files (x86)\Google\Chrome


    But since all is good now, it does not matter anymore.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds