Ad rotators and facebook pop up adverts

Discussion in 'Malware Help (A Specialist Will Reply)' started by loninappleton, Nov 17, 2013.

  1. loninappleton

    loninappleton Corporal

    No I'm not being a troll or anything like it. The Hi Jack This business-- I simply don't recall what you're referring to.

    There is this continuing problem in running anything out of the MGTools folder. If at some point things are starting to get fixed (I guess your programs reinstalled Ad Block Plus) I may have tried to 'check' HJT again. I never see the lines of code for HJT program in the HJT scan. My HJT scan looks normal.
    There is nothing in it checked to "fix"!

    I'll do the OTL routine shortly. It's very hard for me to have to write down complicated instructions and then return to a program I've never seen and have no idea what it's doing or why. There has been little explanation of what is going on. That's my side of it.
     
  2. loninappleton

    loninappleton Corporal

    OTL attachments
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Our programs and my instructions have not done anything to uninstall or reinstall adblocker plus. So I don't know what you're talking about there. :confused
    You should print out these insructions if you are able. These programs I am having you run are either gathering information, or scanning and removing crap. I have provided you with plenty of explanation and precise instructions on what to do and how to do it, but you have either chosen to ignore me, or you do something completely different. Which is frustrating for me. You came here seeking my assistance. So without meaning to be rude, all you need to do, is what I tell you to do. There are many people here in need of help, and I don't wish to feel like my time is being wasted. That's my side of it. Right, onto business....


    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    DRV - (vqdtrh) --  File not found
    IE - HKCU\..\SearchScopes\{43682B77-B546-4606-A6AD-D81710E1AB36}: "URL" = http://proxy.allsearchapp.com/s.php?q={searchTerms}
    
    :commands
    
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Now I want you to Reset Firefox to Defaults

    How are things running?
     
  4. loninappleton

    loninappleton Corporal

    Ok I will not ask any more questions about procedure. I have not seen these programs before in other MG tutorials.

    I took off Ad Block because AB+ popping up is about as annoying as
    Facebook. Likely I don't know how to have it remember anything because when it says "Always Allow" it follows by saying that could dangers so I never say always allow.


    Reset Firefox now or after what's before it?
    Bare in mind I won't get to this until tomorrow.
    I have tried to look up OTL and things. There's a wiki for that.

    I am curious though if others have as many problems going through this.
    It shows my membership is from 2007 but I have few posts and rely on MG in time of need. The point is my problems are rare. My initial question was about browser annoyances and so it seems this is the path to avoid them.

    Who knew?
     
  5. loninappleton

    loninappleton Corporal

    I started this last process but had problems.

    After it started it blanked my screen to blue except for the OTL prog
    and gave an error message about killing processes saying not to interrupt. Well the hourglass and the message was still there after I had my dinner and came back. At that point I quit it.

    Restart went ok, it did not do any damage that I can detect.

    Perhaps all the things in the tray should have been shut down again? I heard nothing about doing so for this step.

    I will try again tomorrow.
     
  6. loninappleton

    loninappleton Corporal

    Also Does the OTL program stay set at minimum output rather than general?


    I can't find an image button anywhere on the OTL screen.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can ask as many questions as you like as long as it's relevant. What I object to is you taking action on things by yourself.


    I just wanted you to do everything in the order that I wrote it down in my last post.

    You've no need to go looking up those kind of things, If you want to train for malware removal there are places for that but you came to me seeking advice, so without being nasty, all I want you to do is listen to me and do exactly what I ask.

    This much trouble is rare...

    Right, so you just wanted a magical fix without any real work being involved. Unfortunately it does not work that way. Without you providing me with information, (which you now have) we would have been shooting in the dark.

    Skip the OTL step for now and just move onto resetting firefox to defaults. If this does not work, we will be doing a very thorough uninstallation of firefox and a reinstall after backing up your settings.
     
  8. loninappleton

    loninappleton Corporal

    I did the restore procedure in Firefox.

    Throbbers are back on, your animated smilies etc.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Refine it for me somewhat, has it made things better, worse, or are things just the same in Firefox now? :confused
     
  10. loninappleton

    loninappleton Corporal

    Zeroing Firefox was too extreme.

    It took out Chrome edit and that user profile which had all the remove throbber stuff in it. Plus the animations such as you have here --->

    Going into chrome edit for this new profile is empty-- no user ident line or any text whatsoever.

    You recall I did a backup? I believe that was just prior to running OTL that second time. I'm going to retrieve my backup disk. Without the profile I can't fix the annoyances I started out with.
     
  11. loninappleton

    loninappleton Corporal

    All is not lost.

    I have retained the disk which had all the logs and programs run.
    What I did was take a MozBackup from the clone disk. copied that to a cd and ran MozBackup restore mode. It seems to have gotten rid of the throbbers again. I really can't stand that (!)

    There's some animations to turn off yet-- like the ones on MG reply page (word) but that should go easier since I found a few Lifehacker tools to smooth it out.

    With the MozBackup I used the default settings of

    General Settings
    History
    User Styles
    Extensions
    Saved Passwords
    cookies
    Saved form details
    Dowloaded file list
    Certificates


    Then I made a second Mozbackup with only three elements checked:

    General Settings
    Bookmarks
    Saved Passwords.

    Did not try that one yet.

    My question is:

    If I install the MozBackup that way will it perform the functions needed which were lost from the Firefox back to year zero procedure which emptied out everything?
    IOW delete the history, cookies certificates etc.?

    I tried another procedure first to just get the text from User Chrome and paste it into those blank windows after restart but it it didn't kill the throbbers.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer one simple question. Did using the Reset Firefox to Defaults procedure remove the problem in the Title of your thread ( the Adrotators and facebook adverts )? Yes or no?
     
  13. loninappleton

    loninappleton Corporal

    Let me use these changes a while and I'll report back. The two things I'll be looking for to be "repaired" are the All Search intrusion in the Firefox Browser and Facebook pop-sideways anywhere.

    I know MG has seen this is as a struggle and that's unfortunate.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you just answer the question I asked?
     
  15. loninappleton

    loninappleton Corporal

    No intrusions seen so far.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then you see why the Reset To Defaults was suggested. Your problem was not truly a malware infection. It was really a problem due to addons and/or extensions that you allowed to be added to Firefox. If you restore everything from backups you will just restore your problem somewhere along the way.

    Thus you would be better off not restoring extensions and addons but rather just manually ( one at a time ) reinstalling an extension/addon and testing after each one to make sure it is not the cause of any unwanted changes. You can reinstall bookmarks from backups as they are not the problem.


    You also had the AllSearch searchscope added to IE according to your last OTL log which showed the below
    Other issues:
    1. The Malwarebytes logs you attached always showed -> No action taken. Why didn't you fix what it found
    2. The fullsize MGlogs.zip file that you attached back in message #26 is for a different PC than what you have been attaching now. The log from message #26 is from a 64bit PC that was running WIndows 7, but what you have been attaching now more recently is Windows XP Professional Edition Service Pack 3. Why are you mixing two PCs together in one thread which is helping to confuse things?
     
  17. loninappleton

    loninappleton Corporal

    Yes I agree with your conclusion. The restart or one of the processes emptied out my user.js folder which is found under Chrome edit. That's where the
    All Search was listed. I deleted it in there earlier but your process has gotten rid of it so far as I can tell..

    I know you want to close this thread but I thought it was worth noting.

    I run Firefox bare minimum so I don't really know where I could be picking up things. I even sampled Pale Moon for a while-- a slimmed down Firefox.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You installed Social Privacy on you computer as seen in your logs. That is where it came from. For example you can see McAfee even lists this junkware on the Virus Characteristics tab of the below link:

    http://home.mcafee.com/virusinfo/virusprofile.aspx?key=2642439#none

    Also you had installed the below which is part of the same junk. But this seemed be on a different PC. As noted earlier, you were posting logs for two different versions of Windows.

    C:\Documents and Settings\lon.LON4MSI\Local Settings\Application Data\Shield\checkhp.exe
     
    Last edited: Dec 1, 2013
  19. loninappleton

    loninappleton Corporal

    I would like to be more independent but do not know how read logs and this is the first note that an analysis was done with them.

    Definitions may be a problem. I have not seen any of the rotating ads that appear when I leave the target website. And I have been more observant when using No Script in that I set my regular ones 'allowed' rather than temporarily allowed and so am prompted fewer times. A program like no script is still a problem-- it inserts itself in the activity over and over. For instance it popped up here by this reply box when I know I okaye'd it earlier.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but problems with NoScript are not a topic for the Malware Forum. It is not malware. You can discuss general software Related issues in the Software Forum.

    I believe that any work we need to do here in the Malware Forum is finished other than giving you final instructions that cleanup from what we have done. That is unless you wish to remove that Social Privacy and Shield items. Do you agree with this?
     
  21. loninappleton

    loninappleton Corporal

    Ok you have the last word and can close the topic. Thanks for the improvements.

    I do not know precisely what changing the privacy would do but more is better than less.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not sure what you mean. The items I pointed out were the source of your problems you really should not be leaving them on your PC. See the McAfee link I gave you. More is not better than less when the more is bad software.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds