Steps To Remove Random Pop Up Please

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by theremotedr, Nov 26, 2016.

  1. theremotedr

    theremotedr Master Sergeant

    As per title.
    Ive ran Malwarebytes Anti-Malware and started pc.
    Ive ran adwcleaner & removed suggested found items.
    Pc retarted but im still getting pages pop up and betting shops etc etc.

    Please advise steps i need to take to flush the system out.

    Thanks
    Win 7
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    theremotedr likes this.
  3. theremotedr

    theremotedr Master Sergeant

    Hi,
    I have now completed the list as requested.
    Since finishing ive used the pc for a while but didnt see the pop ups this time.
    Before i would of seen them by now.
    I have uploaded the files.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    One more... the RKreport.txt file from running RogueKiller.
     
    theremotedr likes this.
  5. theremotedr

    theremotedr Master Sergeant

    I see there are 2 TDS files, both different sizes.
    I think one is RK.
    I did run and save it but don't know how it got named like that.
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    No - those are both TDSSKiller logs. Perform a file-search for the file with Explorer.
     
    theremotedr likes this.
  7. theremotedr

    theremotedr Master Sergeant

    Ok
    In the morning now.
     
  8. theremotedr

    theremotedr Master Sergeant

    Here we go
     

    Attached Files:

  9. theremotedr

    theremotedr Master Sergeant

    Hi,
    Just to confirm that using the pc this morning for 2 hours looked good BUT ive just received my first pop up.
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *You failed to follow Step 4: Disable Any Disk Emulation Software (like Daemon Tools..etc). Return to the READ and RUN ME FIRST guide configure your system as instructed.

    After doing the above, re-run RogueKiller.exe. (Vista/Windows7/8/10 users should right-click and select "Run as Administrator")
    After it finishes the scan, select the following tabs and then select any of the below that exist and then click the Remove Selected button.
    Registry - all PUP's
    Files
    Then immediately reboot your PC.

    Now run a new scan with RogueKiller and save a log as in the original instructions and upload that new log.

    Please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run JRT.exe by double-clicking it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.
    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
    • Do NOT fix/repair anything yet! Please upload that logfile with your next reply.
     
    theremotedr likes this.
  11. theremotedr

    theremotedr Master Sergeant

    Hi,
    I deleted the pups are requested.
    File reports etc as requested.
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Using AdwCleaner.exe previously downloaded:
    • Right-click on AdwCleaner.exe and "Run As Administrator".
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
    Re-run ZHPCleaner per previous instructions
    • After the scan has completed - press the Repair button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
     
    theremotedr likes this.
  13. theremotedr

    theremotedr Master Sergeant

    Hi,
    No internet on PC for 2 days.
    I will upload files as soon as I'm connected again.
    Thanks.
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Thanks for the update. :)
     
    theremotedr likes this.
  15. theremotedr

    theremotedr Master Sergeant

    Internet back on some 10 days without.
    See logs as requested.
     

    Attached Files:

  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now re-run ZHPCleaner per previous instructions
    • After the scan has completed - press the Repair button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.
    *Tell me how the PC is running now.
     

    Attached Files:

  17. theremotedr

    theremotedr Master Sergeant

    See attached file.

    Is the message below the red text for me to complete also ?
     

    Attached Files:

  18. theremotedr

    theremotedr Master Sergeant

    Just read it again and now will press delete as advised,been a long day.
     
  19. theremotedr

    theremotedr Master Sergeant

    Ok
    This time i did it as advised.
    After scan i pressed repair.
    Once finished no report opened up.
    I have attached a file,please check if it is the file you require.

    Please advise if this is what you require,then i can run the fixlist.txt
     

    Attached Files:

  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    That is the correct log. Please now follow the Farbar FRST instructions.
     
    theremotedr likes this.
  21. theremotedr

    theremotedr Master Sergeant

    Would that be the instructions below the red text in #16 or #12 ?

    Awaiting confirmation.

    Thanks.
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Follow the instructions given in message #16.. to run the fixlist.txt fix.
     
  23. theremotedr

    theremotedr Master Sergeant

    Ok
    It automatically restarted PC then i see file of which i have attached.
    5 minutes of use i dont see any pop ups etc but i would like to use it for some hours to confirm all is better.
    I have attached Fixlog file as requested.

    Please advise and i will continue etc tomorrow.

    Thanks
     

    Attached Files:

  24. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Monitor your system for 24 hrs and report back for final instructions.
     
  25. theremotedr

    theremotedr Master Sergeant

    OK
    I will reply back Friday as out a bit tomorrow,

    Thanks for your time.
     
  26. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.
     
  27. theremotedr

    theremotedr Master Sergeant

    Hi,
    Today was cancelled so ive been on the pc and not one pop up.
    I think i am now happy to continue with the next steps that you advise.

    Thanks
     
  28. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  29. theremotedr

    theremotedr Master Sergeant

    All done will now see whats happens.

    Thanks for the time spent with this.
     
  30. theremotedr

    theremotedr Master Sergeant

    Hi,
    Even though i have followed the above i still see a few of the following icons should be hidden ?
    .pdb
    .DLL
    etc etc
     
  31. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    There's nothing wrong with these file extension types showing.
     
  32. theremotedr

    theremotedr Master Sergeant

    OK,just thought i would ask thanks.
     
  33. theremotedr

    theremotedr Master Sergeant

    Can i ask a questions please.
    Im trying to run a piece of software that uses a file from Daemon tools but now will not run.
    Does anything spring to mind why like i have not switched something back on etc etc so it would then work ?

    Thanks
     
  34. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Did you complete the steps to re-enable DAEMON Tools Lite before cross-posting in the software forum?
     
  35. theremotedr

    theremotedr Master Sergeant

    Yes i did but ive just done it again & also restarted pc again,now its worked this time.
    I will make a comment on the other post,i thought i would just ask you a quick question here.

    Thanks again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds