AdChoices Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by Crapgame, Nov 1, 2015.

  1. Crapgame

    Crapgame Private E-2

    Greetings all, any help would be greatly appreciated:

    HP Pavilion Elite m9340f
    Intel Core 2 Quad
    8 GB Ram
    Win 7 Pro

    Identification of this problem and possibly others was delayed, I rarely ever use the infected PC, I have an identical PC in my home office for my use. The computer is used by my kids, their friends, my wife and the two Bernese Mountain dogs, therefore subjected to uncontrolled clicking……. and they never report any problems until it beyond a simple fix. This time I discovered the problem because it was experiencing BSOD (0x0000007B) and would not boot. I ended up moving the infected PC alongside my healthy one to make it easier to work on; once I solved the BSOD problem I started to ensure it was up to date. I soon discovered the updates & automatic scans somehow became disabled, of course no one will admit to it (I suspect one of the two Bernese).

    IE-11 is hung up \ extremely slow do to ad loading.

    Here is what I have done so far:
    •Windows 7 Pro updated
    • Norton updated, scan run
    • CCleaner updated, scan run
    • Malwarebytes updated, scan run, log attached
    • Super antispyware updated, scan run, log attached
    • Adwcleaner updated, scan run, logs attached
    • JRT downloaded, scan run, log attached​
    At this point the ads still appear and slow IE11 to a crawl, quite a PIA, where to from here?

    Thanks in advance:

    Kevin
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you also have logs from:

    • Hitman Pro
    • RogueKiller
    • MGTools.exe >>> MGlogs.zip
     
  3. Crapgame

    Crapgame Private E-2

    Thanks for your quick response Kastrel13!:

    No, have not run them. Can you direct me where to acquire them.

    I am heading to the Ravens Tailgate \ game in a couple of minutes and will do those as soon as I return.

    Thanks

    Kevin
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. Crapgame

    Crapgame Private E-2

    Thanks once more.....

    Ravens won .... good tailgate...

    Attached are the logs as requested.

    I will await the diagnoses.....

    Thanks again

    Kevin
     

    Attached Files:

    Last edited: Nov 2, 2015
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there.

    Activate the free trial for Hitman Pro and have it remove everything it finds.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Re run Hitman again (just a scan) attach new log.

    Explain how things are running.
     
  7. Crapgame

    Crapgame Private E-2

    Kestrel13!:

    Attached are both logs.

    Ads on IE11 still present and it still slows it down.

    Next step?

    Thanks

    Kevin
     

    Attached Files:

    • JRT.txt
      File size:
      611 bytes
      Views:
      1
    • JRT2.txt
      File size:
      611 bytes
      Views:
      1
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  9. Crapgame

    Crapgame Private E-2

    Thanks once more:

    I reset to the defaults, didn't change anything. After the reboot and starting IE11 a window appeared at the bottom of the screen that said "s.flite.com wants to track your location". At that point I turned around to this computer to Google s.flite.com, this is what it showed: "Flite offers a programmatic creative platform to empower professional advertisers to deliver HTML5 ads that live up to the expectations of today's consumers.".

    After I found that I turned to the infected computer to click no and do the screen shot you asked for. The window at the bottom was gone by then, the second screen shot will show you why it was gone (I think).

    At this point I am not certain if Norton got rid of the infection but the ads in screen shot #1 are still there.

    Thanks again for your assistance:

    Kevin
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. Crapgame

    Crapgame Private E-2

    I have that on this computer, works well.

    I installed it on the infected computer, ads still there and when I re-opened IE11 that Norton window appeared again. I had reset my home page and Norton reset it to theirs......

    There must be something that doesn't want to be deleted......

    Thanks again:

    Kevin
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Consulting with colleagues, hang in there. :)
     
  13. Crapgame

    Crapgame Private E-2

    Thanks, note my avatar.........
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Open Internet Explorer, click on the Gear icon (IE menu) on the top right corner of the browser and choose Manage Add-ons.
    You will see a Manage Add-ons window. Here, look for AdChoices and other suspicious plugins. Disable these entries by clicking Disable.

    Did you see anything in there?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also does AdChoices appear in just Internet Explorer or in other browser(s)?
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also try clicking on it, to be taken to their website, look for an opt out button. I'm starting to think this is legitimate. https://en.wikipedia.org/wiki/AdChoices
    See what my colleagues say. You have another computer, right? Is AdChoices on there?
     
    Last edited: Nov 2, 2015
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I went onto the same website as you were on in your screenshot, and I too see the AdChoices logo. It's normal. :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AdChoices is legit and is a source of advertising revenue for websites. It is the same kind of application as AdSense, IntelliText, Vibrant Medie, Kontera ....etc.


    The below is quoted from Wikipedia ( https://en.wikipedia.org/wiki/AdChoices )
     
  19. Crapgame

    Crapgame Private E-2

    Sorry for the delay, daughter's field hockey game (they won, she scored two). Also, thanks again:

    Went to manage add ons, no AdChoices or other suspicious plugins.

    Opened Firefox, they also appeared when using that, I clicked on AdChoices and opted out. I also installed AdBlock Plus for Firefox.

    No ads on this machine, I have AdBlock Plus on this one, it seems to work well.

    I rebooted it after checking Firefox (above, on another user), went into my user (IE 11) and no more AdChoices, AdBlock must be working and \ or the opt out worked.

    Next, any word on s.flite.com, are they associated with AdChoices? I understand why the ad companies want to track your location but it doesn't sit too well with me, especially with the other users (daughter, son & wife).

    AdChoices appears to be under control now, I thank both you and your colleagues for the assistance. I will wait to hear back on the s.flite.com issue.

    Thanks again.......

    Kevin
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. ;) I'm just sorry it went on so long before I realised it was legit.

    With regards to s.flite.com this is all I can find:

    http://s.flite.com.ipaddress.com/

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  21. Crapgame

    Crapgame Private E-2

    Thanks again, once more, etc., etc., etc., .......

    Completed the last steps, all seems good.

    Read Chaslang's "How to protect yourself from malware", I have had those in place for quite some time. No mention (no fault found) of controlling the constant clickers that also have access to that computer or their lack of reporting until it becomes a major problem. I guess a solution is to schedule a couple of minutes on it once a week or maybe more.

    One of the things I am going to look into is a couple of additional hard drives and a piece of software like Acronis to clone the drive, once a week or so alternating between the 2 other drives. Because I travel so much it can be weeks where I only have a day home a week therefore don’t find the time to inspect their common PC much less their laptops. I am not sure if Acronis has scheduling ability or the ability to alternate drives, time will tell......


    Have a great day.....

    Kevin
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! Have a great day, too! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds