adperformance network malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by ivyleaguer, Nov 11, 2015.

  1. ivyleaguer

    ivyleaguer Private E-2

    Hi, My PC is infected with some type of adware or malware that brings in ad popups from adperformance network.com. I received two popups while I was typing this message. I tried avast, malwarebytes, hijackthis, CWshredder, ad-adware antivirus, adware removal by TSA, spybot, combofix, adwcleaner...None have removed it. Can you someone please help me. I have enclosed an example of one of the popups.

    Also, as a side question, can anyone give their thoughts on ad-adware antivirus, it seems to come with shields. Does anyone recommend this freeware over the paid avast? I am looking for a comparable freeware to avast.

    thank you.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. ivyleaguer

    ivyleaguer Private E-2

    I am using firefox. I will try using the procedures in the link you posted. But I am not too optimistic.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, once done attach all the logs and I'll see what I can do. ;)
     
  5. ivyleaguer

    ivyleaguer Private E-2

    hi, I went through all the steps as best I could. it's not as straight forward for a novice like me and all the software such as defogger etc just slowed down my PC when I had to install and run them. Also, i wasn't sure how knowing if I was running windows 32 or windows 64 would help. I used defogger, ran ccleaner, had only one anti virus ( avast) and one firewall avast then I ran spy bot again. All the other spyware recommended did nothing previously including malware bytes and roguekiller requires purchasing which I cannot do now. When I ran spyhunter it was the only one that seemed to detect stuff the others didn't but needed me to purchase it to clean anything. Here the logs I received from spybot. Do you need other logs. Not sure what to attach. but I am still getting pop ups as a I type.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No they do not.

    I need to see logs from:

    • Malware Bytes
    • RogueKiller
    • Hitman Pro
    • MGTools >>> MGlogs.zip
    • TDSSKiller
     
  7. ivyleaguer

    ivyleaguer Private E-2

    spyhunter says my registration has run out and I need to purchase it to clean my files.
    Rogue killer was difficult to find a download link even coming from your page, it seemed to go to a page that was confusing and I could not determine what I needed to click on to download it. when I went to roguekillers main page thorugh google and clicked download, it asked for payment options. There was no trial or freeware option.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Get RogueKiller from this link Choose to Download@Majorgeeks
     
    Last edited: Nov 11, 2015
  9. ivyleaguer

    ivyleaguer Private E-2

    roguekiller will not download. I keep trying but it says download fails. I will keep trying.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, use a different browser, or use a different machine and download it onto a flashdrive.
     
  11. ivyleaguer

    ivyleaguer Private E-2

    Hi, I have spent most of the day into the evening and now the early morning, where I am, scanning. I am attaching the files. Just some background. My avast expired a few months ago and so I have no real time shields only my out of date virus definitions. I used also use spy hunter but that registration also expired. Due to some recent budgetary issues I am not currently paying for software. I think whatever malware I have was derived from Peer to Peer sharing. I have the logs for: rogue killer, TDSSKiller, spy bot (already shared), malware bytes, Hitmanpro, and Spyhunter, cause for some reason, I though the latter was on the list, and it took the longest to scan so I might as well attach it. I might have to do this in two parts. I have two logs for malwarebytes as I thought an earlier scan log could prove useful to you. I just finally got MSGtools to actually run, it seems to get stuck in the command prompt stage. I hope to send it in the next response with the remaining logs . But I hope what I attach now will provide some insight. Many thanks.
     

    Attached Files:

  12. ivyleaguer

    ivyleaguer Private E-2

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you attach the correct log for RogueKiller please. (See the instructions again) Step 3
     
  14. ivyleaguer

    ivyleaguer Private E-2

    if I export text, it comes out completely blank with rogue killer. it's the same if I export HTML.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try "Open text" (you may have to rescan) when scan is finished select Open Text a file should open.... you can select all the text (edit - select all) > right click > copy > and paste > into a fresh notepad. Attach that here in your next reply.
     
  16. ivyleaguer

    ivyleaguer Private E-2

    hi...I tried all of that yesterday and it's still blank today. ONLY Json format has any text. here is the blank text file.
     

    Attached Files:

  17. ivyleaguer

    ivyleaguer Private E-2

    I did all of that yesterday and it's still blank. and it's still blank today. here is the blank file.
     
  18. ivyleaguer

    ivyleaguer Private E-2

    here are the screen grabs. Blank as blank can be.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But it's actually finding things? Can you screenshot what it finds, showing the complete entries, on files tab and registry tab? And any other tab that it finds something on.
     
  20. ivyleaguer

    ivyleaguer Private E-2

    Hi, here are the screen captures. I deleted about 300 or so instances of zeroaccess from the filessystem tab on Roguekiller last night as they were all in red. But it didn't help with the pop ups.
     

    Attached Files:

    Last edited: Nov 12, 2015
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :)

    Sorry about the delay I have been running round all day.

    First off, are you set up to use a proxy? (I presume Hotspot Shield which you use, uses one?) Let me know!
    Uninstall SpyHunter4 - it's not recommended.
    Also uninstall these as they are not needed:

    • McAfee Security Scan Plus
    • Norton PC Checkup

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.

    Re run RogueKiller, on the FileSystem tab have it delete those 2 entries.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
    • O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
    • O4 - Startup: aKNefyi.lnk = C:\Documents and Settings\mypc\Application Data\wNeO4WFYURvm\QRjJOa6J.exe
    • O4 - Startup: Kkth8tnb.lnk = C:\Documents and Settings\mypc\Application Data\X5JJWuPD4NeO\lE4jCnl.exe
    • O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
    After clicking Fix exit HJT.


    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\Documents and Settings\mypc\Application Data\6E1BC9CC-87D6-46F5-A98F-F7FAD116118D
    C:\Documents and Settings\mypc\Application Data\wNeO4WFYURvm
    C:\Documents and Settings\mypc\Application Data\X5JJWuPD4NeO
    C:\Documents and Settings\mypc\Start Menu\Programs\Startup\aKNefyi.lnk
    C:\Documents and Settings\mypc\Start Menu\Programs\Startup\Kkth8tnb.lnk
    C:\WINDOWS\Tasks\At1.job
    C:\WINDOWS\Tasks\At2.job
    C:\WINDOWS\Tasks\At3.job
    C:\WINDOWS\Tasks\At4.job
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please reboot yourself if it doesn't automatically reboot.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now with RogueKiller, re run it again, and once the scan has finished, do fresh screengrabs of each section like you did before and attach them here.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  22. ivyleaguer

    ivyleaguer Private E-2

    Norton will not uninstall. It came preloaded and I have never been able to remove it without getting an error message. Mcafee comes with one of my software updates. Mcafee keeps coming back with a software update, i believe Google Chrome Or I tunes.
    I don't use hot spot shield. that was ages ago and I removed it. if there are files left those are residual. the rest of the steps will take a while. I will let you know how it goes. thanks again.
     
  23. ivyleaguer

    ivyleaguer Private E-2

    Here is the error message with Norton PC check up. I can find no trace of hotspot shield to remove it. Can you please help with these? thanks.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, just continue on with other steps :)
     
  25. ivyleaguer

    ivyleaguer Private E-2

    I don't understand what this means: Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.
    Does this mean avoid safe mode?

    Okay, I just figured it out but couldn't delete this message only edit so scratch the above message. :-D
     
    Last edited: Nov 13, 2015
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nothing to do with safe mode. ;) That's different. You should Click Start, click Run, type msconfig, and then click OK. This will bring up the msconfig window. You need to choose normal start up, click apply, click ok.
     
    Last edited: Nov 13, 2015
  27. ivyleaguer

    ivyleaguer Private E-2

    I did the first part with Msconfig and before it restarted there was an error message because of the changing to "normal' start up. on start up I got a blue screen error I tried to photograph but it went away before I could. then I got this error. Attached. I had to switch off the PC manually and restart it in order to get back into windows. when I ran msconfig again, I checked the start up tab and noticed every program was now checked, including Okay freedom, which was deleted ages ago, mcafee, which was deleted last night... and a whole bunch of other programs such as e-mule are now configured to start up with my PC. is this normal? Cause the blue screen and the error message I attached which froze my PC on startup REALLY scared me.
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm not sure why you had a blue screen error. That shouldn't have happened.
    Yes it's normal. This is why I said you should be using third party software to manage what starts up, such as Start up CPL and not using msconfig, that is the wrong way to manage the processes.
     
  29. ivyleaguer

    ivyleaguer Private E-2

    I downloaded startup CPL and when I clicked on it , it seemed to install, but nothing happened. it's not in my list of programs and there's no read me file, so I am not sure what it has done exactly.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can just use Ccleaner for now to manage start up's if Start up CPL is not working for you.
     
  31. ivyleaguer

    ivyleaguer Private E-2

    hi...I went through the entire process. Here are the files. I only attached the roguekiller tabs that found something. But I am still getting popups from adnetworkperformance as I type this message. It seems to happens most when I click your add attachment window. The popups load from that tab.
    And I couldn't find these files to delete:
    O4 - Startup: aKNefyi.lnk = C:\Documents and Settings\mypc\Application Data\wNeO4WFYURvm\QRjJOa6J.exe
    O4 - Startup: Kkth8tnb.lnk = C:\Documents and Settings\mypc\Application Data\X5JJWuPD4NeO\lE4jCnl.exe
    and I deleted the hotspot files that were popping up in roguekiller since that software shouldn't be installed.
     

    Attached Files:

    Last edited: Nov 13, 2015
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are still not in normal start up mode according to the latest MGlogs.zip. (use msconfig as I said to get into normal start up)

    Re run RogueKiller.... on the Web Browsers tab, have it remove the proxy items which are highlighted in gray in your first screenshot from this latest batch.

    Also follow these instructions to reset Firefox.
    Reset Mozilla Firefox to defaults

    Let me know if it helps.

    Does your Firefox have a adblocker/pop up blocker? :confused
     
  33. ivyleaguer

    ivyleaguer Private E-2

    hi..I selected normal startup and as I mentioned before the system got a blue screen and then froze on start up. You really want me to through the process again?
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No skip it then and just continue on.
     
  35. ivyleaguer

    ivyleaguer Private E-2

    the popup blocker on firefox is checked. I reset the browser and as soon as it reopened an adnetwork performance pop appeared. I will try running rogue killer again now.
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, if after running RogueKiller and removing those items, you STILL have pop up's..... install this browser add on and let me know how you get on.

    AdBlockPlus for Firefox
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Popping out for an hour or so. Back soon. :)
     
  38. ivyleaguer

    ivyleaguer Private E-2

    Hi...I re-ran rogue killer and those gray files were no longer there. perhaps do to the reset. I will keep watching if I get popups and let you know. the first one I mentioned below might have been previous windows sessions opening due to firefox relaunching after the reset and might have not have been new ones. It will take a few hours of surfing up to a full day before I am confident all is clear. Thanks for your help. And you can you recommend a good malware/antivirus program that has realtime protection that is freeware? thanks.
     
  39. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome.
    I use Avast free edition and am very happy with it. You can always post in the software forum to further discuss anti virus choices.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!!!! CCleaner stores changes in MSconfig registry keys and should not be used because it makes it look like MSconfig was used and is broken.

    And StartupCPL is really a inadequate now. Microsoft's AutoRuns tool is a much better program and will show you many more startup than you even knew existed.
     
    Kestrel13! likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds