Dnsunlocker Popup Ads And Hijacking While Surfing

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thebatpeople, Jun 11, 2016.

  1. thebatpeople

    thebatpeople Private E-2

    It started a couple months ago. Don't recall what it was I installed that could have caused it. I haven't had this kind of trouble for a long time since I discovered majorgeeks and come here first to look for programs. I must have let my guard down. Anyway...

    I was using Comodo IceDragon.
    It started with a new tab created. (The problem never happened on a secure site.) It would be an ad using some sort of scare tactic to get me to click. I would close it out and move on. Oddly it seem to learn that I was instantly closing the new tab and it started making itself the first tab and putting my original in the second which I of course closed out. So I started waiting I few seconds to see which was my tab and close out the other. That's about the time the ads started popping up in the tab I was using, marked as DNSunlocker. I also have Maxthon installed so I thought I would switch to using that, but after about a half hour Maxthon started doing the same thing. I ran several scans from some programs I already had on my computer but came up with nothing. I think I uninstalled some of them because they were outdated. I installed IObit Malware Fighter. I think it found one thing but the problem still persisted. I decided to stop doing a hack job and use your support forum to fix my problem. That's when it got worse. I started getting three new tabs, two ad pop ups and my blocked pop up counter was going over a hundred per page. I was being blocked from downloading from majorgeeks as well. I ended up switching to Windows Explorer because it wasn't being effected. I followed the directions in the fixing browser hijack thread first, since that is all it seemed to be effecting but that didn't seem to cure the problem. I then followed the instructions in the read and run first. (yes, I know, I should have) It has been a week since I did that and the browser isn't showing any signs of problems. So yay! But my concern is that some of the scans detected problems but the instructions said not to clean them. Could someone look at my logs and tell me if there is more I should clean?

    Thanks!
     

    Attached Files:

  2. thebatpeople

    thebatpeople Private E-2

    some more logs and screenshots of the carnage
    Is the screenshot of Time Warner a legitimate one? I never called because I just assumed it was fake.
    hijack2j.JPG hijack3j.JPG
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro, enable/activate the free trial and let it remove what it finds (which isn't much)

    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] HKEY_LOCAL_MACHINE\Software\MetaStream -> Found
    • [PUP] HKEY_LOCAL_MACHINE\Software\Uniblue -> Found
    • [PUP] HKEY_LOCAL_MACHINE\Software\Viewpoint -> Found
    • [PUP] HKEY_USERS\S-1-5-21-4097705165-825944303-3043576826-1003\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks | {EF99BD32-C1FB-11D2-892F-0090271D4F88} : -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Rescan with both Hitman and RogueKiller again and upload the fresh logs once the above has been done.
     
  4. thebatpeople

    thebatpeople Private E-2

    Thanks for the fast reply! Followed your instructions.
    One other thing. Look at the screenshot attached. When I run IceDragon this error has been popping up since I tried to clean my computer with IObit. Any ideas or should I just uninstall and then install a fresh copy?
     

    Attached Files:

  5. thebatpeople

    thebatpeople Private E-2

    As per your last bit of instructions. Reboot and re-scan.

    Thanks for the help.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Perhaps you should uninstall and reinstall Ice Dragon to see if that corrects it. Iobit might have been over aggresive and removed a part of Ice Dragon.

    Now how are things running?
     
  7. thebatpeople

    thebatpeople Private E-2

    Everything seems to be running fine. Thanks for your help!

    I have not had time to deal with the browser yet.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are running low on memory, you could do with an upgrade.

    Glad things are running well. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have less than 10% hard drive free space....
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds