Downloaded Adware And Can't Remove. Did The Readme Process...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Strangebrew, Feb 10, 2018.

  1. Strangebrew

    Strangebrew Private E-2

    Hi guys,

    I downloaded some adware today that isn't coming off. It opens a 'Chromium' browser and several pages when I log on, along with prompting flash updates. I knew as soon as I downloaded it that it was a mistake, so I ran Malwarebytes immediately, it found all kinds of crap that it removed, but this last bit it can't remove, so here I am.

    I ran through the Read & Run First file; still having problems. Logs are attached.

    Thanks!
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re-run AdwCleaner and remove all PUPS
    Now run RogueKiller and remove the detections found under Registry.

    Please perform new scans with both and upload the updated logs.

    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan may take some time.
    • Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.

    Are you still having problems?
     
  3. Strangebrew

    Strangebrew Private E-2

    Problem still there, yes. Thanks for your help. Wasn't actually expecting that anyone would be up and working on this stuff this late on a Saturday. Appreciate it. Logs attached.
     

    Attached Files:

  4. Strangebrew

    Strangebrew Private E-2

    Heading to bed. I'll pick this up in the a.m.
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Re-run ZHPCleaner per previous instructions
    • After the scan has completed - press the Repair button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.

    Please download the freeware version of Zemana Antimalware to your Desktop and run it. After the appl auto-updates, click on Scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that log, please.
     
  6. Strangebrew

    Strangebrew Private E-2

    Done. Logs attached.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    How's the PC running, now?
     
  8. Strangebrew

    Strangebrew Private E-2

    Problem still there.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    First export your Bookmarks to save them, then do this --> Reset Chrome settings to default

    Now please download Farbar Recovery Scan Tool and save it to your Desktop.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run from.
    • The first time the tool is run, it also makes another log (Addition.txt).
    • Upload both logfiles to your next reply.
     
  10. Strangebrew

    Strangebrew Private E-2

    Done. Logs attached.
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    No additional malware was found. If you haven't already, re-boot your PC and monitor it for problems.
     
  12. Strangebrew

    Strangebrew Private E-2

    Rebooted, still doing the same thing. It opens several browser tabs on start up. Still a 'Chromium' shortcut in my start menu.
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • O4 - HKCU\..\Run: [Chromium] "c:\users\lord byron\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory=Default --restore-last-session
    • O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_B37305A779402EB2DB9EE6DADE8E9E01] "C:\Users\Lord Byron\AppData\Local\Chromium\Application\chrome.exe" --no-startup-window /prefetch:5
    After clicking Fix, exit HJT and re-boot.
     
  14. Strangebrew

    Strangebrew Private E-2

    That seems to have done it. Nothing weird happening at start up now.
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Good!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. After doing the above, you should work through the below link:
    Safe surfing!
     
  16. Strangebrew

    Strangebrew Private E-2

    Done. Man, you guys are awesome. This is truly an invaluable service you offer.
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Thanks! Glad to be able to help you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds