Excessive Pop-Ups, need help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ninjadier, Jul 15, 2009.

  1. Ninjadier

    Ninjadier Private E-2

    Hi there.

    Yesterday I started having pop-ups appear about every 5th page i navigated to. I use firefox, and these pop-ups are opening up a separate, full sized window (behind what I am looking at). I typed in a google search, and eventually found my way to your "READ AND RUN ME FIRST" removal guide. I followed all the steps, and after completing the first two scans, "SUPERantispyware" and "Malwarebyte's Anti-Malware" the pop-ups ceased. I thought i had fixed the problem, so i stopped the procedure right there. This morning, however, the pop-ups started up again, so i decided to give combofix (the next step) a try. When i tried to run it, it told me that i needed to close Spyware Doctor. I did so. It then told me to close AVG Free Edition, which I also did. However, it still claimed that AVG was running, so I attempted to uninstall it. When i tried to do so, I got this message. "Uninstallation failed. 1 error occurred. Click Details to show more information" I did so, and it said this:

    "Local machine: installation failed
    Installation:
    Error: Action failed for registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: creating registry key....
    Error 0x80070005

    Combofix said it would run anyway, but at my own risk, which didn't sound all that great to me. The only other step i didn't follow was the one that said to unhide protected operating system files. This may have caused some issues, and stopping in the middle probably didn't help any either. I've attached the other two scan logs below, please help me out with this.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    As stated in the READ & RUN ME, you must continue all the way thru. You must not stop. So please continue on thru to the end and attach logs from other scans that run. You can try running ComboFix in safe boot mode, but run other steps in normal boot mode.
     
  3. Ninjadier

    Ninjadier Private E-2

    Sorry about that, I overlooked that instruction. The other three logs are attached. The pop-ups have stopped, but I'd like to know that I'm clean for sure before I toggle a system restore.

    One more question: After I'm clean, what do I do with the cleaning tools? Do I delete them, or should they be left as is?
     
  4. Ninjadier

    Ninjadier Private E-2

    Well, screwed that up. Here's the correct attachments.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean but you do need to do the below.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - Startup: PowerReg Scheduler.exe
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    After clicking Fix, exit HJT.


    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    If your copy of Spyware Doctor is just a free trial that you recently downloaded, uninstall it now as it is of no use to you. The free trial will not do anything but slow your PC down.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds