Help..pop ups everywhere.

Discussion in 'Malware Help (A Specialist Will Reply)' started by julesfl, Nov 3, 2013.

  1. julesfl

    julesfl Private E-2

    Hello, seems like deja vu, I was here last year. I have pop=ups appearing than disappearing. I went through the try this..first files. RogueKiller showed some faults, but wouldn't save the report, and I could'nt cut and paste them (didn't cut). So have attached what I could get.
     
  2. julesfl

    julesfl Private E-2

    heres the files.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello again. :) Reviewing the logs now.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete the item under the heading Malware, Malware Remnants & Potential Unwanted Programs.

    Does RogueKiller run now that TDSSKiller dealt with an infected file? If not run the below:

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  5. julesfl

    julesfl Private E-2

    Hello....Hitman Pro cannot delete problems, unless I pay for their program.
    Heres the files you wanted. Thanks so much for your help.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.




    • Re run Hitman again, just a scan, and attach log.
    • Re run RogueKiller, just a scan, and attach log.

    How are things running?
     

    Attached Files:

  7. julesfl

    julesfl Private E-2

    Hello, No attached logs because: 1) in system recovery I opened FRST64 and get 3 options, a) hives b) log c) quarantine and I did not see a button that says "fix".
    2) I did merge ure files to FixMe register, but received following message: the specified file is not a registry script. You can only input binary registry files from within the reg editor.
    Also, am i suppose to be using a flash drive? because I have not been using one.?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which way did you enter the system recovery? From advanced boot option, or using installation disc? Where is FRST currently downloaded to, your desktop?
     
  9. julesfl

    julesfl Private E-2

    I did merge the Regedit and it worked. I can't seem to find the FRST file when in Repair your computer mode. I am not using recovery disks. Rogue killer I ran again and it didn't find any problems. Attached is the new Hitman file.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then save it to your flashdrive as directed. Try again. There's a fair bit we can fix with FRST. If not, we'll have to try other ways...
     
  11. julesfl

    julesfl Private E-2

    Hello, Ran everything. attached are the files.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please re run Hitman and have it delete Malware Remnants and Potential Unwanted Programs.

    Rescan with FRST (only a scan this time) and attach fresh log.
     
  13. julesfl

    julesfl Private E-2

    Hitman will not remove the virus, unless i buy a subscription for a year, for 25.00. Is there another program I can remove these virus's with, or should I buy it?
    Thanks again for all your help! Julie
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Download and run OTM.



    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\Owner\AppData\Roaming\iPumper
    C:\Users\Owner\AppData\Roaming\iPumper\config.xml 
    
    :reg
    [-HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}]
    [-HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}]
    [-HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}]
    [-HKLM\SOFTWARE\Classes\Prod.cap]
    [-HKU\S-1-5-21-1221558428-1540082639-3331558878-1000\Software\AppDataLow\Software\Crossrider]
    [-HKU\S-1-5-21-1221558428-1540082639-3331558878-1000\Software\Escolade]
    [-HKU\S-1-5-21-1221558428-1540082639-3331558878-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now reboot the machine if it didn't already.

    Re run Hitman, attach the log for me to see.
     
  15. julesfl

    julesfl Private E-2

    Hello, Happy Friday! Here are the results.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now reboot, rescan with Hitman, and again attach log.
     
  17. julesfl

    julesfl Private E-2

    ok. am off to work...
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you comfortable with deleting them manually?
     
  19. julesfl

    julesfl Private E-2

    Hi, let me think ...deleteing manually....hmmm...I guess so, I have not done it before, usually I leave it up to a couple of friends of mine, but they are not available any more..
    I'm game....
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Open up regedit (click start type regedit) and click on regedit.exe to open.

    Navigate to the following keys and delete them one at a time. Stop if you have questions and ask me.

    • HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}
    • HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}
    • HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
    Once done, reboot the machine and re run Hitman again, attach log.
     
  21. julesfl

    julesfl Private E-2

    Wow! you r great! Here r the results.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. How is everything running right now? :)
     
  23. julesfl

    julesfl Private E-2

    Hi, seems to be running good. The pop ups were sporadic at times, so time will tell.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds