iLivid and other popups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by greggwith3G, Nov 17, 2012.

  1. greggwith3G

    greggwith3G Private E-2

    Windows 7 Home Premium SP1 64-bit; battling iLivid and other popups in IE and Firefox. I ran the malware removal steps and have attached logs - please note that tdskiller found no problems and generated no logs, and MGLogs had a zip io error that seems to have prevented it from placing MGlogs.zip in the root directory (authority problem creating files in root?). Thanks for any thoughts!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Had you disabled UAC and rebooted for it to take effect? Also have you disabled any protection software before trying to run MGtools? Also did you use right click and Run As Administrator?

    Please try again. Also do the below no matter what the outcome with MGtools is.


    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  3. greggwith3G

    greggwith3G Private E-2

    Thanks for the quick and helpful reply! I reran MGTools as admin and even tried granting the Users group full control over the root drive, but I continue to get an error that the zip file can't be created on the root. My Norton was disabled during this. I also ran JRT, but it failed to put the JRT.txt log on my desktop or anywhere else on the PC. I'm sorry that I haven't moved this forward...thanks!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then since you can run Hitman, run it again and have it file all the items it showed in your first log. Then reboot your PC.

    After reboot, rerun a scan with Hitman and save a new log and attach it here.
     
  5. greggwith3G

    greggwith3G Private E-2

    Many thanks again - I reran HitmanPro and had it remove or quarantine everything it found. After reboot, the popups appear to be gone, and the attached Hitman log appears to be clean! Please let me know what other steps might be called for. This is a great improvement!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Look in the C:\MGtools folder. Do you see any of the below files?

    newfiles.txt
    nwktst.txt
    runkeys.txt
     
  7. greggwith3G

    greggwith3G Private E-2

    Hello again - I'm sorry not to be faster in these replies - the computer is not in a location I can get to easily. I've attached those 3 txt files from the MGTools folder. Many thanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and save the below to your PC in the C:\MGtools folder. Then locate the ReZip.txt file with Windows Explorer and Right Click on it and select Rename. .

    ReZip.txt

    Change the name to Rezip.bat

    Then Right Click on it and select Run As Administrator.

    It should take a couple seconds to run. You will see a black command prompt window while it is running and it should tell you that the C:\MGtools\MGlogsR.zip file as been created. Attach this ZIP file.
     
    Last edited: Nov 28, 2012
  9. greggwith3G

    greggwith3G Private E-2

    Hi there - sorry for the delay - I'm still on the case and will get that info posted asap. Thank you.
     
  10. greggwith3G

    greggwith3G Private E-2

    MGlogsR.zip is attached. Thanks so much!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java(TM) 6 Update 14

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 149.5.18.172 www.google-analytics.com.
    O1 - Hosts: 149.5.18.172 ad-emea.doubleclick.net.
    O1 - Hosts: 149.5.18.172 www.statcounter.com.
    O1 - Hosts: 108.163.215.51 www.google-analytics.com.
    O1 - Hosts: 108.163.215.51 ad-emea.doubleclick.net.
    O1 - Hosts: 108.163.215.51 www.statcounter.com.
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
    O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
    O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)

    After clicking Fix, exit HJT.

    Deletethe below folder
    C:\Program Files (x86)\Yontoo Layers Client

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now reboot your PC

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    If MGlogs.zip still fails to get created, rerun the Rezip.bat program and attach the C:\MGtools\MGlogsR.zip instead
     
  12. greggwith3G

    greggwith3G Private E-2

    Hi again - I'm still pursuing this. I'm sorry the holidays got in the way, but I appreciate your patience.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's already been almost a month and things could have change a lot in that time. However, we cannot continue until you at least finish the last instructions already given.
     
  14. greggwith3G

    greggwith3G Private E-2

    Completed all steps OK. From your list of 10 HijackThis entries to fix, I only had O2-BHO:(no name) and O2-BHO:NetAssistantBHO. The registry modifications completed successfully. Overall, the computer seems to be running normally again. I've attached the logs. Many thanks...again!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  16. greggwith3G

    greggwith3G Private E-2

    I think we are in good shape! Thank you so much for your patience throughout this process. Your help really made all of the difference…
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds