I've been hit with some kind of malware...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fillibuster, Dec 8, 2013.

  1. Fillibuster

    Fillibuster Private E-2

    Seems another bit of malware has found its way to my computer. When I browse around on a site like, say, Deviantart, ads that slide into the window appear, and sometimes when I click a link, a popup window will come up. Furthermore, certain words are highlighted and double-underlined, leading to links that also pull up ads that I would rather not click on. I'm assuming it might have come from a bad file I downloaded from a ROM site, namely CoolROM--one of their "special" files for downloading a ROM. Guess I should've known better than that. I think it was a couple days ago when that happened, and the problem just now started up after I recently rebooted my computer.

    So far I've followed all the malware procedures, though if I've goofed please let me know and I'll try again to get it working. So far the problem is still persisting, and it's making me worry. I hope you'll be able to help me with this problem soon.
     

    Attached Files:

  2. Fillibuster

    Fillibuster Private E-2

    Also, for that matter, ads have been appearing frequently in other spots and AdBlock doesn't seem to be stopping them. However, in the add ons, I did notice a new one: Surf and Keep. And I seriously doubt that's helpful. Sorry I didn't mention this right off.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Malwarebytes log shows "No action taken." You need to run it again and fix what it finds this time.

    These are not malware issues. These are advertisements that wibsites use as a source of revenue. They are things like AdChoices, AdSense, IntelliText. When a mouse cursor moves over then, a short ad with show.


    You only have a little bit of junkware to cleanup.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • You will be prompted to restart your computer. A text file will open after the restart.
    • You can just close it. Attach the below log file:
      • C:\AdwCleaner[S1].txt

    Are you having any malware problems ?
     
  4. Fillibuster

    Fillibuster Private E-2

    The intrusive pop up ads no longer seem to be appearing, so that's something.

    Also, the AdwCleaner I downloaded was somewhat different from what you described, so it left me confused at first. I hope I'm sending the right logs. Also, terribly sorry on MBytes, I had mistakenly sent the wrong log. My bad entirely. I've included the proper one this time.

    Also, Surf and Keep is gone from my add ons, though it looks like it took a few others with it.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. Fillibuster

    Fillibuster Private E-2

    Right. Everything's pretty much okay now. Thanks very much, I appreciate your help. :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds