Malware: Click To Continue > By Advertise

Discussion in 'Malware Help (A Specialist Will Reply)' started by gvbussel, Mar 21, 2016.

  1. gvbussel

    gvbussel Private E-2

    Hello guys/girls,

    Since two weeks I have noticed malware advertisements in firefox. I have tried a lot of things on the internet and a few malware scanners. Nothing helped.

    I have just tried the comprehensive malware removalhttp://cdncache-a.akamaihd.net/items/it/img/arrow-10x10.png guide on this forum. Attached to this post you can find my .zip file.

    The problems I'm experiencing in Firefox are as follows. When there is plain text on a page, some words will be highlighted, bigger, underlined and have a sort of link symbol next to it. When holding your pointer on the word a pop-up comes up for some random website. This is also where it says: Click to continue > by Advertise.

    Hope you can help me.
    Geordy
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a malware problem. These are just mouse over ads that popup when your mouse moves over various underlined keywords. Many websites, including Major Geeks, use these as a source of revenue to help offset costs of running a free website and forums like this. These are not malware issues. These are advertisements that websites use as a source of revenue. They are things like AdChoices, AdSense, IntelliText. When a mouse cursor moves over then, a short ad will show. Is this what you are referring to?

    Further more, if you wish for me to thoroughly check for malware, you will need to upload ALL of the requested logs, please.
     
  3. gvbussel

    gvbussel Private E-2

    Thanks for the reply. I have never seen it like this, it is only occuring since two weeks, and the style is the same on every website. I just seems to select random words. I've uploaded a few screenshots with this post. I have only saved the MGlogs, haven't saved the others. Stupid of me. Should I run them again? Furthermore I use an adblocker, which I suppose would block this kind of advertising if it was done by the websites themselves? Hope you can help.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, in your first post, I too am seeing the little green symbol (see my uploaded file) But I am not seeing it anywhere else. Also strangely enough... Firefox will not let me post to this thread.... switching to Internet Explorer in order TO post.

    Yes, I would like you to run all the other requested tools, even if you ran them before and didn't save logs. Upload once ready.

    I would also like you to run these:

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     

    Attached Files:

  5. gvbussel

    gvbussel Private E-2

    Finished all the original logs. Have troubles posting in FF as well. This has now been posted in IE :-S
     
    Kestrel13! likes this.
  6. gvbussel

    gvbussel Private E-2

    And the logs...
     

    Attached Files:

  7. gvbussel

    gvbussel Private E-2

    Also ran the second set of tests.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well how strange that both of us can only use Internet Explorer to post here! I can use Firefox in ANY other thread here at Majorgeeks, just not this one. I am not seeing anything in the logs. Try doing this:
    Reset Mozilla Firefox to defaults
    Let me know how you get on.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have no problem using Firefox. I'm using V45.0.1
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not that this has anything to do with the Ads by Advertise, but it will impact performance and ability to cleanup the PC. Both Ad-Aware Antivirus and Symantec Endpoint Protection are installed an running. And per FRST, Ad-Aware is even hidden and needs to be unhidden so that you can choose whether to uninstall it or Symantec.


    However the below was seen in FRST which needs to be removed because it is adware

    FF Plugin HKU\S-1-5-21-1895577662-1677200029-1617787245-552282: @acestream.net/acestreamplugin,version=3.0.4 -> C:\Users\s100342\AppData\Roaming\ACEStream\player\npace_plugin.dll [No File]
    FF Extension: AS Magic Player - C:\Users\s100342\AppData\Roaming\Mozilla\Firefox\Profiles\hcnizlm8.default-1457528334585\extensions\magicplayer_unlisted@acestream.org [2016-03-09]
    FF HKU\S-1-5-21-1895577662-1677200029-1617787245-552282\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\s100342\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
     
    Last edited: Mar 24, 2016
    Kestrel13! likes this.
  11. gvbussel

    gvbussel Private E-2

    I did a reset of Firefox, had done that before already. Helped for a day or so, then the problem came back. I seem to be problem free now as well. I hope this stays this way, otherwise I will come back here offcourse. Thanks for the help. (still can't post here on FF though)
     
  12. gvbussel

    gvbussel Private E-2

    I have just uninstalled Ad-Aware. The adware found by FRST, can I just go to the location on the disk and remove the files? Or is there something else I should do?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.


    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply.
    Then attach the below log:



      • Fixlog.txt


        Also at this point, I want to double check the status of things by having you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.
     

    Attached Files:

  14. gvbussel

    gvbussel Private E-2

    Did as you explained :) No ads seen since yesterday.
     

    Attached Files:

    Kestrel13! likes this.
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's awesome!! I will post final steps below... :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  16. gvbussel

    gvbussel Private E-2

    Haven't had any problems anymore since doing this. Thanks a lot guys! PS. This wasn't posted in Firefox :-(!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's great! Having to use IE to post here... still no joy with FF after a couple updates....
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds