Persistent virus - jointheshop

Discussion in 'Malware Help (A Specialist Will Reply)' started by 38devand, Apr 12, 2015.

  1. 38devand

    38devand Private E-2

    I have seemed to out of the blue start getting ad pop up messages in my firefox browser and noticed that there were some installed programs that weren't supposed to be there and were obviously some kind of adware/virus/malware. I ran my primary antivirus, AVG, and when that didn't detect anything I downloaded and used malware antibytes antimalware. that detected a few things and was able to help me a little. But I am still seeing persistent signs of the virus on whatever site I go to online. There is still the occasional popup that covers 90% of my screen. I can easily close it out but it's still annoying and obviously a virus nevertheless. and there is also various words throughout every website that end up getting highlighted in green and become clickable as links to other various ad sites. In the popup on the bottom corner are the words: "jointheshop" - basic googling of how to remove 'jointheshop' brings me to many different very obviously fake 'anti virus blogs' on removing such virus and every single one the answer seems to be to download this fake anti virus program 'spyhunter'.

    Okay so that's the meat of it. I then started searching for help forums. This is the first place that I've found and I've followed all of the basic 'read me' thread instructions. The following logs have been attached:

    RKreport[1].txt from RogueKiller
    Malwarebytes' Anti-Malware log
    TDSSKiller log
    HitmanPro log
    MGlogs.zip

    Please help me get rid of this annoyance. I am fearful that it will eventually turn into something very malicious if left alone for too long on my system, as it is mainly just an annoyance at present.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please run Hitman Pro again and allow it to fix all of the Potential Unwanted Programs items that it lists. Leave the other Suspicious items alone.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  3. 38devand

    38devand Private E-2

    I followed the described steps above and here attached are the logs from the two new programs that you asked me to download and scan. I didn't see anything in the log of the second program that looks important to keep. But I did see what looks to be the culprit behind this issue I've been having with the adware. I didn't delete anything yet though so just waiting on your next post to proceed.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you can rerun AdwCleaner and have it fix what it finds this time and then reboot and see what happens. This may not resolve the problem because it may be hooked into Firefox ( and possibly other browsers ) as an addon of some sort. And a reset of the browser to defaults may be required.
     
  5. 38devand

    38devand Private E-2

    Okay I deleted the stuff that was detected in the scan that you suggested. It all mostly seems to be fixed, not noticing any popups or anything. Though there is still some minor word, link, highlighting where it shouldn't be. How do I go about resetting firefox to its defaults as you described? I've not heard of doing that before. I could google it, but I kinda wanna make sure I do it right.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is it still working okay? Sometimes it will be okay for a few hours or a day and then all of a sudden the problems will reappear.

    Are you referring to double underlined keywords on various webpages? If so, this may be normal context sensitive advertisements from AdChoices, Intellitext, Vibrant Media....etc.

    I would only do this if you still have a problem, but you can see the below link for Firefox.

    Reset Firefox to Defaults
     
  7. 38devand

    38devand Private E-2

    So far so good. I'll wait before defaulting things in my browser. And yeah those word highlights seem to be just from adchoice, which I'm assuming isn't adware or anything and just normal ads from this website. So since that's the case I'll just wait a few more days and see if anything else pops up as an issue. Thanks for the help that you've given, it was a big help :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds