Popup Keeps ...popping Up

Discussion in 'Malware Help (A Specialist Will Reply)' started by hcoons, Jan 23, 2016.

  1. hcoons

    hcoons Private E-2

    A popup appears when my wife logs in on our laptop, and when we close it it keeps popping up. I think I have run the cleaning procedures correctly, and my logs are attached. The popup keeps coming up, though, so maybe I missed something. Would you mind helping us figure out what's going on?

    Thanks!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, you missed the MGLogs.zip from running MGTools.exe. Please upload that and then I can get to work on a complete analysis.
     
  3. hcoons

    hcoons Private E-2

    ...Yes, yes I did. :( I hope this is the right one!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Malware Bytes again and let it remove anything else it may find.

    Re run Hitman Pro, activate/enable the free trial, and then let it too remove what it finds.


    Delete these:
    C:\ProgramData\7bbf41c8-27f7-1
    C:\ProgramData\7bbf41c8-3ff3-0


    Download >>> Cleano 1.31

    Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows (click on link below to see image)

    View attachment 148092
    Click clean now and exit the program.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Re run Hitman Pro yet again and hopefully upload a clean log.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  5. hcoons

    hcoons Private E-2

    Okay. I think I did everything right:
    • I ran Malware Bytes, and it had some stuff in the quarantine, so I downloaded a log before I cleaned out the quarantine area. I hope that's okay (and I think that's what I actually did). Log attached.
    • I ran Hitman Pro, went to the License tab, activated the free trial, ran it, and downloaded the log. Log attached.
    • Then I deleted those two folders you indicated.
    • Then I downloaded CleanO, checked the two boxes in the popup, and ran it.
    • Then I downloaded JRT and ran it. Log attached.
    • Then I ran Hitman Pro again, and this time it found only one thing, so I deleted that item, too. Log attached.
    • Then I ran MGTools GetLogs.bat, and I got the logs. Heck, they might even be the right ones, this time! File attached.
    I'm a bit nervous about whether or not I'm following the steps correctly, so if I need to fix/do something else please let me know.

    Thanks!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And how are things running now?
     
  7. hcoons

    hcoons Private E-2

    Actually... much better! No more popups on my wife's user account! Yay! Thank you! :) And things seem to be running a quicker in general, too, than they have in a long time. :) I salute you!

    I think the last time I used the service there was a link to buy T-shirts or something to support the site. Is that still an possibility, or are there different options now?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I am very pleased to hear that everything is running nicely again ;) You are welcome for the assistance.
    With regards to showing your support, you could indeed purchase an item such as a T shirt, or you could make a little donation to us. The yello 'donate' button in on the main page (see link in my signature) towards the bottom right.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds