Popup's Galore

Discussion in 'Malware Help (A Specialist Will Reply)' started by scottmd1, Feb 9, 2015.

  1. scottmd1

    scottmd1 Private E-2

    Hey all - thanks in advance for helping my wife's laptop out that has popups galore with google chrome - IE is not infected at all but Chrome has popup's, new tabs with ads, the main screen is divided into several frames that has ads...

    Followed the instructions and all logs are attached.

    Again thanks in advance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Re run Hitman Pro and have it fix all it finds.
    • Same for Malware Bytes on a second sweep.
    • Now re run RogueKiller (just a scan) and attach log.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  3. scottmd1

    scottmd1 Private E-2

    Thank you very much. I have attached the logs. Not sure if you want feedback yet or not if so the issue is still there and if not ignore I said that : )

    Thank you again.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You forgot to re run RogueKiller (just a scan) and attach log.
     
  5. scottmd1

    scottmd1 Private E-2

    Correct you are - ran it but never attached - now attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
    • O15 - Trusted Zone: http://search.genieo.com
    • O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    After clicking Fix exit HJT.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [Suspicious.Path] \\DSite -- C:\Users\Theresa\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE (/Check) -> Found
    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Delete this:
    • C:\Windows\system32\tasks\DSite


    • Re run RogueKiller once more and attach log.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  7. scottmd1

    scottmd1 Private E-2

    I have completed a portion of what you asked and have run Rogue Killer - I do not find the item you are asking me to delete under registry - I do find that item under tasks.

    There were two items under register with suspicious.path

    How should I proceed?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just continue on with the rest of my instructions. :)
     
  9. scottmd1

    scottmd1 Private E-2

    Thank you - logs are attached. Chrome still has issues with in browser popup's - left side is taken over by ads - new tab popup's etc.....it does not to be any change as of yet.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm very sorry, I've had a rather busy 24 hours. Reviewing those logs now!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | ApnUpdater : "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" -> Found
    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKLM\..\Run: [SpeetItUpFree] "C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe"
    • O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"

    After clicking Fix exit HJT.




    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Delete this:
    C:\Program Files (x86)\SpeedItup Free


    Uninstall Google Chrome using Revo Uninstaller Reboot the machine and reinstall it.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  12. scottmd1

    scottmd1 Private E-2

    No worries on my end greatly appreciate the assistance whenever it comes! Had some success and a few things I couldn't do:

    - Rogue Killer - success and attached
    - HJT - speed it up free - found and deleted but ask.com was not present
    - fixME - success
    - delete speed it up free - was not there
    - uninstall / reinstall chome - success

    After re-installing things seem to be well in chrome - in 20 min of random clicking and surfing no pop-ups or tabs - so seems to be resolved!
     

    Attached Files:

  13. scottmd1

    scottmd1 Private E-2

    My wife used the computer all day today and said it is working great with no pop-up's or unwanted ads etc....so it would appear as though you have done it again : )
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's excellent. I am pleased things are running nicely again. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  15. scottmd1

    scottmd1 Private E-2

    Great - thank you as always for your help and assistance.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds