1. SailZoom

    SailZoom Private E-2

    Malwarebytes found a pum and I'm wondering if that's where these targeted ads I'm getting are coming from. At any rate I'd like to get rid of it.

    I did the malware removal steps
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you did the steps, please attach the requested logs.
     
  3. SailZoom

    SailZoom Private E-2

    ok
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rerun RogueKiller and remove these items:

    ¤¤¤ Files : 1 ¤¤¤
    [Tr.Gen0][File] C:\Users\Zoom\AppData\Local\Temp\0.txt -> Found

    ¤¤¤ Web browsers : 1 ¤¤¤
    [PUM.HomePage][Firefox:Config] 3mqrhetl.default : user_pref("browser.startup.homepage", "http://www.qconline.com/"); -> Found

    Reboot and rescan with Roguekiller and also please attach the log from ADWCleaner.

    Attach both new RogueKiller and ADW logs.
     
  5. SailZoom

    SailZoom Private E-2

    I deleted and roguekiller is clean but malwarebytes still says I have a pum and I think it's giving me ads all the time

    won't upload roguekiller log

    RogueKiller V12.11.7.0 (x64) [Jul 17 2017] (Free) by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : https://forum.adlice.com
    Website : http://www.adlice.com/download/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 8.1 (6.3.9600) 64 bits version
    Started in : Normal mode
    User : Zoom [Administrator]
    Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
    Mode : Scan -- Date : 07/19/2017 08:26:19 (Duration : 00:31:16)

    ¤¤¤ Processes : 0 ¤¤¤

    ¤¤¤ Registry : 0 ¤¤¤

    ¤¤¤ Tasks : 0 ¤¤¤

    ¤¤¤ Files : 0 ¤¤¤

    ¤¤¤ WMI : 0 ¤¤¤

    ¤¤¤ Hosts File : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ MBR Check : ¤¤¤
    +++++ PhysicalDrive0: HGST HTS541075A9E680 +++++
    --- User ---
    [MBR] d6ef60349a0b824adcb4dcf6d0c76b41
    [BSP] 7a44df082fa489be1bdb074e59290137 : Empty MBR Code
    Partition table:
    0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 400 MB
    1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 821248 | Size: 260 MB
    2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1353728 | Size: 128 MB
    3 - Basic data partition | Offset (sectors): 1615872 | Size: 80445 MB
    4 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 166367232 | Size: 451 MB
    5 - [SYSTEM] Basic data partition | Offset (sectors): 1407565824 | Size: 28116 MB
    User = LL1 ... OK
    User = LL2 ... O
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you unable to have MBAM remove the item?
     
  7. SailZoom

    SailZoom Private E-2

    It quarantees but it's still there on the next scan

     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from MBAM.
     
  9. SailZoom

    SailZoom Private E-2

    mbam pum gone I think but maybe morphed to this - now I keep getting a urgent firefox path needed from
    uubeilisthoopla.net. I was trying to change my password and the download for it popped up again I had killed that page. see attached
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista,Seven,Eight or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  11. SailZoom

    SailZoom Private E-2

    thanks
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds