Shop to Win Ask Bar PUPs

Discussion in 'Malware Help (A Specialist Will Reply)' started by safetydave, Apr 27, 2014.

  1. safetydave

    safetydave Private E-2

    Malewarebytes found several pups. I unfortunately had MB delete them before I read the READ ME FIRST POST:(
    I did a screen print of the quarantine log if needed
    Observations
    Shop to win appeared afterwards on another user account on the same computer
    Opening weblinks or files is erratically a problem
    Takes a long time to for computer to shut down
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.

    Re run Hitman and have it remove what it finds.




    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [V2][SUSP PATH] IHSelfDeleteTASK : CMD - /C DEL C:\Users\spike\AppData\Local\Temp\IHUB914.tmp.exe [x][x] -> FOUND
    • [V2][SUSP PATH] IHUninstallTrackingTASK : CMD - /C DEL C:\Users\spike\AppData\Local\Temp\IHUB7DB.tmp.exe [x][x] -> FOUND
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. safetydave

    safetydave Private E-2

    Kestrel13!
    Thank you!
    1-Hitmanpro came back clean post removal see attached log
    2-Roguekiller files deleted as instructed see attached
    3-TShut down firewall and ant-virus then ran JRT as an admin logs were attached
    4-Ran C:\MGtools\GetLogs.bat as admin and attached mglogs.zip
    All above were completed with User Account Control Off
    Woke up to a blue screen this am after leaving PC on overnite
    PC still takes extended time to shut down
     
  4. safetydave

    safetydave Private E-2

    5-Also put into normal starting mode with msconfig
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs did not attach. :(
     
  6. safetydave

    safetydave Private E-2

    Apologies for not checking my post for attachments...
    I hope you can better assist me with them attached this time;)
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Let me know how things are running now please. :)
     
  8. safetydave

    safetydave Private E-2

    Good evening
    Woke up to a blue screen yesterday after leaving PC on overnite, nothing today
    PC still takes extended time to shut down
    Rescanned with hitman, malwarebutes, roguekiller & tdsskiller all clean
    You must not have seen anything on JRT & MGTools logs?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you still seeing anything to do with shop to win?
     
  10. safetydave

    safetydave Private E-2

    Nothing with shop to win
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So what are your remaining issues? :confused I have already removed what little I found.
     
  12. safetydave

    safetydave Private E-2

    Sorry for confusion
    I believe we are done and I am grateful for your assistance
    I have not seen anymore malware issues
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds