This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Popups on Windows 8 [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

There are popups coming up all over the place when I access the internet on a Windows 8 computer. I downloaded and ran Malwarebytes Antimalware and it found and fixed over 1500 issues. I also downloaded and ran scans using aswMBR and FRST. Logs below. Thanks for your help!

 

aswMBR version 1.0.1.2161 Copyright© 2014 AVAST Software Run date: 2014-10-29 19:52:24 —————————– 19:52:24.373 OS Version: Windows x64 6.2.9200 19:52:24.373 Number of processors: 2 586 0x3708 19:52:24.374 ComputerName: LAPBUSCUS UserName: Nathaniel 19:52:25.628 Initialize success 19:52:25.628 VM: initialized successfully 19:52:25.647 VM: Intel CPU supported 19:52:28.583 VM: supported disk I/O storport.sys 19:57:39.119 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000021 19:57:39.125 Disk 0 Vendor: WDC_WD5000LPVX-80V0TT0 01.01A01 Size: 476940MB BusType: 11 19:57:39.268 VM: Disk 0 MBR read successfully 19:57:39.273 Disk 0 MBR scan 19:57:39.278 Disk 0 unknown MBR code 19:57:39.282 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1 19:57:39.320 Disk 0 scanning C:\Windows\system32\drivers 19:57:46.302 Service scanning 19:58:09.129 Modules scanning 19:58:09.140 Disk 0 trace - called modules: 19:58:09.149 19:58:09.158 Disk 0 statistics 131230/0/5 @ 12.53 MB/s 19:58:09.166 Scan finished successfully 19:58:21.119 Disk 0 MBR has been saved successfully to "C:\Users\Nathaniel\Desktop\MBR.dat" 19:58:21.131 The log file has been saved successfully to "C:\Users\Nathaniel\Desktop\aswMBR.txt"

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-10-2014 Ran by [removed] (administrator) on LAPBUSCUS on 29-10-2014 20:00:06 Running from C:\Users\[removed]\Desktop [removed]

Hello, p1052445.

 

My name is fbfbfb.  I will gladly assist you with your concerns.

 

While working to resolve the issues with your machine, please follow these guidelines:

  • Please be patient.  Logs are lengthy and can take time to analyze.
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • Use only those tools that you have been directed to use.
  • Do not install or uninstall any applications or run any other scans without being directed to do so.
  • Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
  • Stay with me until your machine has been deemed all clear.
  • Please reply within 3 days of each posting to avoid closing this topic.  If you need more time to complete tasks, or if you will be away, please let me know in advance.

 

Please run the following scans

 

1.  AdwCleaner

 

We will be running this cleaner in 2 parts.  The first time you run it, please scan only and send me the log.  We will rerun it again later to clean.

 

Please download AdwCleaner from HERE.

  • Double click on adwcleaner.exe.  Note:  Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

 

2.  Junkware Removal Tool

 

Please download Junkware Removal Tool from HERE and save it to your desktop.

  • Shutdown your antivirus to avoid any potential conflicts.
  • Right-mouse click JRT.exe and select Run as Administrator.
  • JRTwill begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
  • Post the contents of JRT.txt into your next reply.

 

3.  Malwarebytes Anti-Malware (MBAM)

 

Download MBAM from HERE > Save it to your Desktop.

 

Note:

  • Windows XP > Double click on the icon to run it.
  • Windows Vista, Windows 7 and 8 > Right-click and select Run As Administrator.

[external image: MBAMDashboard_zpsddef9b5f.gif]

 

  • On the Dashboard, click Update Now.
  • Click the Settings tab > Click Detection and Protection.
  • Under Non-Malware Protection, make sure that both PUP and PUM are set to show Treat Detections as Malware .
  • Click Advanced Settings > Check mark Automatically Quarantine Detected Items.
  • On the Dashboard, click Scan.
  • Select Threat Scan > Click Scan Now.
  • When the scan is finished and the log pops up, select Copy to Clipboard .
  • Please paste the log into your next reply.
  • Exit Malwarebytes.

 

4.  Security Check

  • Download Security Check from HERE.
  • Save it to your desktop.
  • Double-click SecurityCheck.exe > Follow the onscreen instructions inside the black box.
  • In the event you get the message Unsupported operating system. Aborting now., reboot and try again.
  • A Notepad document should open automatically called checkup.txt.  This may take a few minutes.  Please copy and paste the contents of that document into your next reply.

 

CHECKLIST : In your next reply, please post the following:

  • AdwCleaner[R0].txt
  • JRT.txt
  • MBAM log
  • checkup.txt

 

Hello, p1052445.

 

I have not heard back from you.  Do you still need help?  If so, please reply within the next 24 hours to avoid closing this thread.

 

Thank you.

Ran Adware Cleaner and JRT - logs below. Malwarebytes hangs up on initialization stage and couldn't run a scan. Should I go ahead and run SecurityCheck w/o Malware bytes?

# AdwCleaner v3.311 - Report created 31/10/2014 at 21:00:34
# Updated 30/09/2014 by Xplode
# Operating System : Windows 8.1 Connected  (64 bits)
# Username : Nathaniel - LAPBUSCUS
# Running from : C:\Users\Nathaniel\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
Service Found : APNMCP
Service Found : sbmntr
 
***** [ Files / Folders ] *****
 
File Found : C:\END
File Found : C:\Users\Nathaniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Found : C:\Users\Nathaniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Found : C:\Users\Nathaniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage
File Found : C:\Users\Nathaniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage-journal
File Found : C:\Users\Nathaniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage
File Found : C:\Users\Nathaniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage-journal
Folder Found : C:\Program Files (x86)\AskPartnerNetwork
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\Optimizer Pro
Folder Found : C:\Program Files (x86)\Settings Manager
Folder Found : C:\Program Files (x86)\YTDownloader
Folder Found : C:\ProgramData\374311380 
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\AskPartnerNetwork
Folder Found : C:\ProgramData\eaisytoshOp
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tech Hotline
Folder Found : C:\Users\NATHAN~1\AppData\Local\Temp\apn
Folder Found : C:\Users\Nathaniel\AppData\Local\AskPartnerNetwork
Folder Found : C:\Users\Nathaniel\AppData\Local\Astromenda
Folder Found : C:\Users\Nathaniel\AppData\Local\globalUpdate
Folder Found : C:\Users\Nathaniel\AppData\LocalLow\Object Browser
Folder Found : C:\Users\Nathaniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
Folder Found : C:\Users\Nathaniel\AppData\Roaming\PC Tech Hotline
Folder Found : C:\Users\Nathaniel\Documents\Optimizer Pro
Folder Found : C:\Users\Public\Documents\ShopperPro
 
***** [ Scheduled Tasks ] *****
 
Task Found : BlockAndSurf Update
Task Found : ShopperPro
Task Found : ShopperProJSUpd
Task Found : SMupdate1
Task Found : SPDriver
Task Found : YTDownloader
 
***** [ Shortcuts ] *****
 
Shortcut Found : C:\Users\Public\Desktop\Google Chrome.lnk ( hxxp://www-search.net/?s=E9Pztugdu0341,0b955ef0-bd49-4dd7-9093-b5eb75c02723,&pi=2 )
Shortcut Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk ( hxxp://www-search.net/?s=E9Pztugdu0341,0b955ef0-bd49-4dd7-9093-b5eb75c02723,&pi=2 )
Shortcut Found : C:\Users\Nathaniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www-search.net/?s=E9Pztugdu0341,0b955ef0-bd49-4dd7-9093-b5eb75c02723,&pi=2 )
Shortcut Found : C:\Users\Nathaniel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ( hxxp://www-search.net/?s=E9Pztugdu0341,0b955ef0-bd49-4dd7-9093-b5eb75c02723,&pi=2 )
Shortcut Found : C:\Users\Nathaniel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk ( hxxp://www-search.net/?s=E9Pztugdu0341,0b955ef0-bd49-4dd7-9093-b5eb75c02723,&pi=2 )
 
***** [ Registry ] *****
 
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\Software\Compete
Key Found : HKCU\Software\AppDataLow\Software\Object Browser
Key Found : HKCU\Software\AskPartnerNetwork
Key Found : HKCU\Software\BRS
Key Found : HKCU\Software\Compete
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\ShopperPro
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\Tutorials
Key Found : [x64] HKCU\Software\AskPartnerNetwork
Key Found : [x64] HKCU\Software\BRS
Key Found : [x64] HKCU\Software\Compete
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\ShopperPro
Key Found : [x64] HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\Tutorials
Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\SOFTWARE\AskPartnerNetwork
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
Key Found : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\CompeteInc
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\InstallCore
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\iWebar-nv
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Found : HKLM\SOFTWARE\ShopperPro
Key Found : HKLM\SOFTWARE\Tutorials
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : [x64] HKLM\SOFTWARE\iWebar-nv
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Found : [x64] HKLM\SOFTWARE\ShopperPro
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17344
 
 
-\\ Google Chrome v38.0.2125.111
 
[ File : C:\Users\Nathaniel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [10364 octets] - [31/10/2014 21:00:34]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [10425 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.21.2014:1)
OS: Windows 8.1 Connected x64
Ran by [removed] on Fri 10/31/2014 at 21:08:45.62
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
Successfully stopped: [Service] APNMCP
Successfully deleted: [Service] APNMCP
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] "hkey_current_user\software\askpartnernetwork"
Successfully deleted: [Registry Key] "hkey_local_machine\software\askpartnernetwork"
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
 
 
 
~~~ Files
 
Successfully deleted: [File] "C:\Users\Nathaniel\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Nathaniel\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Nathaniel\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Nathaniel\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Nathaniel\appdata\local\google\chrome\user data\default\local storage\https_static.livelyrics00.live-lyrics.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Nathaniel\appdata\local\google\chrome\user data\default\local storage\https_static.livelyrics00.live-lyrics.com_0.localstorage-journal"
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\ProgramData\eaisytoshOp
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\Nathaniel\AppData\Roaming\pc tech hotline"
Successfully deleted: [Folder] "C:\Users\Nathaniel\appdata\local\globalupdate"
Successfully deleted: [Folder] "C:\Program Files (x86)\globalupdate"
Successfully deleted: [Folder] "C:\Program Files (x86)\optimizer pro"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pc tech hotline"
Successfully deleted: [Folder] "C:\Users\Nathaniel\documents\optimizer pro"
Successfully deleted: [Folder] "C:\ProgramData\AskPartnerNetwork"
Successfully deleted: [Folder] "C:\Program Files (x86)\askpartnernetwork"
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 10/31/2014 at 21:17:51.79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Hello p1052445.

 

Thank you for your reply.  Yes, you can go ahead and run Security Check.

 

Your FRST log indicates that your system is heavily infected with malware.  Most likely, this is preventing MBAM from running on your machine. 

 

Please run the following tools

 

1.  AdwCleaner

 

Double click on AdwCleaner.exe to run the tool again.

  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
  • This time, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleanerto restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

 

2.  RKill

 

Please download RKill from the list below. (Courtesy of bleepingcomputer.com).

There are 5 different versions of this tool.  If one of them won't run,  please try the next one in the list. You only need to get one of the tools to run, not all of them.

 

Note: Vista and Windows 7 Users must right click and select Run as Administrator to run the tool.

 

1. rkill.exe
2. rkill.com
3. rkill.scr
4. WiNlOgOn.exe
5. uSeRiNiT.exe

 

Note:

  • You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message open – do not close the message.
  • Run RKill repeatedly until it's able to do it's job. This may take a few tries.
  • You will know RKill has completed its job when your desktop (explorer.exe) cycles off and then on again.
  • Do not reboot your computer after running rkill as the malware programs will start again.

Once RKill has finished, try running Malwarebytes Anti-Malware again.

 

CHECKLIST : In your next reply, please post the following:

  • checkup.txt
  • AdwCleaner[S0].txt
  • MBAM log

 

 

Hello p1052445.

 

Do you still need help?  I would like to remind you that I close my threads after 3 days of no response.  Please advise.

 

 

Please reply within 3 days of each posting to avoid closing this topic.  If you need more time to complete tasks, or if you will be away, please let me know in advance.

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI