Cannot Remove Ad's by 'Notification' / 'Advertising Support'

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
This is what happens when you give a 13 year old administrator privileges. -.-

EDIT: In fact on this page the ads appear IN the posts. Not even spaced out in between them.

For clarification sake this is the site it directs me to:

advertising-support why.php?type=3&zone=372666&pid=1685&ext=Notification

That website says it's as simple as uninstalling this website's program:

coupondropdown

Which I also do not have installed.

I'd also like to note that by uninstalling the internet browser and re-installing it the ads briefly disappear. Leading me to believe the adware/malware is located elsewhere on the system, and isn't just a simple extension like all of the quick fix guides suggest.

I just noticed pop-up tabs also attempt to emerge in the browser as well.
 

Attachments

  • FRST.txt
    62.7 KB · Views: 97
  • Addition.txt
    79.9 KB · Views: 123
Last edited:

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
I browsed through a few other forum posts and think I may have found he solution. I simply reset my router, as it was a solution for 'blue highlighted text' a few posts back hopefully this is a permanent solution if not i'll be back within the week with and update.

EDIT: Nevermind -.- they came back after leaving this page.
 
Last edited:

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


Let's make one fix with FRST.


FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    1.8 KB · Views: 89

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
Yes I do still see ads. :T

I'd also like to note that physical popup tabs have made their way through now. With the same link appearing in the bottom right to 'advertising support'

I haven't check other users for symptoms though, when running the adware scans files appeared to be found on other users. Is it possible for it to be isolated one user's account? I might login as another user to test this between now and tomorrow morning.
 
Last edited:

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
It's getting worse I'm getting pop-ups approximately every 20-25 web page changes or clicks, here are some examples of ads and popup attached. :(

I'm getting scared that this is going to get worse. It's asking me to download 'updates' or 'repairs' now, it wasn't doing that before.
When these pop-ups appeared the browser downloaded files for the one in the middle it was called: DownloadFileSetup_55MdT.exe
And the other was a blatant fake: Player-Chrome.exe
The firewall removed both immediately.
In website ads.png Pop up example.png WTF really....png
 

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
Just by pressing and holding the router button correct? I believe i attempted this previously but i'll give it another shot. Should i shut off the computer in the meantime? Maybe remove the LAN cable as well?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
You can remove it if you wish. Please consult your manufacturer/model manual how to perform factory reset. I am not sure you will do the job only by holding reset button.
 

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
Reset the router a second time no luck. Running AdwCleaner again. I feel like I'm just running troubleshooting options at this point. I'll run all the scanners and post the results from them all afterwords.
 

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
[AdwCleaner Reports]
 

Attachments

  • AdwCleaner[R1].txt
    2.7 KB · Views: 98
  • AdwCleaner[R2].txt
    1.9 KB · Views: 64
  • AdwCleaner[R0].txt
    19.4 KB · Views: 112
  • AdwCleaner[R3].txt
    2.3 KB · Views: 44
  • AdwCleaner[S0].txt
    18.7 KB · Views: 107
  • AdwCleaner[S1].txt
    2.4 KB · Views: 50
  • AdwCleaner[S2].txt
    1.9 KB · Views: 56
  • AdwCleaner[S3].txt
    2.5 KB · Views: 63

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Okay, let's scan your PC again.



FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
Reran JRT, (Side note did they just recently update JRT?)
and I also reran FRST scan to see if there were any new changes.
I'd also like to note the the in site ads have reduced in frequency there used to be interspersed larger square ads in addition to the rectangle ones inside the page, the square ones have ceased to appear.

(I ran the additional scans if that's what you meant.)
 

Attachments

  • JRT.txt
    930 bytes · Views: 62
  • FRST.txt
    78.5 KB · Views: 84
  • Addition.txt
    65.2 KB · Views: 77
  • Shortcut.txt
    118.9 KB · Views: 268

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
First, go and remove Shopop


FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    102 bytes · Views: 59

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
Ran the fix, also ran HitmanPro and Malwarebytes. Ads are still here though. Reran FRST scan.

In addition Norton has been locking down viruses more frequently when I am simply browsing on a static page. In the bottom left of my browser it keeps 'waiting for' the data for ads from different sources, noting that common addresses are revsci net, rlcdn com, and majuwe com. Does that help?
 

Attachments

  • Fixlog.txt
    648 bytes · Views: 51
  • HitmanPro_20140919_1407.log
    38.9 KB · Views: 56
  • FRST.txt
    52.5 KB · Views: 116
  • Addition.txt
    65.2 KB · Views: 40
Last edited:

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
I would like to see report from one more tool:


TDSSKiller_Kaspersky.png
Scan with TDSSKiller

Please download TDSSKiller by Kaspersky and save it to your desktop.

  • Right-click on
    TDSSKiller_Kaspersky.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Click on Change parameters and put a checkmark beside Loaded modules. A reboot will be needed to apply the changes, allow it to do so.
  • Your machine may appear very slow and unusable after that - it's normal.
  • TDSSKiller will run automaticaly. Click on Change parameters and click OK.
  • Click the Start Scan button and wait patiently.

If anything will be found follow this guidelines:
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    If Cure is not available, please choose Skip instead.
  • Do not choose Delete unless instructed!

A report will be created in your root directory, (usually C:\ drive) in the form of TDSSKiller.[Version]_[Date]_[Time]_log.txt. Please include the contents of that file in your next post.
 

Kyle Dressler

New Member
Thread author
Verified
Sep 17, 2014
17
Scanner found one thing an updater for a gaming program. It says the file size is too large to upload here are it's contents:

not good.
 
Last edited by a moderator:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top