Lots and Lots of Adware

Skoodge

New Member
Thread author
Apr 26, 2015
4
I've tried everything I know from experience, and it's still bothering me. You can check the 'steps taken' thing, because I've done quite a bit. And I've researched what I could, and it turns out this thing likes to steal data, which is a real bummer, because I've been meaning to buy some stuff that has an urgent date approaching, and my/my brother's birthday is soon, so I really don't want any of my family member's info taken either, just because they were trying to shop online. I would *really* like to buy what I wanted to buy before it comes too late to be of use, and also be able to have a good birthday as well, y'know? So I would LOVE if this could be over ASAP. I really don't want this ruined for me. Really.

So yeah, the blunt rundown of what it does - track/distribute info, use up storage, install adware , and allow other baddies entrance. Sucks to suck, I guess. It's also usually a piggybacker from other malicious downloads , but I don't know where that would have come from. I'm not usually the culprit for falling for fishy programs . ...Or should I say, phishy programs. Hahahahaha......I hate myself.

Okay.

The virus(es) presumably stem(s) from "TremendousCoupon"/"Tremendous Sale", since that's the little signature on everything, and the extensions/ads I keep getting are either under that same name, or "SallePlus." I've also included an image of the little green links that pop up everywhere, that I mentioned before. Oh, and these are the ads that come up every time I search something. (Yes, I would really love to buy that! Thank you for the offer! /sarcasm)
  • upload_2015-4-26_18-54-59.png
  • upload_2015-4-26_18-56-13.png
  • upload_2015-4-26_19-24-16.png
And, um, I'm not really sure of what else to say here. A little help that *doesn't* involve everything I've already done would be 'tremendous.' (I'm really starting to hate that word.) None of the other tutorials for getting rid of it I've come across go over anything i don't already know/haven't tried yet.

I would also really love not having to pay for removal, since I'd rather not have my parents be pissed at me, or have them bring it into the godawful staff at my local Staples. (When the 8.1 update totally wrecked everything, locked us out of our account, and changed the system font to Wingdings/some other stupid crap like that, we had to pay $500 just to wait a couple *days* longer than we were supposed to for someone who knew what he was doing to actually deal with the problem. The other guy was like 'dang, I've never seen this before....uh, I'll call you later.' And then never actually called. Ever.) Anyway. I'm rambling. The point is, I'd rather solve this with as little money poured into it as possible, and as soon as I'm able.
 

Attachments

  • Addition.txt
    49.8 KB · Views: 26
  • FRST.txt
    34.5 KB · Views: 39

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Helllo,

My name is Argus and and I will be helping you with your computer problems.

Before we begin, please note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The logs can take some time to research, so please be patient with me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not be able to help you if you do not follow my instructions.


51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    autoclean;
    emptyalltemp;
    ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.
 

Skoodge

New Member
Thread author
Apr 26, 2015
4
yo yo sorry for the delay, gotta share this computer with the whole family yknow how that is
here's the results, and thank you for the help
 

Attachments

  • zoek-results.txt
    7.4 KB · Views: 25

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION



Chrome installation is altered by malware. Reinstall is needed.


Close all Chrome windows and tabs.
Go to the Start menu > Control Panel.
Click Programs and Features.
Double-click Google Chrome.
Click Uninstall from the confirmation dialog. Delete your user profile information, like your browser preferences, bookmarks, and history, select the "Also delete your browsing data" checkbox.


Click Start, copy in search %LOCALAPPDATA%\ and remove folder Google

Download Chrome
https://www.google.com/intl/en/chrome/browser/desktop/
 

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Zoek is remove fake profiles, but reinstall chrome is necessary because that is fake version chrome.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top