Solved Infected by very sticky adware, now nothing can dectect it

Status
Not open for further replies.

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
My new computer has been infected by very sticky adware. When I use browsers (both Edge and Chrome) and if the webpage I'm on contains any pop-ups or audio to play (such as pronunciation link on a dictionary webpage), some ad audio will play automatically, sometimes also some scam pop-up window shows up (saying my system was infected and have to call a 1800 number). I have tried Adwcleaner, Malwarebytes, HitmanPro, Zemana and others. At first Adwcleaner, Malwarebytes and HitmanPro all found some malwares and handled it. But the problem continues! Then I reseted my Windows 10 twice which still didn't fix the problem. I even used Microsoft tool to get a clean installation of Windows 10. To my surprise, the problem IS STILL THERE after the clean installation! Now none of the malware cleaners can find any malwares in my computer. I ran FRST and uploaded the files. Please help and your advice will be very much appreciated!
 

Attachments

  • Addition.txt
    16.5 KB · Views: 3
  • FRST.txt
    92.7 KB · Views: 1

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    233 bytes · Views: 6

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
Thank you so much for such a prompt response! Very much appreciated!
 

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
Hi TwinHeadedEagle, I have run the fix and pls see attached fixlog. I will let you know how my computer goes later!
 

Attachments

  • Fixlog.txt
    1.7 KB · Views: 2

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
MS Edge works fine now! I'll install Chrome to see if there's an)y problem with Chrome. By the way, If I reset my OS to the factory state (I sort of want to get my manufacturer Win10 back as it contains some preinstalled apps and features and my current OS is a generic 'clean' installation of Win10). If I do so, will the adware come back? After getting infected, I had resetted my OS twice but the adware lived on. I'm worried the recovery files have been infected by the adware?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
I am not sure if this corrected the problem. You should install Chrome and let me know. I don't know how exactly you reset your system.
 

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
Very sad, I just installed Chrome and rogue ad audio played again! To increase my pain, the problem returns to my newly fix Edge also! I ran FRST again and uploaded the files for you to have a look.
 

Attachments

  • FRST.txt
    96.4 KB · Views: 5

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's try this:

FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    49 bytes · Views: 3

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
Thanks! I ran it again but it doesn't make any change this time. Please see the attached fixlog.
 

Attachments

  • Fixlog.txt
    567 bytes · Views: 1

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
So, it only happens in your browsers? Is it happening no matter which website you visit?
Yes. If I don't open any browsers I don't have any problem. I don't seem to have problem if I don't click some specific link, such as 'rating' in a forum, which will normally bring up a pop-up window for me to choose the value of rating, or if I click on the link to play the pronunciation of a word. Please look at the dictionary website page which I have problem with. If I click on the speaker icon to play the pronunciation, the rogue ads will start, however, not immediately, but after a while!
 

Attachments

  • dictionary.jpg
    dictionary.jpg
    198.1 KB · Views: 6

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
Does this mean the adware is still in my machine, however I can keep the symptoms in the bay by enabling adblock? I hate this adware and it has been taking all my available time for 4 days straight. Is there any solution for me to get rid of it? Thanks!
 

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
Previously I reset my laptop from Setting>Recovery>Reset PC as the screenshot attached and it didn't get rid of the adware. Even I started fresh with a clean installation of Win10 downloaded from Microsoft still didn't kill the adware. Do you think my only choice is to contact technical support of the manufacturer to get them to format and reinstall my machine?
 

Attachments

  • Reset PC.jpg
    Reset PC.jpg
    172 KB · Views: 5

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Why would you disable adblock? It is designed to stay enabled on your browser. There is not adware on your system, there is nothing on your system. This is related to the website you visit, they have advertisements.
 

JennyF

New Member
Thread author
Verified
Sep 17, 2016
16
Why would you disable adblock? It is designed to stay enabled on your browser. There is not adware on your system, there is nothing on your system. This is related to the website you visit, they have advertisements.
I really think the adware is still in my computer:(. The forum I have problem with I have been visiting for more than 5 years and had never had any problem. When I click 'rating' in a thread, it will normally bring up a pop-up window for me to select the value of the rating I would want to give. With the adware infect, the normal pop-up window won't show up and the browser is redirected to various rogue ad websites, which I can literally see at the left bottom corner of the browser, with lines saying 'waiting for www.ad***.com'. Adblocker so far gets the normal rating pop-up window back and prevent browser being redirect to various rogue ad websites. However, I think the adware is still in my system?
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top