Solved Linkbucks, new tab ads, and "update media" popups

Hi - sorry... I was working very late last night. I never use IE, but I just tried it to see - it happens in both Chrome and IE.
 
redtarget.gif

Reset Internet Explorer.
Go here: http://support.microsoft.com/kb/923737 and run "FixIt" procedure.
You can use ANY browser to download "FixIt" file.
Make sure you follow ALL steps listed there.

redtarget.gif

Reset Chrome...
Click on "Customize and control Google Chrome":
p22003758.gif

Click "Settings" then "Show advanced settings" at the bottom of the screen.
Click "Reset browser settings" button.
Restart Chrome.
 
I did the browser resets. I'm not seeing linkbucks on my pc, but it's still on my phone. The "update now" popups and new tabs, however are staying strong.
 
I don't deal with mobile devices.

Here...

Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download
51a5ce45263de-delfix.png
DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

11. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

12. Please, let me know, how your computer is doing.
 
Okay - yeah - forget I mentioned the Galaxy.
That's cool I don't see Linkbucks anymore, but still, so many popups and new tabs begging me to "download" or "update" media, video, etc., and my sound still does not work.
I'm beginning to wonder if these popups to update are real. Do I need to update something to get my sound to work and stop these new tabs? Will this final step remedy that, or do you have any other suggestions?

“The page at plynow.chasewing.eu says: UPDATES RECOMMENDED! It is recommended that you install the software to ensure your browser is the latest version. Please update to continue.”

“The page at www.appimat.com says: There is a new Codec Pack version. Install new version now for better performance.”

“Recommended You are currently browsing the web with Google Chrome and it is recommended that you update your video player to the fastest version available. Plesase update to continue.”

“You are currently browsing the web with Google Chrome and your Video Player might be outdated..”

“Codec Performer Update is Recommended Please Install Codec Performer Update…”

“Update Windows 7 Drivers… “

“The Best 100% Free FLV Player- Top Download 2014… Free Download”

“Malwarebytes Anti-Malware Potentially malicious website blocked protecting you from hackers and cyber criminals.”
 
I never use IE, but I just tried it to see - it happens in both Chrome and IE.... You actually asked me this before, then had me reset both browsers, which I did, but the popups continue, and honestly seem to be getting more aggressive. :(
 
# AdwCleaner v3.208 - Report created 12/05/2014 at 09:22:57
# Updated 11/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Renee - LIBRARY-PC
# Running from : C:\Users\Renee\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASMANCS

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17041


-\\ Google Chrome v34.0.1847.131

[ File : C:\Users\Administrator King\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Users\Grumblub\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Users\Renee\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [2923 octets] - [30/04/2014 07:52:16]
AdwCleaner[R1].txt - [1312 octets] - [05/05/2014 13:49:10]
AdwCleaner[R2].txt - [1473 octets] - [12/05/2014 09:17:21]
AdwCleaner[S0].txt - [2955 octets] - [30/04/2014 07:57:44]
AdwCleaner[S1].txt - [1381 octets] - [05/05/2014 13:56:34]
AdwCleaner[S2].txt - [1402 octets] - [12/05/2014 09:22:57]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1462 octets] ##########
 
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 12-May-14
Scan Time: 8:59:35 AM
Logfile: MBAM log 12may2014.txt
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.05.12.03
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Renee

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 362093
Time Elapsed: 9 min, 20 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Renee on 12-May-14 at 9:34:57.77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-4111083629-4137538892-1715785686-1000\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12-May-14 at 9:44:14.04
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Windows was asking me to update before I ran MBAM, AdwCleaner and JRT -should I do that? However, now the only thing in my systray is MBAM. Avast used to be there, but even though I have selected to show the icon and notifications, it does not show up.
 
Ok. I'll have to do it when I get home. Graduation night. :)
My Chrome profile seems much improved, but when I log on another profile.. still mafd popups.
 
Everything is looking much better so far... :)
I ran Delfix - log is below. When I try to update Windows, though, installation failed. I tried it again, only selecting a few smaller-sized updates, and the "preparing to install" step seemed to be hanging.

# DelFix v10.7 - Logfile created 16/05/2014 at 07:52:51
# Updated 27/04/2014 by Xplode
# Username : Renee - LIBRARY-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\_OTL
Deleted : C:\AdwCleaner
Deleted : C:\Users\Renee\Desktop\mbar
Deleted : C:\Users\Renee\Desktop\RK_Quarantine
Deleted : C:\ComboFix.txt
Deleted : C:\Users\Renee\Desktop\adwcleaner.exe
Deleted : C:\Users\Renee\Desktop\ComboFix.exe
Deleted : C:\Users\Renee\Desktop\dds.txt
Deleted : C:\Users\Renee\Desktop\esetsmartinstaller_enu.exe
Deleted : C:\Users\Renee\Desktop\Extras.Txt
Deleted : C:\Users\Renee\Desktop\FSS.exe
Deleted : C:\Users\Renee\Desktop\FSS.txt
Deleted : C:\Users\Renee\Desktop\JRT.exe
Deleted : C:\Users\Renee\Desktop\JRT.txt
Deleted : C:\Users\Renee\Desktop\OTL.Txt
Deleted : C:\Users\Renee\Desktop\OTL.exe
Deleted : C:\Users\Renee\Desktop\RKreport[0]_D_05042014_141356.txt
Deleted : C:\Users\Renee\Desktop\RKreport[0]_S_05042014_141300.txt
Deleted : C:\Users\Renee\Desktop\RogueKiller.exe
Deleted : C:\Users\Renee\Desktop\SecurityCheck.exe
Deleted : C:\Users\Renee\Desktop\Startup Programs and Services List.docx
Deleted : C:\Users\Renee\Desktop\TFC.exe
Deleted : C:\Windows\grep.exe
Deleted : C:\Windows\PEV.exe
Deleted : C:\Windows\NIRCMD.exe
Deleted : C:\Windows\MBR.exe
Deleted : C:\Windows\SED.exe
Deleted : C:\Windows\SWREG.exe
Deleted : C:\Windows\SWSC.exe
Deleted : C:\Windows\SWXCACLS.exe
Deleted : C:\Windows\Zip.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #130 [Restore for TechSpot | 05/04/2014 19:18:09]
Deleted : RP #131 [Windows Backup | 05/05/2014 00:00:04]
Deleted : RP #132 [Installed Microsoft Fix it 50195 | 05/08/2014 02:50:54]
Deleted : RP #133 [Windows Backup | 05/12/2014 00:00:05]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
 
Sorry – just realized I wasn’t supposed to send you that last log.

On step 3, How do I know “If any trojans, rootkits or bootkits were listed among your infection(s)?”

Windows updates are done. Browser extensions updated. Installed WOT, PSI (in the process of updating 7 programs), downloaded JRT, ADW, and TFC. Installed Quicktime 7 per BrowserCheck.

Everything seems great – I so appreciate your help!
I still have no sound, though. Should I post that on another thread?
 
Your passwords are safe.

Please create new topic regarding sound issue in Windows forum.

Good luck and stay safe :)
 
Back