Author Topic: Ads out of nowhere help please  (Read 4010 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Ads out of nowhere help please
« on: August 28, 2015, 08:50:10 PM »
Hello I asked for help in reddit but no one knew what happened so I'll copy/paste what I wrote

"I've literally searched everywhere and I cant find the solution to this...
I've been with this problem recently and its becoming extremely annoying. I'm getting plagued by (at first) russian ads and (now) spanish ads in almost every website that doesnt use "https". I havent downloaded anything in months and this started to happen of all sudden. They even appear on My steam: https://i.imgur.com/Db990L1.png and when i close that ad, it always comes with a pop up with even more ads... https://i.imgur.com/zF3s2Im.png
I've been years (bout 10 years) without having any kind of problems with "viruses" but this is the first time I come across with this... I've checked with everything I have... Anti-adware softwares and anti-viruses and none have found the problem....
It's like the ads are saying "look how i dont give a shit about what you do" https://i.imgur.com/MHnje49.png Ads even on my AVG interface... (the not protected means that I dont have the pro version, just free)
I really really need help with this... I've tried everything that is within my knowledge..
Also I stopped ads from popping up in chrome when I installed the "HTTPS Everywhere" extension. But this is just a small bandaid to a big ass injury... Im desperate... "


Fun fact: This happened when my bro purchased AVG and told me to use it. (I said why not) I have always used Avast and ever since I changed to AVG this happens LOL. Not gonna use AVG EVER AGAIN.  Sadly I switched back to avast but i believe the adware is now well hidden that Avast detected nothing :/

Already checked my hosts files in case it was hijacked and everything was ok. Already used Adwcleaner and detected nothing.... I really dont know what else I can do :/

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ads out of nowhere help please
« Reply #1 on: August 28, 2015, 08:55:21 PM »
Lets have a look see :)

Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select  additions at the bottom
  • Press Scan button.

  • It will produce a log called FRST.txt in the same directory the tool is run from. 
  • Please attach both logs generated.

REDACTED

  • Guest
Re: Ads out of nowhere help please
« Reply #2 on: August 28, 2015, 09:02:53 PM »
Here are the txt files

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ads out of nowhere help please
« Reply #3 on: August 28, 2015, 09:34:47 PM »
I will need to reset your internet settings so wtfast may need to be re-installed

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKU\S-1-5-21-1819221242-1544159838-1318617619-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Ads out of nowhere help please
« Reply #4 on: August 28, 2015, 10:34:12 PM »
here's the fixlog

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ads out of nowhere help please
« Reply #5 on: August 28, 2015, 10:35:51 PM »
Are the ads still present ?

REDACTED

  • Guest
Re: Ads out of nowhere help please
« Reply #6 on: August 28, 2015, 10:54:55 PM »
yeah they keep showing up :/

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ads out of nowhere help please
« Reply #7 on: August 28, 2015, 11:19:10 PM »
OK next lets look deeper

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

REDACTED

  • Guest
Re: Ads out of nowhere help please
« Reply #8 on: August 29, 2015, 03:19:02 AM »
Here's the log and ads keep showing up ;-;

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ads out of nowhere help please
« Reply #9 on: August 29, 2015, 11:33:08 AM »
Could you temporarily uninstall WTFast

REDACTED

  • Guest
Re: Ads out of nowhere help please
« Reply #10 on: August 29, 2015, 07:05:13 PM »
They keep popping up :/ Would this might be a DNS hijacking?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ads out of nowhere help please
« Reply #11 on: August 29, 2015, 07:26:17 PM »
I reset your DNS etc in the first fix... Does this only occur on steam ?

REDACTED

  • Guest
Re: Ads out of nowhere help please
« Reply #12 on: August 29, 2015, 07:35:15 PM »
This occured in Chrome too but I stopped them using the HTTPS Everywhere extension. But they keep popping up in other browsers, steam and even on my Anti-Virus Interface.... I dont mind formatting if its the only choice... (I'm just lazy to re-download all my game library in steam LOL, internet is not fast here in Mexico) but I'd love to find a solution to this just in case I come across with this in a future.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ads out of nowhere help please
« Reply #13 on: August 29, 2015, 08:06:37 PM »
Does any one else use your router ?  If so do they experience the same symptoms ?



Download aswMBR.exe ( 4.5mb ) to your desktop.
Double click the aswMBR.exe to run it.
You may be offered the option of using virtualisation, accept that
When it offers to download the virus database allow that as well
Click the "Scan" button to start scan




On completion of the scan click save log, save it to your desktop and post in your next reply

REDACTED

  • Guest
Re: Ads out of nowhere help please
« Reply #14 on: August 29, 2015, 10:03:04 PM »
Ads still showing up.... and yea I live with an Aunt here and she uses the internet as well but only uses it to check her email and online shopping in Amazon