Windows 10: I have contracted a Virus that shows many Ads

Discus and support I have contracted a Virus that shows many Ads in AntiVirus, Firewalls and System Security to solve the problem; I just got started at about 9:30 am Thanks for all of the new Information. I created another System Restore Point: "11-17-2015 Tuesday"... Discussion in 'AntiVirus, Firewalls and System Security' started by Writer, Nov 14, 2015.

  1. Writer Win User

    I have contracted a Virus that shows many Ads


    I just got started at about 9:30 am
    Thanks for all of the new Information.

    I created another System Restore Point: "11-17-2015 Tuesday"

    Concerning lx07's query about Defender: I just checked, and it says the same as yesterday: "This app is turned off by Group Policy." So, I don't know if it is still incapacitated from the virus. Thanks for the question, @lx07.

    When I booted up this morning, the following message appeared: I don't know it's significance:
    Concerning my not finding "Open Proxy Settings": I looked again, and this option is not there. You show it as being just above "Privacy and Services." On mine, just above "Privacy and Services" is "Always use caret browsing." However, as you write, we may not need to reset Edge since www-searching.com is now gone.

    I'll download ESET now and run the Scan. I don't know if I can use the computer for other matters when the Scan is running, so I'll probably be occupied with the Scan for at least an hour.

    Malwarebytes did an automatic Scan this morning at 9:09 am; here is the Scan Log:
    One file was removed: PUP.Optional.CrossRider

     
    Writer, Nov 16, 2015
    #61
  2. Borg 386 Win User

    You still have to be careful of the genuine article, Adobe has been sneaking in stuff for a while & it seems as if they have escalated the effort to put crap on your OS in order to get some extra $$$$. Not surprising since flash seems to be on the way out & under heavy fire. They have to make up lost revenues somehow.
     
    Borg 386, Nov 16, 2015
    #62
  3. Writer Win User
    Question about ESET:

    When I go to their Website, there are a few options: At the top it says: Run ESET Online Scanner;

    below, on the left, there are two options: Online One-Time Scan or Unlimited 30-Day Scanner

    Which one of these options should use?
     
    Writer, Nov 16, 2015
    #63
  4. simrick Win User

    I have contracted a Virus that shows many Ads

    Yes, and it will normally be disabled because you have the free trial of ESET on there now, right? So it's difficult at this point to know if it is a legitimate disabling or not. We will address that in the future. You can only have one active anti-virus running on a system at a time. Running multiple active/real-time antivirus programs will cause conflict, and reduce their effectiveness. MBAM is designed to run in conjunction with your active anti-virus - they play nice together.

    This is caused from a leftover of one of the malware. It is trying to call a DLL file (Dynamic Link Library file), which was set to run automatically. But, the file it's looking for has been deleted/quarantined, so it's failing, and you see the error. As you can see, we still have some work to do. I wouldn't worry about it at this point, but good you let us know it's happening.

    You can try getting to the same page from Settings, or you could search for Proxy Settings in the search bar at the bottom left. I am not at my W10 rig right now, so I can't give you exact steps. I assume there is no difference between Home and Pro in this setting, but I can't be sure, and I don't know which version you have.

    Sounds good.

    Again, Rootkit detection is turned off - need to turn that on in the setting of MBAM. It must default to that setting because you're on the trial of that too, right? No matter. You'll be running Malwarebytes Anti-Rootkit (MBAE) soon anyway. And yes, we may find leftovers cropping up yet in some of the scans. Sometimes, you have to get rid of some of the layers of infections before the others are found.

    You're doing a great job! Keep up the good work! *Biggrin

    I am in and out of the forum today, so I will try to keep up here. Please follow my "RECAP" a couple posts back, and report in. Thanks.
     
    simrick, Nov 16, 2015
    #64
  5. simrick Win User
    The one-time scanner as in my first photo.
     
    simrick, Nov 16, 2015
    #65
  6. simrick Win User
    So true!
     
    simrick, Nov 16, 2015
    #66
  7. simrick Win User
    Settings>Network and internet>Proxy


    I have contracted a Virus that shows many Ads [​IMG]
     
    simrick, Nov 16, 2015
    #67
  8. Borg 386 Win User

    I have contracted a Virus that shows many Ads

    Great help on this simrick, +1
     
    Borg 386, Nov 16, 2015
    #68
  9. simrick Win User
    Cheers @Borg 386. Unfortunately, I will be unavailable for much of today - in and out - so, if you could assist @Writer with my "RECAP" of what's to be done today if I am not answering, I would greatly appreciate it! *Smile
     
    simrick, Nov 16, 2015
    #69
  10. Borg 386 Win User
    Will do if I get back later soon enough, I have a doc appt today & so does my Wife. Busy day for both of us eh?
     
    Borg 386, Nov 16, 2015
    #70
  11. simrick Win User
    Right! Thanks.
     
    simrick, Nov 16, 2015
    #71
  12. Writer Win User
    I ran the ESET Scan; here is the Scan Log: This was the first Scan; I did a second Scan, the Scan Log of which is posted below. I forgot to click on Advanced Settings for the first Scan.


    I was able to get to the "Proxy Settings." The Automatically Detect Settings" is "On." I accessed the Proxy Settings via "start > search > Proxy."
     
    Writer, Nov 16, 2015
    #72
  13. Writer Win User

    I have contracted a Virus that shows many Ads

    I did a second Scan with ESET because I forgot to click on the Advanced Settings the first time: Below is the Scam Log:
    There is a check-box at the bottom that asks if you want to "Delete Quarantined Files." Should I check that box?

     
    Writer, Nov 16, 2015
    #73
  14. simrick Win User
    Moment please - I have just returned.

    EDIT:
    Based on what I see here, yes - go ahead and delete. Some of it is from ADWCleaner, but that's not a problem. We can always reinstall that if we need it.

     
    simrick, Nov 16, 2015
    #74
  15. simrick Win User
    I'm pasting the RECAP notes here, to keep things simple - this thread is getting a little long...

    So, to recap,
    DONE-Set another restore point,
    DONE-Run ESET from Firefox, save the log file and paste it here, let it delete whatever it finds.
    Run Malwarebytes Anti-Exploit (see post #17)Download and install Malwarebytes Anti-Exploit
    This will help protect your browsers against zero-day attacks. Run SuperAntiSpyware ( see post #49)

    (a lot of instructions with pics - I will not paste here.)

    Run one last scan of Malwarebytes Antimalware - but this time you're going to do a full scan of drive C and not just a threat scan (I'll give you those instructions in the next post).


    Once this is all done:
    Then we'll run SFC /SCANNOW to make sure your operating system files are intact.
    Finally, we will have you install CryptoPrevent to stop these nasties from running in the future.

    We will then set 2 new restore points, calling them CLEAN1 and CLEAN2.
    Then we will install Ccleaner (free version), open the list of existing restore points, and we will delete all old ones, because they contain infection remnants and we don't want to have them available for a restore. We will also have a look at your startups and autoruns, and your installed programs from here.

    Then, I will suggest you put a couple add-ons into Firefox and adjust some settings for safety, and ONLY use Firefox to browse the web, until Edge has extension support (sometime next year).

    Okay?
     
    simrick, Nov 16, 2015
    #75
Thema:

I have contracted a Virus that shows many Ads

Loading...
  1. I have contracted a Virus that shows many Ads - Similar Threads - contracted Virus shows

  2. I contracted a trojan virus named trojan virus zynom And i cant remove it please help me

    in Windows 10 Gaming
    I contracted a trojan virus named trojan virus zynom And i cant remove it please help me: Hello, i got a trojan virus its name is trojan wacatac/H!ml? And i troed all kinds of stuff delleting the files and all that stuff that people are saying and none of it works so i saw that malwarebytes is good and i installed it ran the scanes removed the viruses but somehow...
  3. I contracted a trojan virus named trojan virus zynom And i cant remove it please help me

    in Windows 10 Software and Apps
    I contracted a trojan virus named trojan virus zynom And i cant remove it please help me: Hello, i got a trojan virus its name is trojan wacatac/H!ml? And i troed all kinds of stuff delleting the files and all that stuff that people are saying and none of it works so i saw that malwarebytes is good and i installed it ran the scanes removed the viruses but somehow...
  4. I contracted a trojan virus named trojan virus zynom And i cant remove it please help me

    in AntiVirus, Firewalls and System Security
    I contracted a trojan virus named trojan virus zynom And i cant remove it please help me: Hello, i got a trojan virus its name is trojan wacatac/H!ml? And i troed all kinds of stuff delleting the files and all that stuff that people are saying and none of it works so i saw that malwarebytes is good and i installed it ran the scanes removed the viruses but somehow...
  5. I contracted a trojan virus named trojan:win/Wacatac.H!ml? And i cant remove it

    in Windows 10 Gaming
    I contracted a trojan virus named trojan:win/Wacatac.H!ml? And i cant remove it: I have laptop with windows 10,and i somehow conracted a trojan virus its name is trojan:win32/Wacatac.H!ml? But sometimes it varies it gets a different name but mostly that and i tried all kinds of things like loading a last system save, or tracking down and deleting its...
  6. I contracted a trojan virus named trojan:win/Wacatac.H!ml? And i cant remove it

    in Windows 10 Software and Apps
    I contracted a trojan virus named trojan:win/Wacatac.H!ml? And i cant remove it: I have laptop with windows 10,and i somehow conracted a trojan virus its name is trojan:win32/Wacatac.H!ml? But sometimes it varies it gets a different name but mostly that and i tried all kinds of things like loading a last system save, or tracking down and deleting its...
  7. I recently contracted the "Unconfirmed 7033017.crdownload virus

    in AntiVirus, Firewalls and System Security
    I recently contracted the "Unconfirmed 7033017.crdownload virus: Well it has degenerated my entire file system duplicated .DLL files all over my desktop and some programs seem to work fine while others don't even have a shortcut on the desktop anymore. I've done some minor research online and have some basic and general idea of what is...
  8. Taskbar Contracts

    in Windows 10 Customization
    Taskbar Contracts: On Windows 10 Home my task bar contracts to left side and the icon for additional function icons system tray? does not work. This has been answered and locked but the answer "Right Click the Task Bar - Properties - Taskbar tab - uncheck Group similar taskbar buttons - APPLY /...
  9. I have had an Assure contract for many years. I believe I was to renew on 7/1/20. I did not...

    in Windows 10 Installation and Upgrade
    I have had an Assure contract for many years. I believe I was to renew on 7/1/20. I did not...: I want a tech. to go into my computer. I usually do this every 6 months. I have a contract # from the last time I needed ehlp. https://answers.microsoft.com/en-us/windows/forum/all/i-have-had-an-assure-contract-for-many-years-i/b15d3793-b0cc-4166-8595-711405ce2dc6
  10. Paid for no ads and I have ads.

    in Windows Hello & Lockscreen
    Paid for no ads and I have ads.: I paid $14.99 for a year with no ads. I got a new computer but when I signed in to play the solataire collection the ads were there again. Yes, I am signed in under the same name, email address, and pseudo name. Please contact me or I will just cancel it through my credit...