Windows 10: I have contracted a Virus that shows many Ads

Discus and support I have contracted a Virus that shows many Ads in AntiVirus, Firewalls and System Security to solve the problem; One question - when you rebooted last time, did you still receive the bad DLL call error? Yes, I still received the exact same error. Okay. I hope... Discussion in 'AntiVirus, Firewalls and System Security' started by Writer, Nov 14, 2015.

  1. simrick Win User

    I have contracted a Virus that shows many Ads


    Yes, I still received the exact same error. Okay. I hope to resolve that when we get to the Ccleaner step. Just making sure it's still on the list to fix.

    Yes, this is a full scan, not just a threat scan, and it will take some time. But, it is necessary, so we must be patient.

    Okay. Please let it finish. I will need the log file when it's done.

    If you plugged in the flash drive, and it was assigned a letter, say E:\, and you checked the box to scan E:\ as well, then yes, MBAM will scan it.

    Internet Explorer (IE) does not have the add-on & settings capabilities like Firefox does, which I will be recommending for you. In Firefox, we can add several extensions, and also modify certain settings to *not* allow flash and java to run without your input. I'll also recommend a password manager, all of this for your surfing safety. In this case, I would strongly suggest you stick with Firefox, and only use IE if you happen to come across a particular website which does not function in Firefox (FF) (which almost NEVER happens anymore).

    Yes, I was afraid of this. That's why I kept pushing for log files. It's important to not only clean the system, but to identify exactly what was on it, so you know just how much and what kind of damage was done. There are some infections which are so bad, your only course of action is a complete wipe of the hard disk, and a fresh install. In some cases, you will even find that a hidden partition has been created by the malware on the hard drive. Even, there are some infections that survive a complete wipe and fresh install.

    Yes, well, good that you were using a different computer; bad that the infections got as severe as they did. The problem is, anything existing on the computer could have been compromised: i.e. any passwords saved in browsers are assumed stolen now. Any tax info/social security numbers/other personal ID information that may be stored in documents on the computer are assumed compromised. The Zbot/Zeus infection affords the attacker complete control of the infected computer - you have to assume they had access to everything, and proceed accordingly.

    I'm glad we are able to help! I only wish we could have gotten to it sooner....

    Thank you for your patience, and following, what can be at times, some very confusing instructions.
     
    simrick, Nov 17, 2015
    #91
  2. Writer Win User

    I ran the Malwarebytes AM Scan (complete); it took a few minutes over 2 hours: below is the Scan Log of items detected:
    There were only 16 items.
    I notice that "shopperz" is on the list: this is one file that gave me a lot of trouble: it constantly plagued me.

    I just clicked on Remove Detected Files. It says that they were all quarantined.

     
    Writer, Nov 17, 2015
    #92
  3. Writer Win User
    MWAM wanted a "Restart," so I just restarted. The same DLL Error message appeared, by the way.
     
    Writer, Nov 17, 2015
    #93
  4. simrick Win User

    I have contracted a Virus that shows many Ads

    Okay, this is a good scan. All of the items were from the quarantine using ADWCleaner, except for one:

    --------------------------------------
    updating the RECAP list:

    DONE-Set another restore point,
    DONE-Run ESET from Firefox, save the log file and paste it here, let it delete whatever it finds.
    DONE-Run Malwarebytes Anti-Exploit (see post #17)Download and install Malwarebytes Anti-Exploit
    This will help protect your browsers against zero-day attacks. DONE-Run SuperAntiSpyware ( see post #49)

    DONE-Please run one last scan of Malwarebytes Antimalware - but this time you're going to do a full scan of drive C and not just a threat scan (see my instructions in previous post #75)

    sfc /scannow
    CryptoPrevent
    Set 2 restore points: CLEAN #1 and CLEAN #2
    Ccleaner: open the list of existing restore points, and we will delete all old ones, because they contain infection remnants and we don't want to have them available for a restore. We will also have a look at your startups and autoruns, and your installed programs from here.

    (I may have a couple of other tools I will add to the list here, if we find they are necessary, so TBD.)

    Then, I will suggest you put a couple add-ons into Firefox and adjust some settings for safety, and ONLY use Firefox to browse the web, until Edge has extension support (sometime next year).

    --------------------------------------


    Please now let's run SFC /SCANNOW to make sure your operating system files are intact.
    When you run the tool, we are looking for the answer "No integrity violations found".
    If you get something else other than that, please reboot, and run the tool again. You should run this tool at leaast 3 times, to see if we can get the answer we are looking for.


    EDIT: USE OPTION #3

    Here are the instructions:
    SFC Command - Run in Windows 10 - Windows 10 Forums
     
    simrick, Nov 17, 2015
    #94
  5. Writer Win User
    I just completed the sfc/scannow process: The message read:

    I used "Option 3."

    "Windows Resource Protection did not find any Integrity Violations."

    I accessed the Command Prompt via Start > Command Prompt (Admin)
     
    Writer, Nov 17, 2015
    #95
  6. simrick Win User
    Excellent news.

    Next:

    Let's download and run CryptoPrevent

    We will use standard protection. The computer will need to be rebooted after you've applied the protection.

    Please give me a few moments to post some screenshots for you.
     
    simrick, Nov 17, 2015
    #96
  7. simrick Win User
    Running CryptoPrevent


    I have contracted a Virus that shows many Ads [​IMG]


    Select default protection and click apply.


    I have contracted a Virus that shows many Ads [​IMG]


    Check for updates. Please wait a minute or even minute and a half for it to contact the server for updates.


    I have contracted a Virus that shows many Ads [​IMG]


    If an update is available, take it.
    Please note this is the free version. It will not auto-update, so you could check that once and a while.

    This is NOT a scanner. This makes group policy changes to your computer to prevent malicious code from running from within certain locations in your computer (like appdata), from which malware tend to typically execute their payload/code. It is not a "running" program. It simply makes the group policy changes and then does nothing else until you open it up to check for updates or change the settings.


    I have contracted a Virus that shows many Ads [​IMG]



    I have contracted a Virus that shows many Ads [​IMG]




    I have contracted a Virus that shows many Ads [​IMG]



    I have contracted a Virus that shows many Ads [​IMG]



    I have contracted a Virus that shows many Ads [​IMG]


    That's it.
     
    simrick, Nov 17, 2015
    #97
  8. Writer Win User

    I have contracted a Virus that shows many Ads

    The Link that you give in Post 95 brings up a Website that is very busy. It is difficult to determine where to click in order to download the software. Could you tell me what to click on there?

    One possibility says: Download Locations. Below that it reads: Download at Author's site

    Above this it Reads: CryptoPrevent 7.4.20
     
    Writer, Nov 17, 2015
    #98
  9. simrick Win User
    click here
    [link removed]

    when you've got it let me know, so I can delete the link, in case it changes in the future, and then we have a broken link in our thread.
     
    simrick, Nov 17, 2015
    #99
  10. Writer Win User
    OK, I installed CryptoPrevent. After the "Restart," a message came up that read: Prevention Successfully applied.

    A window came up during the process about "WhiteListing" certain segments. It said that if I wasn't sure that I should click on "No" Do not WhiteList. So I clicked on No.
     
    Writer, Nov 17, 2015
  11. simrick Win User
    That's fine. Please stand by for my next post.
     
    simrick, Apr 5, 2018
Thema:

I have contracted a Virus that shows many Ads

Loading...
  1. I have contracted a Virus that shows many Ads - Similar Threads - contracted Virus shows

  2. I contracted a trojan virus named trojan virus zynom And i cant remove it please help me

    in Windows 10 Gaming
    I contracted a trojan virus named trojan virus zynom And i cant remove it please help me: Hello, i got a trojan virus its name is trojan wacatac/H!ml? And i troed all kinds of stuff delleting the files and all that stuff that people are saying and none of it works so i saw that malwarebytes is good and i installed it ran the scanes removed the viruses but somehow...
  3. I contracted a trojan virus named trojan virus zynom And i cant remove it please help me

    in Windows 10 Software and Apps
    I contracted a trojan virus named trojan virus zynom And i cant remove it please help me: Hello, i got a trojan virus its name is trojan wacatac/H!ml? And i troed all kinds of stuff delleting the files and all that stuff that people are saying and none of it works so i saw that malwarebytes is good and i installed it ran the scanes removed the viruses but somehow...
  4. I contracted a trojan virus named trojan virus zynom And i cant remove it please help me

    in AntiVirus, Firewalls and System Security
    I contracted a trojan virus named trojan virus zynom And i cant remove it please help me: Hello, i got a trojan virus its name is trojan wacatac/H!ml? And i troed all kinds of stuff delleting the files and all that stuff that people are saying and none of it works so i saw that malwarebytes is good and i installed it ran the scanes removed the viruses but somehow...
  5. I contracted a trojan virus named trojan:win/Wacatac.H!ml? And i cant remove it

    in Windows 10 Gaming
    I contracted a trojan virus named trojan:win/Wacatac.H!ml? And i cant remove it: I have laptop with windows 10,and i somehow conracted a trojan virus its name is trojan:win32/Wacatac.H!ml? But sometimes it varies it gets a different name but mostly that and i tried all kinds of things like loading a last system save, or tracking down and deleting its...
  6. I contracted a trojan virus named trojan:win/Wacatac.H!ml? And i cant remove it

    in Windows 10 Software and Apps
    I contracted a trojan virus named trojan:win/Wacatac.H!ml? And i cant remove it: I have laptop with windows 10,and i somehow conracted a trojan virus its name is trojan:win32/Wacatac.H!ml? But sometimes it varies it gets a different name but mostly that and i tried all kinds of things like loading a last system save, or tracking down and deleting its...
  7. I recently contracted the "Unconfirmed 7033017.crdownload virus

    in AntiVirus, Firewalls and System Security
    I recently contracted the "Unconfirmed 7033017.crdownload virus: Well it has degenerated my entire file system duplicated .DLL files all over my desktop and some programs seem to work fine while others don't even have a shortcut on the desktop anymore. I've done some minor research online and have some basic and general idea of what is...
  8. Taskbar Contracts

    in Windows 10 Customization
    Taskbar Contracts: On Windows 10 Home my task bar contracts to left side and the icon for additional function icons system tray? does not work. This has been answered and locked but the answer "Right Click the Task Bar - Properties - Taskbar tab - uncheck Group similar taskbar buttons - APPLY /...
  9. I have had an Assure contract for many years. I believe I was to renew on 7/1/20. I did not...

    in Windows 10 Installation and Upgrade
    I have had an Assure contract for many years. I believe I was to renew on 7/1/20. I did not...: I want a tech. to go into my computer. I usually do this every 6 months. I have a contract # from the last time I needed ehlp. https://answers.microsoft.com/en-us/windows/forum/all/i-have-had-an-assure-contract-for-many-years-i/b15d3793-b0cc-4166-8595-711405ce2dc6
  10. Paid for no ads and I have ads.

    in Windows Hello & Lockscreen
    Paid for no ads and I have ads.: I paid $14.99 for a year with no ads. I got a new computer but when I signed in to play the solataire collection the ads were there again. Yes, I am signed in under the same name, email address, and pseudo name. Please contact me or I will just cancel it through my credit...