Weird adverts, cant get rid of

slippyjim

Honorable
Feb 28, 2012
25
0
10,580
I got a call from my friend who has 3 PC’s and was having some problem with some naughty popups on all the computers so I thought this would be fairly simple to fix, but………

So when I get there they have AVG on all the PC’s and one of them has recently updated to 2015 internet security and the trial has run out but over where it is trying to get you to upgrade there is another advert of some cartoon porn.

I opened up firefox and was getting some adverts on that as well a yellow bar with black writing either at the top or the bottom of the screen and also this cartoon porn thing in the bottom right corner. They don’t appear on all websites, they seem to be worse on filehippo.com for some reason. These adverts appeared in Firefox on 1 PC and Chrome on the other 2, but no ads appeared with IE!!

So I ran
ccleaner
adwcleaner – found ask toolbar on all PCs
malware bytes – found nothing on 2 and some Trojans in recycle bin in the other
combofix – found a couple of folders

But the advert over AVG and in Firefox/Chrome were still kind of there. Whenever they tried to open Malwarebytes blocked them and all I saw was a big black cross where the advert used to be.

Then I noticed that all the PC’s had a strange DNS (8.8.8.8) even though they were set to automatically get the DNS from the router (and none of the anti malware programs I had run had found any DNS changers) so I thought I've found the problem. I reset and re-setup the router and all PC’s then showed they were getting the DNS from the router but still the adverts appeared over AVG and in Firefox but seem to have gone from Chrome.

Does anyone have any ideas?
What other programs can I try running?

TIA
 

alsar88

Estimable
Nov 10, 2014
22
0
4,570
download kaperskey free trial and uninstall all questionable programs. post a screen shot of the control panel programs if you want some help. also delete all fire extensions and restore it to normal by deleting all weird/annoying things, and set it to the right start up page and search engine.
 

slippyjim

Honorable
Feb 28, 2012
25
0
10,580
there are no dodgy programs installed on any PC now

I cant see anything untoward in Task Manager

Thats kind of good news about the DNS then, just a bit weird as Ive never seen the ISP use that DNS before

Also I've just remembered some more details
I connected my laptop via wifi hotspot to my mobile, I didnt see any adverts on filehippo with firefox, then I connected to their wifi and suddenly filehippo had the same ads all over it and this think trying to get me to install a fake version of adobe flash and the ads remained after reconnecting to my wifi hotspot
 

Emanuel Elmo

Estimable
Mar 21, 2014
14
0
4,560


That is awesome to hear. Sad that they were using google's public DNS server to do their annoying deeds.