Malware Chinese Characters

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bluesbreaker, Feb 2, 2016.

  1. Bluesbreaker

    Bluesbreaker Corporal

    Just to be clear, I typed it in BC I had no Internet access as I am still in safe mode, so wanted to make sure it's correct....here goes..!
     
    Kestrel13! likes this.
  2. Bluesbreaker

    Bluesbreaker Corporal

    OK I got a success message.
     

    Attached Files:

  3. Bluesbreaker

    Bluesbreaker Corporal

    Do I reboot? Can go into normal mode using msconfig
     
  4. Bluesbreaker

    Bluesbreaker Corporal

    I got the same result. Error message script and blank screen.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  6. Bluesbreaker

    Bluesbreaker Corporal

    That was with msconfig. In order to run roguekiller
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't think you should access safe mode in that way. It can cause many problems. At this point Blues, you need to go post in the software forum, explain what operating system you are using, and tell them how you accessed safe mode. Ask if this could have caused a problem. Also tell them about the error message you recieve when you try and boot up. Give the exact word for word error message.

    Once they get you back up and running I would like you to return here to continue on with junk removal. Best of luck!
     
  8. Bluesbreaker

    Bluesbreaker Corporal

    OK. I'll go there and ask and come back. It feels almost there BC we got intobthe desktop. Should I stay I I mode for now or go normal?
     
    Kestrel13! likes this.
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It doesn't really matter which mode you stay in for now. ;) Just make your post in s/w and see what they say. I will follow the thread, and we can continue to work here once you are done.
     
  10. Bluesbreaker

    Bluesbreaker Corporal

    OK did it
     
    Kestrel13! likes this.
  11. Bluesbreaker

    Bluesbreaker Corporal

    Hi Kestrel, so I've redone the Regedit File that _nullpetr asked me to run. Did it in safe mode (NOT through msconfig safe either). Still no luck. There is that Baidu there supposedly blocking and that appears to be junk. He recommended I come back here if not successful. Regedit uploaded ok but still script error
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So from what I understand you did not knowingly install Baidu. It appears to be uninstalled but I see signs of it left behind.....

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run FRST like this:

    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  13. Bluesbreaker

    Bluesbreaker Corporal

    Hi Kestrel - so I copy the bold text from the last square ] all the way up to REGEDIT4?

    Also, do I run in safe or normal.

    You are correct, I did not do the Baidu. In fact, I think all those applications appeared when _nullpetr noticed (jan 30/31). Any application that you see on this desktop (like that fancy T with the chinese characters) are the ones that I have also not been able to remove from Add/Remove programs....

    Thanks Kestrel
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to copy ALL that is in the quote box, from REGEDIT4 to the last parenthesis.
    Try running in normal mode. :)
     
  15. Bluesbreaker

    Bluesbreaker Corporal

    ok. success message from fixME.reg addition.

    and attached are the FRST files. I think 2 are duplicates and I included Addition from when I first ran the FRST tool...thanks again
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.
    Also at this point, I want to double check the status of thingsby having you run another scan with FRST like in my last message and attach the new FRST.txt log.


    Explain how things are running.
     

    Attached Files:

  17. Bluesbreaker

    Bluesbreaker Corporal

    OK. Now do I need to set a restore point just in case?
     
  18. Bluesbreaker

    Bluesbreaker Corporal

    ok here are the 2 logs, Fixlogs and MGlogs. I have not run the subsequent FRST test.

    also, when I logged back in, I got the same vbs error. the chinese text files, however, appear to be gone from my desktop....
     
    Kestrel13! likes this.
  19. Bluesbreaker

    Bluesbreaker Corporal

    whoops sorry
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hang in there Blues, I am conferring with colleagues.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these too, Blues... (remnants)

    C:\Program Files (x86)\Common Files\Baidu
    C:\Program Files (x86)\Common Files\Tencent
    C:\ProgramData\Tencent
    C:\Program Files (x86)\Tencent
     
  22. Bluesbreaker

    Bluesbreaker Corporal

    OK. Like straight delete or go into registry too and find them? Thank you small Falcon 13!
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just straight delete... use Windows Explorer to find them and simply right click and delete.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Next I'd like you to navigate to this in the same way as you found those folders I asked you to delete... BUT we won't be deleting this one....

    Navigate to this:
    C:\FRST\Quarantine\C\WINDOWS\run.vbs.xBAD

    • I want you to right click and select rename on that file. (run.vbs.xBAD)
    • Rename it to remove the .xBAD extension if there is one.... so it is just called run.vbs
    • Once done, right click on the file, choose COPY then PASTE it to your desktop. Once done...right click it and send to compressed (zip) folder
    • Upload that zipped file here.
     
    Last edited: Feb 13, 2016
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Edited post above to COPY not CUT
     
  26. Bluesbreaker

    Bluesbreaker Corporal

    so check this out. I did a search in C: for Baidu and got all these. actually for whatever reason I can't see .doc files on the desktop anymore. but there are non-quarantined files like BaiduHips.exe, Baiduehipsupdate.exe, etc...like more than those 2 Baidu files above...but I'll take the ones you referred to out and then come back...
     
  27. Bluesbreaker

    Bluesbreaker Corporal

    ok did all those steps and here is the file:
     

    Attached Files:

    • run.zip
      File size:
      608 bytes
      Views:
      4
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK I have examined the file and it belongs to a junk program called CleanBrowser. Which I have already cleaned from your machine... the removal of this junk unsteadied your system, it can do that sometimes. I will now search for any more possible remnants, which if any do come up, I'm hoping that removing the rest will shape you up again... but let's not get our hopes up with that. All will not be lost anyway, I'm conferring with colleagues about this in the background. ;)

    SystemLook

    Please download SystemLook from one of the links below appropriate for your operating system and save it to your Desktop.
    Download 32 Bit
    Download 64 Bit

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      CleanBrowser
      Clean Browser
      :regfind
      CleanBrowser
      Clean Browser
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  29. Bluesbreaker

    Bluesbreaker Corporal

    ok will do...thanks... is it possible that through all this, for whatever reason, sound is disabled on my computer now? no music files, movies, etc...
     
  30. Bluesbreaker

    Bluesbreaker Corporal

    and here be the system look log...
     

    Attached Files:

  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't know about your sound...

    Delete this if you see it.
    C:\Program Files (x86)\CleanBrowser

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
    Last edited: Feb 14, 2016
  32. Bluesbreaker

    Bluesbreaker Corporal

    OK I will try and run this later. Btw could any of the Baidu or Tencent or what we've been working on have such an impact on the sound? Thanks again and Happy Valentines Day if you're so inclined...;)
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not sure, Blues, I have to try and focus on one thing at a time though, your thread has had me quite baffled.

    I'd like you to download Autoruns, save it to your desktop.


    Rn Autoruns ( you will have to extract the contents from the ZIP file into its a new folder you create for it ( like AutoRuns on your Desktop ) and keep the Everything tab selected in AutoRuns. Then click on the File menu selection and select Save. Save this log file in default format to your Desktop. The default format and filename should be AutoRuns.arn

    Now put the AutoRuns.arn file into a ZIP file and attach this ZIP to your next message. ( you cannot attach the AutoRuns.arn file. It must be ZIP'ed ).

    Let me know how you get on with the reg patch.
    Happy Valentine's to you too.
     
    Last edited: Feb 14, 2016
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Editing my previous post to include autoruns instructions.
     
  35. Bluesbreaker

    Bluesbreaker Corporal

    ok success message received with FixME.reg....and here is the autoruns zipped file....


    [edit chaslang] incorrect attachment deleted!
     
    Last edited by a moderator: Feb 15, 2016
  36. Bluesbreaker

    Bluesbreaker Corporal

    this is becoming the rubik's cube of junkware?
     
  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Blues you need to follow my instructions properly. All you did here was upload the program itself in a zipped file, you did none of what I said to do.
     
  38. Bluesbreaker

    Bluesbreaker Corporal

    Sorry this on threw me off. I will come back.
     
    Kestrel13! likes this.
  39. Bluesbreaker

    Bluesbreaker Corporal

    ok. so heres the autoruns zipped file. what I did was to click on autoruns, selected the everything tab, hit REFRESH and then it did the scan. saved it as autoruns.arn and now zipped.
    is this right or is there a step I missed
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you download and use the version of AutoRuns that Kestrel13! gave you a link to or did you use some copy you already had? You need to use the version given so that correct logs are generated. Your file is showing up as corrupted which typical happens when different version of the program are run.
     
    Kestrel13! likes this.
  41. Bluesbreaker

    Bluesbreaker Corporal

    hey chaslang long time no chat. I did actually download the file from the link Kestrel13! provided. Ive run the program again and attached the zip file...thanks for helping out.
     

    Attached Files:

  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The file is still corrupt.
     
  43. Bluesbreaker

    Bluesbreaker Corporal

    I followed all the steps, including the link over to the sites. when I create the zip file, I am right clicking and saying create a compressed file and zip it up. I'm not sure if I'm doing something wrong on my end?
     
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We'll have to wait and see what Chaslang says, Blues.
     
  45. Bluesbreaker

    Bluesbreaker Corporal

    hey...don't be demoralized, we'll get there...
     
    Kestrel13! likes this.
  46. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm hanging in there don't you worry. Just need some guidance from the boss. :)
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think that perhaps you are not waiting for AutoRuns to complete the analysis of your PC before you are saving the log file. The file you have inside of the ZIP file is way too small to be a complete log. This is probably why it is saying the file is corrupt.
     
  48. Bluesbreaker

    Bluesbreaker Corporal

    OK. Let me make sure I am doing this correctly. When I launch auto runs, I have a screen with a bunch of tabs. I made sure the Everything tab was clicked. Hit refresh and it said scanning down at the bottom. Saved file per instructions above. I did not click on anything else. Is this how you run Autoruns?
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes. You just have to wait for it to finish scanning. The message at the bottom should turn to Ready. And then when you click File, Save it should default to naming to file with an AutoRuns Data (*.arn ) file extension. Your last log had a .arn extension but the file was only about 726 K or so which maybe 10% of what I would expect.
     
  50. Bluesbreaker

    Bluesbreaker Corporal

    THanks chaslang, I will give it another shot tonight. But I'm quite sure I waited before I saved. Nevertheless, I will have at it again...thanks for your help, thanks Kestrel13
     
    Kestrel13! likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds