Caught A Bug!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dseils, May 31, 2016.

  1. dseils

    dseils Private E-2

    I own a Surface Pro 3 on Win 10

    I caught a piece of Malware. The Symptom is that on one of the users, when I log in I am greeted by a false BSOD that masks everything else. I have run the four initial processes and MG Tools. I have the logs
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome! :)

    Re run Hitman Pro, and have it remove all that it finds.



    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X64) HKEY_LOCAL_MACHINE\Software\SearchModule -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\csdimedia -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\SearchModule -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\{12A61307-94CD-4F8E-94BC-918E511FAA81} -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Zofhe ("C:\Users\Donald\AppData\Roaming\LogpKyudpik\Sablep.exe" -cms) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Zofhe ("C:\Users\Donald\AppData\Roaming\LogpKyudpik\Sablep.exe" -cms) -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...same for this entry on the files tab please...
    • [PUP][Folder] C:\ProgramData\VideoDownloaderUltimateWinApp -> Found

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    MGTools did not run to completion, please run it again this time ensuring you ran it as admin, that protection software is disabled and that UAC is turned off.

    Upload the log once done.


    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  3. dseils

    dseils Private E-2

    Will do...does it make any difference which user account I run these in? One user account let's me see everything on the desktop and the other has the desktop blocked.

    I will delete the video Downloader, but I know it to be a good app
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do it from the account you uploaded these logs from.
     
  5. dseils

    dseils Private E-2

    Here are the additioal logs. When I ran Rogue Killer, some of the entries were not found...
    • [PUP] (X64) HKEY_LOCAL_MACHINE\Software\SearchModule -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\{12A61307-94CD-4F8E-94BC-918E511FAA81} -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} -> Found
    • "C:\Users\Donald\AppData\Roaming\LogpKyudpik\Sablep.exe" -cms) -> Found
     

    Attached Files:

  6. dseils

    dseils Private E-2

    There is no change on the system...fake bsod still greets me at login on the other account. Should I do the same process on that one, too?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's finish this account now we have started. Once we are finished here we will begin the same tests on the other.

    Uninstall the below:
    Registry Cleaner

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.



      • You should now have both fixlist.txt and FRST64.exe on your Desktop.
      • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
      • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
      • Click the Fix button just once and wait.
      • Your computer should reboot after the fix runs.
      • Reconnect your internet connection after reboot so you can come back here to continue.
      • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:



      • Fixlog.txt
      • C:\MGlogs.zip

    Also at this point, I want to double check the status of things by having you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.
     

    Attached Files:

  8. dseils

    dseils Private E-2

    Here are the requested logs. I made a note in the 30-day files section that highlights file changes during the period where the pop-ups and fake bsod appeared. the point where new anti-malware software installation began was the point where I reached out to majorgeeks. If the FRST.txt file is the basis for a fixlist.txt file, they should probably be removed. I appreciate your efforts.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Follow the instruction as in my post #7 for running this, but use THIS fixlist... not the last one. Skip the running of MGTools again...
     

    Attached Files:

  10. dseils

    dseils Private E-2

    Okay...here is the latest set of logs...
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And do you also have the FRST log please?
     
  12. dseils

    dseils Private E-2

    here they are...sorry...
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, I am satisfied we have done enough on this account for now.
    Let's move onto the next account where all the trouble is.
    Run all the tools in the Read and Run me First and also run a scan with FRST. Upload logs once done. :)
     
  14. dseils

    dseils Private E-2

    okay...here are my logs
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I haven't checked the logs... I have to dash out for about 2 hours. Can you tell me how things are running currently?
     
  16. dseils

    dseils Private E-2

    Pretty good, actually. There were only a couple of attention items, and I eliminated one rogue directory and app in the system with a cleaning. Initially, I was getting attempts to call out that MB antiexploit caught. Using that info, I cleaned them. I am now running Comodo Complete.
     
    Kestrel13! likes this.
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, sorry for the delay I was out longer than expected. Going to eat my dinner and get straight onto your next set of logs, give them a good once over.. and respond back to you.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have uploaded a fixlist. Repeat the same steps as in my post #7. You do not have to run MGTools again though.
     

    Attached Files:

  19. dseils

    dseils Private E-2

    I think this is probably a closeout message....the last fixliswt seems to have gotten the last of it. Comodo is in place and has not reported further infections. here is the log, along with my profound thanks!
     

    Attached Files:

    DavidGP and Kestrel13! like this.
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So pleased to hear things are running well. ;) Would you like me to post final steps? Basically, the infection had tainted your dnsapi.dll file, replacing it with a clean copy fixed it up.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds