Possible Malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by helpmeplease2, Aug 21, 2016.

  1. helpmeplease2

    helpmeplease2 Private E-2

    Hi, After you helped me fix my mom's main laptop yesterday, when I dropped it off she gave me the laptop she was using saying it has a problem too. The only thing I experienced is that the internet is a little slower than normal and sometimes freezes, typing does not keep up so it misses some letters (not a keyboard issue) and today it installed a program that I did not install. The program is called qcoupons. She does have a coupon printer software she uses but this was today while I had it. I did not uninstall this since it started after I did your "read and run". I have attached all the logs. Thank you in advance.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Working your logs now, pleasehelpme2...
     
    helpmeplease2 likes this.
  3. helpmeplease2

    helpmeplease2 Private E-2

    Thank you!
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!

    re: Using Malwarebytes Anti-Malware
    Please re-run Malwarebytes and Remove Selected. Upload the new log.

    Re-run RogueKiller.exe. (Vista/Windows7/8/10 users should right-click and select "Run as Administrator")
    After it finishes the scan, select everything under these tabs and then click the Delete button.
    ¤¤¤ Registry ¤¤¤
    ¤¤¤ Files ¤¤¤

    Then immediately reboot your PC.

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Upload RKreport[2].txt to your next message.
    After uploading RKreport[2].txt, now run a new scan with RogueKiller and save a log as in the original instructions and upload that new log also.

    Now re-scan with Hitman Pro and have it delete everything under the headings of
    • Potential Unwanted Programs
    • Malware remnants
    Ignore all other detections.
    Afterwards, click the Next button.
    Now reboot the PC in order for the changes to take affect.

    After reboot and when you are back in Windows, rescan with HitmanPro and upload that new log.

    Uninstall the below software using
    GeekUninstaller 1.4.0.88, a portable appl.
    Java 8 Update 51 <= outdated
    QponPrinterV2 1.0.3

    Now run CCleaner to empty out the trash.

    *Upload all requested logs and tell me how the pc is running.
     
    helpmeplease2 likes this.
  5. helpmeplease2

    helpmeplease2 Private E-2

    Hi. I did the Remove Selected per Malwarebytes "using Malwarebytes" Run and read. So I reran it and there was nothing. I want to make sure about RogueKiller.exe instruction. I don't see tabs (screenshot) I don't see Files but I see Folder so remove all shown?
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes. Please read my instructions closely and don't do things on your own. That's what changing what I saw in the original logs and what you see now. Also go back and view the original MB log that you uploaded. See what I mean?

    Continue on with my instructions, please.
     
    helpmeplease2 likes this.
  7. helpmeplease2

    helpmeplease2 Private E-2

    Oh Man, I apologize. I see what I did. Originally I exported a log to text before I clicked the Remove Selected and did not go into History and create/upload the new log per the run and read. I have been working the last 2 days helping a senior citizen in her yard in 98 degree heat and my brain is fried and possibly dehydrated. I have been having to read things 4 or 5 times and am still having issues. I launched RogueKiller, went out of the room. When I came back it was open with the threats displayed. I thought I rescanned so did the Delete. I rebooted and there was not another RKlog (2). So I thought maybe I did not Rescan and need to rescan to make a log. So I rescanned , rebooted and did not get another log RK (2). I have attached everything so far but think I need to drink copious amounts of water and restart tomorrow. Let me know if you want me to start from the very beginning. If there I any way you can delete this after reading it, please do.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please rescan with Hitman Pro and upload an updated log.

    Also - please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.

    Describe how the pc is running.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Are you wanting to complete the malware cleaning, helpmeplease2?
     
  10. helpmeplease2

    helpmeplease2 Private E-2

    Sorry Doc, just got out of hospital yesterday. Can I have 1 more day please.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Of course! I wish you a swift recovery and this thread will remain open. We'll continue when you're ready.

    dr.m
     
  12. helpmeplease2

    helpmeplease2 Private E-2

    Ok, I am ready to continue. I rescanned with Hitman Pro. You typed delete PUP and Malware remnants. Here is the log and a screen shot. I don't see anything listed as PUP or Malware. Should I let it delete all?
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, all of the (CouponBar) listings.
     
  14. helpmeplease2

    helpmeplease2 Private E-2

    I rescanned with Hitman Pro, deleted PUP and Malware remnants, Rebooted laptop, rescanned, uploaded log, installed geek Uninstaller, removed Java 8 update 5 and Qpon printer, ran cc cleaner. ran junkware removal tool, rebooted, uploaded log. Will test run and let you know.
     

    Attached Files:

  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Those logs look good, by the way.
     
    helpmeplease2 likes this.
  16. helpmeplease2

    helpmeplease2 Private E-2

    Ok. Well, still having the same issues. Typing lags, slow internet and now random pop up to update Flash. Also, we were working on my mom's other laptop and she informed me today it is also still asking her to randomly update Flash. The address bar shows different addresses these requests are coming from. She uses Internet Explorer on this laptop and Edge on the other. I looked and both have the updated version. Should I go back to that post to inquire about the other laptop? It seems OS MS 10 has a vulnerability. After the lat sentence it seems my insert has changed. Now cannot go back and insert the missing ltters. I do not see an Insert key on this laptop.
     

    Attached Files:

  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now run this online scan on both PCs and then upload the resulting logs. *NOTE: Each log to the proper thread:
    eSet Online Scan
     
    helpmeplease2 likes this.
  18. helpmeplease2

    helpmeplease2 Private E-2

    Hi. I let it run all night and awoke to the attached error. Do you want me to try again?
     

    Attached Files:

  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  20. helpmeplease2

    helpmeplease2 Private E-2

    Ok the second scan finished. It found nothing. Last night ,before I went to sleep, I saw it showed threat found. I do not see a way to get logs. So I have left the program open and sent you 2 screenshots. I am leaving it open awaiting your instructions. Insert back to normal.
     

    Attached Files:

  21. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I see the "Adware.Toolbar" detection and also the expected False Detection on a process in MGTools. You can close the scanner now.
    What does that mean???

    Describe how the pc is running.
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now run the below instructions and upload the logs.

    Please download ZHPcleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
      • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
      • Then press the ''Repair'' button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
    Then, download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
     
  23. helpmeplease2

    helpmeplease2 Private E-2

    Hi I had typed earlier, incidentally, that before I ran this scan, that while typing the insert status changed. Now it changed back. I do not see an "insert" key on the keyboard. It just changed on its own. Example: if I typed "Help Please" and it missed letters, when I went back to insert those letters, it would delete all I typed after the insert point instead of inserting it. Usually a key named Ins changes this. I will test the Laptop and report back.
     
  24. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Run the last instructions that I gave, upload the logs... then tell me how the machine is running.
     
    helpmeplease2 likes this.
  25. helpmeplease2

    helpmeplease2 Private E-2

    Hi, is there an English page for ZHPCleaner or is the "Telecharger" button the download button? BTW the keyboard issues seem to be only when I type online. Thanks in advance.
     
  26. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Keyboard issues aren't part of this malware removal.

    Yes. *There are online language translation sites, such as
    https://www.google.com/#q=french+to+english+translation

    EDIT: A reminder to run all suggested tools while browsers are ClOSED.
     
    helpmeplease2 likes this.
  27. helpmeplease2

    helpmeplease2 Private E-2

    Thank you. Do you have an alternate site for downloading? Getting a HTTP 500 Internal server error for the ZHPCleaner after clicking the Telecharger button..
     

    Attached Files:

  28. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    helpmeplease2 likes this.
  29. helpmeplease2

    helpmeplease2 Private E-2

    Ran the ZHP Cleaner and it did not find anything. I ran the ADWCleaner and it found some things but I didn't Clean since it was not in your instructions. Now will test the laptop.
     

    Attached Files:

  30. helpmeplease2

    helpmeplease2 Private E-2

    Everything seems to be fine. No more typing issues online either. I am so glad I did not just Reimage. I learned a lot. Since there was something in her old backup, the first issue would not have been resolved without your help. Well none of the issues would have been resolved but at least I was not repeating the same mistake over and over by reloading her old backup. When I have her other computer back, approximately Saturday, I will post on the other thread. Waiting for your clean bill of health Dr. Thank you so much for your time, patience and effort.
     
  31. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome... but we're not finished.

    Using AdwCleaner.exe previously downloaded:
    • Double click on AdwCleaner.exe to run the tool. (Vista, Win7/8/10 users should right-click and "Run As Administrator")
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
     
    helpmeplease2 likes this.
  32. helpmeplease2

    helpmeplease2 Private E-2

    Log upload
     

    Attached Files:

  33. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Again - you're welcome. I'll get a notification when you do post in the other thread.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
    helpmeplease2 likes this.
  34. helpmeplease2

    helpmeplease2 Private E-2

    Thank you!
     
    dr.moriarty likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds