Computer compromised (again)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fizkowie, May 4, 2014.

  1. fizkowie

    fizkowie Private First Class

    Hi,

    My computer (husband's actually) has problems again. I did all the steps from the Read This first post and am attaching the logs it requests. Note, I couldn't perform any "fix" with HitmanPro as I was told that my trial license had expired - it did find issues however. Also, Malwarebytes did not find anything at all.

    Please let me know to proceed.

    Thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still need to attach the Hitman log. Also the log from running MBAM.

    And please tell me what issues you are having.
     
  3. fizkowie

    fizkowie Private First Class

    Hi,

    Ok, I found the logs and they are attached. We started getting floating windows on the computer that ask us if we want to fill out a survey, or clean our computer or buy something. Also, whenever we tried to search for something in Firefox or IE, it would change to rsearch and also the internet was REALLY slow. These windows came up even as I was cleaning the computer today.

    Thanks!

    BTW - your picture is really spooky.
     

    Attached Files:

  4. fizkowie

    fizkowie Private First Class

    Just an add-on...we didn't use the computer since mid afternoon yesterday and today the desktop switched to a Window's logo with all the icons rearranged (normally there is a picture for our desktop). Once I logged off and reclogged on, it came back to how it should look.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it fix these items:

    Code:
    ask.com
       C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Web Data
       session/startup_urls[2]
       C:\Users\Radek1992\AppData\Local\Google\Chrome\User Data\Default\Preferences
       ask.com
       C:\Users\Radek1992\AppData\Local\Google\Chrome\User Data\Default\Web Data
       search.conduit.com
       C:\Users\Radek1992\AppData\Local\Google\Chrome\User Data\Default\Web Data
       C:\Users\Radek1992\AppData\Local\NativeMessaging\ (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\ (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\1_0_0_4\ (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\1_0_0_4\nmHostConfig.json (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\1_0_0_4\nmHostManifest.json (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\1_0_0_4\TBMessagingHost.exe (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\1_0_0_9\ (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\1_0_0_9\nmHostConfig.json (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\1_0_0_9\nmHostManifest.json (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\1_0_0_9\TBMessagingHost.exe (Conduit)
       C:\Users\Radek1992\AppData\Local\NativeMessaging\CT3153924\nmHostManifest.json (Conduit)
       HKLM\SOFTWARE\Classes\s\ (Softonic)
       HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B3C014A8-96FF-47A9-80CA-0AB86100AC19}\ (AskBar)
       HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Browsersafeguard_RASAPI32\ (BrowserSafeguard)
       HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Browsersafeguard_RASMANCS\ (BrowserSafeguard)
       HKU\S-1-5-21-3192997070-4047456054-176730348-1004\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}\ (FLV Player)
    Cookies 
    Reboot and rescan with Hitman and attach the new log. Let me know how things are running.
     
  6. fizkowie

    fizkowie Private First Class

    Hi Tim,

    Please see my initial post - I can't "fix" anything with Hitman as my trial subscripton has expired - it can only "find" problems. Can I use another program? Thanks.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Reboot and give me another log from Hitman.
     
  8. fizkowie

    fizkowie Private First Class

    Hi Tim,

    Thanks for the email. I ran JRT and the log is attached. Apparently, Hitman will no longer post logs or because it displays "No Threats Found" there isn't one. I do have a question - when I originally ran RogueKiller according to the "Read & Run Me First" - it apparently found some PUP"s which weren't removed as the directions said to not do anything with the results - just post the log. I think these may still be in the RK quarantine - did JT get rid of these or were they not actually PUP"s?

    Let me know what to do next. Txs.

    Tammy
     

    Attached Files:

    • JRT.txt
      File size:
      5.5 KB
      Views:
      2
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The RogueKiller log was OK. What issues are you still having, if any?
     
  10. fizkowie

    fizkowie Private First Class

    Hi Tim,

    It seems to be okay now - no floating messages. Can I reinitiate my UAC? Thanks.

    Tammy
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
    8. How to Protect yourself from malware!
     
  12. fizkowie

    fizkowie Private First Class

    Thank you Tim. I think we're good now. Except that we seem to have lost our microphone. When I click on All Programs/Accessories/Sound Recorder I get an error message that tells me that "An audio recording device cannot be found"? Is this related somehow?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, it shouldn't be related. You can post in the software forum for that issues. You will have to check in Device Manager.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds