Malicious Website Protection - Trcklion.com

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Aggie9092, Oct 13, 2016.

  1. Aggie9092

    Aggie9092 Private E-2

    For the past week, Malwarebytes has popped up the message:

    Protection, Malicious Website Protection, Domain, 74.120.16.187, trcklion.com, 56209, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    The IP address is always the same, but the ports keep changing. I have tried all the recommendation I can find online, but with no luck. I'm using Chrome on the latest version of Windows 10.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now please download ZHPcleaner to your desktop.

    Double click on ZHPCleaner to run the tool.
    If you are using Windows Vista, 7, 8, or 10; instead of double-clicking, right-mouse click on ZHPCleaner and select "Run as Administrator".
    Please click J'accepte/I accept
    Then press ''Repair'' button.
    Browsers will automatically shut down.
    A logfile will automatically open after the scan has finished.
    Please attach the logfile to your next reply.
     
  3. Aggie9092

    Aggie9092 Private E-2

    Here you go.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Are you still experiencing issues?
     
  5. Aggie9092

    Aggie9092 Private E-2

    Yes, still have the same problem.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I see you have the Premium (Paid for) version of Malware Bytes. I think it's just doing it's job, and the paid for version does pop up alerts that can sometimes confuse users into thinking they are infected when in fact, it's just reporting what it has blocked.

    Do you have any issues using other browsers? Or is it just Google Chrome?

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  7. Aggie9092

    Aggie9092 Private E-2

    I don't mind the occasional pop up, but this is happening 100 times a say so I assume it is not supposed to be happening.

    Here are the logs.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK I understand.


    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Files tab and locate these detections:

    • [Hidden.ADS][Stream] C:\Windows\SysWOW64\MSIHANDLE:6000 -> Found
    • [Hidden.ADS][Stream] C:\Windows\SysWOW64\MSIHANDLE:6048 -> Found
    • [Hidden.ADS][Stream] C:\Windows\SysWOW64\MSIHANDLE:6146 -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine. See if this makes a difference.

    Don't forget to address this question I asked:

    Do you have a log you can attach from Malware Bytes?
     
  9. Aggie9092

    Aggie9092 Private E-2

    RougeKiller wouldn't let me scan again because I had never selected what to do with the stuff it found last time. So the log is the original from when those three errors you had me delete, were found. I've attached that log and the Malwarebytes log. That may have solved the problem. I can 't get the pop-up in IE or Chrome right now. I'll keep trying.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There is no reason why RogueKiller will not let you scan again. In any case you need to open up the program and have it REMOVE these three items as I indicated before:

    • [Hidden.ADS][Stream] C:\Windows\SysWOW64\MSIHANDLE:6000 -> Found
    • [Hidden.ADS][Stream] C:\Windows\SysWOW64\MSIHANDLE:6048 -> Found
    • [Hidden.ADS][Stream] C:\Windows\SysWOW64\MSIHANDLE:6146 -> Found
    Once done, you need to do JUST a SCAN and upload FRESH log.
     
  11. Aggie9092

    Aggie9092 Private E-2

    Here you go. I have a bunch of new ones popping up today. I've attached the RK log and the new Malwarebytes log.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  13. Aggie9092

    Aggie9092 Private E-2

    So I tried to run the ESET scanner 4 times and each time it crashed before I could get a log. That was with my AV off and nothing else running. The good news is that ever since RougeKiller removed those 3 items, I haven't had any issues.

    Now, the question is that I changed networks at the same time I ran RK and haven't been back to the one where I was getting the pop-ups. Any chance this could be related to the network setting where I was? That was a corporate office and the two different networks that I am on now are more open network.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm not too sure to be honest, Aggie9092, but I am pleased to hear that everything is fine since running RogueKiller. Is there anything else I can help with or do you feel it's time for final steps?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds