Malware Removal? All steps taken?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by monsta, Sep 13, 2013.

  1. monsta

    monsta Private E-2

    Hi.

    4 days ago my machine began running slow, mouse was erratic, net was dragging and every re-boot I got the error window as in the attatched screenshot.

    After running Norton as standard - and Advance System Care (which I then deleted) and finding nothing I came here - and followed your advice to the letter . The log attatchments are below. Im stumped - please help. Thanks.

    Im running W8, 64 Bit. 6.00 gig Ram, i5.
     

    Attached Files:

  2. monsta

    monsta Private E-2

    plus this TDSKILLER log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do have some junk to remove but your problems may not be due to malware.

    Did you knowingly install the below stuff?

    C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
    C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\tasks\MySearchDial.job
    C:\Users\MICKWO~1\AppData\Roaming\MySearchDial\UpdateProc\UpdateTask.exe
    C:\ProgramData\Babylon
    C:\ProgramData\PC Tools
    C:\Users\Mick Wood\AppData\Local\Temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\DataMngr]
    [-HKEY_USERS\S-1-5-21-1963584255-3594785602-1249667100-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKEY_USERS\S-1-5-21-1963584255-3594785602-1249667100-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_USERS\S-1-5-21-1963584255-3594785602-1249667100-1001\Software\Softonic]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{2330B73E-00D0-1085-FC60-3DFFBD1CC8D2}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{C5366604-2FED-4B35-9AEB-30FC4DA8F5B8}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{2330B73E-00D0-1085-FC60-3DFFBD1CC8D2}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C5366604-2FED-4B35-9AEB-30FC4DA8F5B8}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. monsta

    monsta Private E-2

    Hi Chaslang, thanks for your swift and detailed reply. After completing the process (los attached) I re-booted, everything seems fine - even the HP helper updated itself and I no longer get the error screen. All seems good.

    Am I fit for duty now ? :)

    Also, if so - do I keep the seven progs I have downloaded today? Leave them as is or configure them?

    and what would you recommend I d/l as protection against this - or any other issues in the future (I only have Standard Norton - paid edition).

    Thanks again .

    STOP PRESS : This page wont allow me to upload the zip folder??
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You need to follow my instructions properly. ;) You have to run the C:\MGtools\GetLogs.bat file first to create a new log.
     
  6. monsta

    monsta Private E-2

    Attatched now - sure it was a glitch here that stopped me uploading earlier :)

    BTW - to answer your earlier question, I did knowingly install this free trial - (C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
    C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe)

    used it once but forgot about it , deleted all files from it now:-o
     

    Attached Files:

    Last edited: Sep 14, 2013
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay a few items we were trying to fix did not get fixed. Also Delta still shows as an addon in Google Chrome. Let's see if we can get the rest removed. First we need to scan with another tool.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  8. monsta

    monsta Private E-2

    As requested :)
     

    Attached Files:

    • OTL.Txt
      File size:
      287.6 KB
      Views:
      1
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts.
    • Double-click OTL.exe to run. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    :OTL
    IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL]http://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1Qzu0F0A0B0BtA0AyE0E0A0EzytB0B0C0FyEtN0D0Tzu0CyDzytAtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=1031832799&ir[/URL]=
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = [URL]http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dnldmsd&cd=2XzuyEtN2Y1L1Qzu0F0A0B0BtA0AyE0E0A0EzytB0B0C0FyEtN0D0Tzu0CyDzytAtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=1031832799&ir[/URL]=
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = [URL]http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF[/URL]
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{C5366604-2FED-4B35-9AEB-30FC4DA8F5B8}: "URL" = [URL]http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms[/URL]}
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = [URL]http://rover.ebay.com/rover/1/710-29550-11896-25/4[/URL] ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
    IE - HKLM\..\SearchScopes,DefaultScope = {2330B73E-00D0-1085-FC60-3DFFBD1CC8D2}
    IE - HKU\S-1-5-21-1963584255-3594785602-1249667100-1001\..\SearchScopes,DefaultScope = {2330B73E-00D0-1085-FC60-3DFFBD1CC8D2}
    IE - HKU\S-1-5-21-1963584255-3594785602-1249667100-1001\..\SearchScopes\{2330B73E-00D0-1085-FC60-3DFFBD1CC8D2}: "URL" = [URL]http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&cof=&q={searchTerms[/URL]}
    CHR - default_search_provider: Delta Search (Enabled)
    CHR - default_search_provider: search_url = [URL]http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=C2A572E6F7E9A658&affID=119357&tt=180813_220&tsp=4980[/URL]
    O4 - HKU\S-1-5-21-1963584255-3594785602-1249667100-1001..\RunOnce: [Application Restart #0] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --flag-switches-begin --flag-switches-end --restore-last-session [URL]http://sitedirector.symantec.com/932743328/?ssdcat=264&spskup=21244261&spskum=21244261&spefsku=21228659&psn=GT227YVP3WQM&plang=sym:EN&oslang=iso:ENG&displang=iso3:ENG&oslocale=iso:GBR&displocale=iso3:GBR&vendid=0&vendtag=&action=login&serviceTicket=ST-WzlDKpLhkAIQ6w9H6FXA-13f64d3bf6f-nav&product=Norton%20Internet%20Security&version=20.0.0.136&layouttype=OEM&buildname=OEM30&heartbeatID=5EBF4464-4996-4951-BE9C-B8C7798567D7&env=prod&vendorid=32430&plid=2&plgid=2&skup=21244261&skum=21244261&skuf=21228659&cipherid=0&endpointid=%7B5EBF4464-4996-4951-BE9C-B8C7798567D7%7D&partnerid=32430&lic_type=512&lic_attr=21123089&osvers=6.2&os=windows[/URL] File not found
    @Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:24051EFF
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the [​IMG] button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. monsta

    monsta Private E-2

    Done and attatched.

    Just to let you know that Malwarebytes and Hitman Pro are still running in the background as I wasnt told to change that?

    Machine seems fine:cool

    Thanks.:)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Chrome is still showing Delta in seach entries.
    • Run Chrome
    • Click the Customize and Control Google Chrome button ( the 3 parallel lines down below the X button used to close the window ).
    • Then on the pop down form select Settings.
    • Now under the Search heading, click the Manage Search Engines button
      • Look in here for anything related to Delta and select it and delete it by clicking the X button to the far right side.
      • Make sure that you look in both the Default Search Engines and Other Search Engines areas and delete any Delta junk.
      • Select the default search engine you want ( like Google ) and click the Make Default button.
      • When finished, click the Done button
    • Now back on the Settings page to the top left you should see an Extensions selection, click on it to bring up the installed extensions.
    • Look for any undesired extension ( like Delta or anything else you did not install ) and if found, click the Trash Can icon to delete the extension.
    • Now close the Extensions/Setting tab to get back to normal view
    • Exit Chrome and reopen. See if it works okay.
    • Are you any more problems now with any browsers?
     
  12. monsta

    monsta Private E-2

    Hi.

    Heres a problem - I dont have Chrome :confused ,installed - un-installed it months ago?
     
  13. monsta

    monsta Private E-2

    Hi.

    Heres a problem - I dont have Chrome :confused ,installed - un-installed it months ago?

    Im running Firefox - all is fine.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then just delete the below folder to remove the last of it.

    C:\Users\Mick Wood\AppData\Local\Google\Chrome


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. monsta

    monsta Private E-2

    Chaslang - you rock! :cool

    Thank you very much for taking the time to do this - my machine is running perfectly.

    I followed all that you posted, all good ( the Autorun Eater 2.6 link is down, I will keep trying).

    Everything else is fully understood and sorted.

    Very much appreciate the time, effort and expertise you guys all provide (for free!).

    Cheers chaslang, Cheers Major Geeks :major

    Monsta salutes you ;)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I fixed the broken link. ;)

    You're welcome. Surf safely!
     
  17. monsta

    monsta Private E-2

    Theres a prob with the fixed Autorun Eater 2.6 link, downloaded and installed but when I try to run the prog Malwarebytes finds "Trojan.injector.o....."(cant read full name in the quarantine log).

    Have deleted the prog - please advise. Thanks
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no problem with the Autorun Eater download. Malwarebytes is incorrect.
     
  19. monsta

    monsta Private E-2

    I cant run it - even as admin - I get this (see attachment).:cry
     

    Attached Files:

    • 1.jpg
      1.jpg
      File size:
      70.4 KB
      Views:
      3
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since MBAM falsely detects the C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe file from Autorun Eater as a problem. You just need to add it to MBAM's Ignorelist.

    You will also have to Restore the file from the Quarantine. This is why the shortcut cannot located it. MBAM quarantined the file.
     
  21. monsta

    monsta Private E-2

    Done all that - it just keeps re-quarantining it. Tried fresh downloads too - it wont let it run.?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I tested this directly on my Windows 8 based PC and it works perfectly fine if I add the C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe file to the Ignorelist. Do you see the file showing in MBAM's Ignorelist?
     
  23. monsta

    monsta Private E-2

    When I select "add" on Malwarebytes ignore list I can only click through to find:
    C:\Program Files (x86)\Autorun Eater
    NOT the oldmcdonald.exe part of the file name.

    So, I tried that - no flagging up from Malwarebytes - but the shortcut on my desktop refuses to open - even "as admin"?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to restore the file first from quarantine. You already deleted it previously.
     
  25. monsta

    monsta Private E-2

    I started from the beggining again, followed your instructions to the letter.

    Everything is all cool - up to the point where it re-boots.

    I STILL cant open the desktop shortcut.

    Nothing in MBAM quarantine (restored) and ignored the full file path.
    C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe

    The prog will not open (I get a "flash" of a donkey? and thats it). ???:banghead
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So does the below file actually exist?

    C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe

    What is the desktop shortcut pointing too? Do you still get the same error message that you previously posted a snapshot of? If yes, then the shortcut is not pointing to the correct location or the file does not exist.

    Other possibilties, MBAM and/or Norton are getting in the way.
     
  27. monsta

    monsta Private E-2

    I dont get any error message, it just doesnt open.

    The shortcut properties point to
    "C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe"
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but I also asked the below question:
    If it does exist, try shutting down Norton and MBAM protection and see if it runs. Also run this file directly without using your shortcut.
     
  29. monsta

    monsta Private E-2

    Sorry - I missed that.

    Disabled all and ran direct - its there but its only 511kb, and obviously is not installed?

    Should I just look at alternatives to both this and MBAM?

    Thanks for your continued help :confused
     
    Last edited: Sep 18, 2013
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you mean. 511kb is the correct size.

    Again not sure what you mean. What alternatives?

    If it does not run properly when you have MBAM's protection disabled then you have something else blocking it. Possibly Norton. As I stated earlier, I have Autorun Eater working on my Win 8 PC and MBAM is running with full protection enabled. I however do not use Norton. I even allowed MBAM to quarantine it at one point and then restored it from quarantine and put in the Ignorelist entry and it worked just fine again afterward. You have something else blocking it if you cannot run it.
     
    Last edited: Sep 26, 2013
  31. monsta

    monsta Private E-2

    Thanks chaslang - I have the full version of Norton -paid for so I wont drop it. Any alternatives you can suggest?

    Cheers.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Alternatives for what?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds