Malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jallenaz, Jul 21, 2015.

  1. jallenaz

    jallenaz Private E-2

    We have malware in one computer. After running all the programs Iminent is still the home page and other pop ups keep appearing from the browser. Please help. Thank you.
     

    Attached Files:

  2. jallenaz

    jallenaz Private E-2

    I think I have rid the Iminent web page that kept opening in Chrome. Now everything seems to be working as it should.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there.

    Start by rerunning Hitman Pro and letting it remove all that it finds.

    Did you let Malware Bytes fix all what it found? The log reflects that you didn't, so re run it again and if there's anything to be found let it remove it. Attach a new log for me to see please.



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Tasks tab and locate these detections:

    • [Suspicious.Path] \DHRYHOEWM1 -- C:\ProgramData\LolliScan\LolliScan.exe -> Found
    • [Suspicious.Path] \Security Installer -- C:\Users\Tiffany\AppData\Roaming\Updater\winupd.exe -> Found
    • Place a checkmark next to each of these items, leave the others unchecked.

    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  4. jallenaz

    jallenaz Private E-2

    Hello, I've been away and just got back to finish this up.

    I ran Malwarebytes again. It found 2 pups. I saved the log before deleting them. After it deletes the pups it rebooted not leaving me a chance to save the log again. I was afraid that might happen so had saved it before deleting the files.

    I ran Hitman Pro, but it wanted me to buy it before it would delete anything. So I didn't get to delete anything with it.

    Everything has been working as it should for the past 10 days. No complaints anyway.

    Thanks for your time and expertise.

    Jim:)
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good evening :)


    [​IMG] Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hchje (System32\drivers\jrje.sys)

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\WINDOWS\system32\tasks\DHRYHOEWM1
    C:\WINDOWS\tasks\DHRYHOEWM1.job
    C:\WINDOWS\tasks\NYIWMTUHRNVMHPUJ.job
    C:\Program Files (x86)\app_setup
    C:\Program Files (x86)\SearchProtect2_IMonetizer
    C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066
    C:\ProgramData\1L42Iln3.dat
    C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066
    C:\WINDOWS\system32\tasks\NYIWMTUHRNVMHPUJ
    C:\WINDOWS\system32\drivers\jrje.sys
    
    :reg
    [-HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}]
    [-HKLM\SOFTWARE\Microsoft\Tracing\SevereWeatherAlerts_RASAPI32]
    [-HKLM\SOFTWARE\Microsoft\Tracing\SevereWeatherAlerts_RASMANCS]
    [-HKLM\SOFTWARE\Microsoft\Tracing\SWAUpdater_RASAPI32]
    [-HKLM\SOFTWARE\Microsoft\Tracing\SWAUpdater_RASMANCS]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SevereWeatherAlertsApp_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SevereWeatherAlertsApp_RASMANCS]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
    [-HKLM\SOFTWARE\Wow6432Node\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}]
    [-HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-18\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-19\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-20\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-21-1602778222-2260973681-152632175-1207\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-21-1602778222-2260973681-152632175-1207\Software\PowerPack]
    [-HKU\S-1-5-21-1602778222-2260973681-152632175-4170\Software\PowerPack]
    [-HKU\S-1-5-21-1602778222-2260973681-152632175-4170\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}]
    [-HKU\S-1-5-21-1602778222-2260973681-152632175-500\Software\PowerPack]
    [-HKU\S-1-5-21-420837302-700111541-3423538724-1001\Software\PowerPack]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    Download Cleano 1.3.1

    Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows (click on link below to see image)

    View attachment 148092
    Click clean now and exit the program.


    • Now re run Hitman Pro again and attach the log, let's see what remains.
    • Same for RogueKiller, rescan and attach log.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  6. jallenaz

    jallenaz Private E-2

    It looks like Hitman found more items. Might be cheaper to buy that if it would get rid of what is necessary.

    Rogue Killer has to export and name the log files is why the different names than you have.

    Thanks again for the help so far. I hope we are getting somewhere.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How would you feel about going into the Windows Registry and making some deletions yourself? Let me know. I have to go to bed now, it's late and I am tired. Will work on this some more in the morning. :)
     
  8. jallenaz

    jallenaz Private E-2

    I could do that. It's the weekend and I'm not at that computer until Monday.

    Thanks, have a nice weekend.

    Jim
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just enable the free 30 day trial and use it to cleanup all the Potential Unwanted Programs it is reporting. ;)
     
  10. jallenaz

    jallenaz Private E-2

    We can't because we are on a business domain.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then perhaps Kestrel13! can provide a registry patch but many times this will not work completely which then means you have to clean it up manually. ;)
     
  12. jallenaz

    jallenaz Private E-2

    If Hitman will clean it, then spending the $25 would be worth it. Will it do the job?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's try either with a reg patch or manually.


    Reg patch first...

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Reboot the machine....

    Now rescan with Hitman and attach newest log! :)
     
  14. jallenaz

    jallenaz Private E-2

    I got the message that the text was successfully merged.

    Attached Hitman log.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK that wiped out a good chunk. Do you want to manually remove what remains? Just delete the entries in bold.

    Once done, reboot the machine and rescan with Hitman once again. Attach log. :)
     
  16. jallenaz

    jallenaz Private E-2

    The last three entries you had me delete were already gone when I got there. Hitman said no more malware. I think we got it.:celebrate
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent!! :) And how are things running?
     
  18. jallenaz

    jallenaz Private E-2

    Everything seems to be running as it should. I just rebooted and the lady using it just came in and started running her programs. Looks good.

    She will be much more careful where she gets downloads from now.

    Thank you so much. :)
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds