Need Some Help--found A Malicious Web Site

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Stiina59, Aug 5, 2016.

  1. Stiina59

    Stiina59 Private First Class

    I clicked on something in facebook and realized immediately I had found a malicious site.

    My Chrome was hijacked so I ran the couple of pre-scans and am including those results as well since I have no clue what I have infected myself with.

    The TDSSKiller log will not upload--error says the file is empty and I did get no findings. I can rerun it and see if I can get a log if you need it.

    Thanks in advance for your help!

    Laura / Stiina59
     

    Attached Files:

  2. Stiina59

    Stiina59 Private First Class

    Here is the MGLog file
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Hello, Laura / Stiina59

    Please re-run RogueKiller and upload an updated log, so I can double-check what AdwCleaner may have corrected.

    Next, download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them both in your next reply.
    Please describe any problems you are still having.
     
  4. Stiina59

    Stiina59 Private First Class

    OK, have run the two scans. I'm attaching the logs as requested. My system seems to be running OK, except my internet connection seems slow. Prior to running the Adv Cleaner, the virus was systematically taking my hardware out. My pen table was first and they typically take my wireless adapter next. I reinstalled my pen tablet and it is now working fine. I may need to reinstall my wireless too? I'm only showing 1 bar when I normally get 3.

    Thanks again for your help!

    Laura / Stiina59
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now re-run RogueKiller and run a scan. After it finishes the scan, select the following tabs and then select any of the below that exist and then click the Delete button.
    *Make sure you select the Click to Expand text ( if present ) at the bottom of the quote box to see the whole fix.
    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in the original instructions and upload the new log.

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.
    Tell me how your machine is running now.
     

    Attached Files:

  6. Stiina59

    Stiina59 Private First Class

    Dang it, I wasn't fast enough. It's taken my network adapter out and I can't find the disk. I have it, but probably didn't put it away where it belongs. Grrrrr. Will respond when I get my PC back on line.
     
  7. Stiina59

    Stiina59 Private First Class

    Ok, was able to find driver and get back on line. I've had to do back handsprings to get here, though. I installed the driver 3 times before I went to services and didn't find the one that was disabled. I ended up doing a system restore to July 26. Then I couldn't get this thing out of Safe Mode boot. I couldn't get the <F8> to work, so I had to set up safe mode in Control Panel, but once I got everything back to normal, I couldn't find where I had changed the boot mode and the searches wouldn't work because I was in Safe Mode. I really hate Windows, even more so now! It only took me 3 hours to do what 30 min. should have taken care of.

    I was able to run the Rogue Killer and get the new result. Do I need to run it again after the restore point return? I tried to run the FRST64. but it wouldn't go--that was before the restore. I didn't try to run it after in case it would mess things up.

    I'm sure the system restore has totally messed up what you were trying to do, but it was the only way I could get my drivers back and working.

    Let me know what I should do next.

    Thanks in advance!

    Laura / Stiina59
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please rerun the below and upload the logs:
    • RogueKiller
    • Malwarebytes Anti-Malware
    • AdwCleaner
    • FRST64
    NOTE: I see no signs of malware being the cause of losing your network driver(s). That may be an issue with Windows itself, but let's see the above logs first.
     
  9. Stiina59

    Stiina59 Private First Class

    With the system restore, I lost the downloaded scanning tools. I'm tearing my hair out--I can't locate the FRST64 software. Everything I'm finding is the 32 bit version which won't run on my computer. Can you tell me where to find it?

    Thanks!
    Laura
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Using system restore undid ALL changes except for "Documents". You'll have to re-download all of the tools again IF your restore point took your system back to a point before you began our malware removal procedure.
     
  11. Stiina59

    Stiina59 Private First Class

    I understood that I had to download all the files again, but that FRST64 is very well hidden! I finally found a link to it from another thread. I just kept trying to find it.

    I'm attaching the scan results that you asked for. I'm hoping by doing the system restore that I also got rid of that nasty thing. I refuse to pay a ransom request!!

    Thanks for your help.

    Laura
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome. System restore cannot be counted on to remove malware because it acts differently from regular software. But more importantly - what ransom request have you received??? Why are you just now mentioning that???
     
  13. Stiina59

    Stiina59 Private First Class

    I forgot about it, I'm sorry. It's what freaked me out and got me moving to try to prevent a total wipeout of my HDD. I was so focused on backing up and cleaning, I lost that detail. [[[Me shrinking in embarrassment]]] Does that change things? BTW I get calls all the time with those scammers trying to access my computer...I guess I'm getting numb to some of it. I didn't take a screen shot, just immediately shut my internet down and started working on things. All I know is I got a message that I need to call some phone number to obtain technical help to clean up the infection. That's when my pen tablet quit working and my wireless adapter began acting up. I've seen this before and the first time it happened, I ended up losing everything. (Not the threat, just the critter that ate up my HDD.) I also noticed that my Avira had been disabled. Again, my apologies for missing that detail!

    Laura
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    1) Receiving calls from scammers does not mean your pc is already infected.
    2) You got a message [HOW?] to call some number?
    3) Your pen tablet and wireless acting up could be a driver problem, as I said earlier.
    4) Will have to look into Avira being disabled.

    *You must be calm and think logically for me to help you. It's late and I'll review your logs after resting for the night.
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now re-run RogueKiller and run a scan. After it finishes the scan, select the following tab and then select any of the below that exist and then click the Delete button.
    *Make sure you select the Click to Expand text ( if present ) at the bottom of the quote box to see the whole fix.
    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in the original instructions and upload the new log.

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.

    Now run this online scan and then upload the resulting log:
    eSet Online Scan
     

    Attached Files:

  16. Stiina59

    Stiina59 Private First Class

    1. I know the scammers put things onto your PC if you give them access--I get the calls all the time, just saying that I've become indifferent to it, but I do get very rude with them.
    2. I was redirected to a web site that said I had been infected and that I needed to call technical support at some phone number. I don't remember what it said, just the bells and whistles went off and I knew I had gone to a bad place.

    I ran the Rogue Killer twice as directed. The second time had more detections...hmmmm. Log attached.

    After rebooting, I ran the FRST64 and invoked the Fix using your fixlist.txt file from my desktop.

    I ran the eSet Online Scan, but after several hours (and I was careful to not do anything on my computer) it stalled and crashed. I must have accidently bumped one of my mouse devices. I tried very hard to leave things alone. Before the crash, it showed 3 detections. I ran the second time and it went all the way through, but with nothing found. It didn't give me an option to save a log file when nothing was found that I could see. I can't find a log either on my desktop or in the C: directory. If it would be somewhere else, let me know so I can search for it.

    Laura
     

    Attached Files:

  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    A browser re-direct. It should be clean now.
    That's why you upload logs here - for analysis.
    Delete these folders:
    C:\Users\Mom\AppData\Roaming\Easeware
    C:\Program Files\Easeware
    Normal

    Your machine is now malware free. How is it running?
    NOTE: Any other problems with things such as drivers disappearing need to be addressed in our Software forum. *Avira being disabled would also be a software issue.
     
  18. Stiina59

    Stiina59 Private First Class

    Thank you very much for your help, dr.moriarty. I deleted the two folders per your directive. I will get Avira back up and running. Is there a cleanup I need to do? Run the .bat file in MGTools? I'll go back to the Read and Run First and do the standard cleanup.

    Laura / StiinaQT
     
  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing and remember - Facebook can be a minefield these days! [​IMG]
     
    Stiina59 likes this.
  20. Stiina59

    Stiina59 Private First Class

    Thank you again dr.moriarty! :)

    Laura / Stiina59
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds