Possible Rootkit, logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by molov127, Jul 29, 2014.

  1. molov127

    molov127 Private E-2

    View attachment HitmanPro_20140728_1838.log

    View attachment MGlogs.zip

    View attachment RKreport_DEL_07282014_133938.log

    View attachment TDSSKiller.txt

    View attachment mbam-log-2014-07-28 (13-53-12).txt

    Hi, i had to change the malwarebytes xml file to txt format. sorry. Most of the problems when away that I was experiencing, but little weird things r left over.. my trackpad keeps freezing and cant move my mouse for a couple minutes, then its completely fine, everytime i go to type in a password on any website, it freezes for a couple seconds, only when i do passwords though. None of this has ever happened until the past two weeks when this istart123 stuff starting showing up as my home page. I followed the Win 7 malware guide to the T and it helped. ccleaner helped too.

    i got the logs and didnt do anything else.

    I wont bump this post, ill check back every now and then.. thankyou
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The instructions in the sticky clearly explain how to get us a .txt log. Did you indeed have Malware Bytes fix what it found or not?


    Re run Hitman Pro and have it remove all that it finds (including the cracked software you have;)) Warning about Porn, Keygens, Cracks, and other Illegal Software

    But do not have it touch the PunkBuster entry(ies)



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IePluginServices
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WindowsMangerProtect
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IePluginServices
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WindowsMangerProtect
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\IePluginServices
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WindowsMangerProtect
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istart123.com/web/?type=ds&ts=1406242128&from=irs&uid=ST9750420AS_5WS0AD5ZXXXX5WS0AD5Z&q={searchTerms}
    • O2 - BHO: (no name) - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - (no file)

    After clicking Fix exit HJT.



    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\ProgramData\8fe66056e2f900bc
    C:\ProgramData\Conduit
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A039A284-C94B-4BE8-B9E4-159DC165B4A9}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    • Re run RogueKiller (just a scan! Do not fix anything) and attach new log.
    • Also re run Hitman Pro and attach the new log from that also.
    • Let me know about Malware Bytes.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. molov127

    molov127 Private E-2

    Hi Kestrel. First let me thank you for some major help, all of your instructions as well as the other members' contributions were well put together and easy to follow.

    OK i have followed your new steps and so far everything has gone as you asked. now i am at the point where i will re-run rogue killer for a log only and continue with the rest.

    I am posting from another computer right now.

    I did hit ignore all on malware bytes

    I will have the reports soon, just checking in for now.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. You are most welcome! :)

    Please then do have it remove what it finds.
    Sure.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds