Resilient Malware - Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tpanagos, Nov 15, 2014.

  1. tpanagos

    tpanagos Private E-2

    My wife's computer has gotten good and infected. I think it was the result of an xbox modding software install done by my son (minecraft!).

    I first got involved because the computer would no longer recognize the network printer. It was also inserting adds into every web page visited and introducing ad pop-ups randomly while browsing. When I went to run antivirus, it blocked the programs.

    I did a new install of ESET but was unable to get the latest definitions downloaded because there was a localhost:5050 proxy setup that could not be changed. After running a number of tools, I was able to get the proxy fixed and updated ESET which fixed a number of issues.

    But... there are still lingering issues. I ran the gamut suggested in the READ FIRST post. Some of the tools found no threats. The logs are attached. The browser ads are still being inserted.
    Thanks for your help!
    Tim
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like Eset removed what malware might have been there as your logs are clean. What issues are you still having, if any?
     
  3. tpanagos

    tpanagos Private E-2

    Thanks for looking, Tim.

    The browsers IE, Firefix, and Chrome are all showing the same ad banners inserted at the head and foot of every page that you visit. It happens to be a red cross ad which I am sure is a spoof.

    I think that I got the LAN proxy settings back to normal.
    Tim
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  5. tpanagos

    tpanagos Private E-2

    Attached are the logs from FRST.

    Update: I uninstalled Firefox & Chrome and reinstalled both. Firefox is now free of the spurious ads but Chrome is still affected. IE is also free of ads though I did not uninstall.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Chaslang will check your log, but in the meantime, rerun Hitman and have it remove all it found. Rescan with Hitman and attach the new log.
     
    Last edited: Nov 16, 2014
  7. tpanagos

    tpanagos Private E-2

    Reran Hitman.

    The log from the first run is labeled #1. I had it clean everything except FRST.exe. The #2 log is from a run after the needed reboot.

    I am also attaching a couple of screenshots from Chrome showing the ads. These two show-up alone or in combination on any URL. They pop in after the main page is loaded so it looks like maybe some corrupted javascript. I cleared the browser cache so it isn't something from cache.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only one minor item showed up with FRST. Let's remove it and run a junk cleaner too.


    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.

    Download this >> View attachment fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  10. tpanagos

    tpanagos Private E-2

    End of the story: the chrome browser setting reset worked to clear out the ads. I run the FRST cleanup as well. Hopefully we will be malware free from here out.

    Thanks guys!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, attach the two logs I request ( FRST.txt and JRT.txt ).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds