Something Is Calling Home, Help.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rubinontheroad, Aug 12, 2016.

  1. rubinontheroad

    rubinontheroad Private E-2

    Hi, first post, Malwarebytes Pro has just started "stopping" an item from sending something outbound. (XMl.clk1013.com) I did complete scans and also scanned the folder MB told me that the item lived in. Scans found no threats. I will enclose the MBs log from today for further help. The item originated in the Mozilla Firefox folder at C/Program Files/Mozilla Firefox (86) /Mozilla firefox exe. and the MB action, shows up whenever FF starts. I looked there and also found nothing but I don't know anything. Google found the item "xml.clk1013.com" and it looks like malware/adware. Something call "UnHackMe" was recommended and it did nothing except confuse me and cause me to uninstall/reinstall FF. it also said that programs I've had and used for years were dangerous. I use a new up to date PC with Win 10 pro and FF as my browser of choice, AV is Win Defender and Malwarebytes Pro and Anti Exploit. I would appreciate any help anyone on this forum can give. Thank you, S Rubin

    Here is a Google directed site that came up for xml.clk1013.exe

    Mod Edit: Blog reference suggesting non-recommended software removed



    see below for today's MB log:
    Mod Edit: Inline log removed and uploaded
     

    Attached Files:

    Last edited by a moderator: Aug 12, 2016
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  3. rubinontheroad

    rubinontheroad Private E-2

    dr. moriaty, I believe I have followed your instructions, I sure you and your fellow helpers will let me know if I messed up in anyway. My only mistake was after running "Rogue Killer" I deleted the objects that were found, you all should see a list of what I deleted. I hope I have not screwed up too much. I'm going to attach the files I got and hope you all will get them. Thank you S Rubin
     

    Attached Files:

  4. rubinontheroad

    rubinontheroad Private E-2

    dr. I ran into the five file limit and am attaching the last log file to this post response. Again thank you all.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) From what I see - you run a "tight ship", S Rubin.

    Let's see if these find anything:

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.

    Let me know how your machine is running.
     
  6. rubinontheroad

    rubinontheroad Private E-2

    dr. PC is running just fine. In starting and restarting PC and Firefox browser many times since we started this, Malwarebytes Pro, has NOT flagged any call home attempts. I have used AdwCleaner, HitmanPro before and have downloaded RogueKiller, but never installed or of course, run it. As stated before I am a happy Malwarebytes Pro used and have used CCleaner for many years. Attached are the log files you asked for. Thank you again for shepherding me through this and I await further instruction....S Rubin
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!

    I would only say "Use caution!" when using Hitman Pro & RogueKiller because as you see - legit programs and registry keys do get flagged.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
    * Now - create a new clean restore point and note it's date and time!
    Safe surfing!
    [​IMG]
     
  8. rubinontheroad

    rubinontheroad Private E-2

    dr. moriaty, Many thanks again, all seems fine. I will try not to screw up in the future (Ha), it's great to know that their are folks like you and the team for those times when it all goes to hell. Take care, Stan Rubin
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool: You're welcome! Have fun and stay on top of things the way you have been, Stan.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds