Malware for sure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pixelmanjoe, Nov 8, 2014.

  1. pixelmanjoe

    pixelmanjoe Private E-2

    Hi,

    I suspect I have malware on my system. Attached are my logs. Can you guys take a look and let me know what you think?

    Thanks so much!

    Joe
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you fix what MBAM found?
     
  3. pixelmanjoe

    pixelmanjoe Private E-2

    I allowed it to quarantine everything.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware, just some junk and pup's. Let's do this:



    Download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Processes
    explorer.exe
     
    :files
    C:\ProgramData\2435d64e5880ad74
    C:\ProgramData\CooolSaleCoupuoon
    C:\ProgramData\deoiwnnloadiTokeepo
    C:\ProgramData\Greeatsaavving'
    C:\Program Files (x86)\CooolSaleCoupuoon
    C:\Program Files (x86)\deoiwnnloadiTokeepo
    C:\Users\admin\AppData\Local\Temp\*.*
     
    :Commands
    [purity]
    [ResetHosts]
    [start explorer]
     
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach that document back here in your next post.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Be sure to tell me how things are running now.
     
  5. pixelmanjoe

    pixelmanjoe Private E-2

    Attached are the log files. Thanks so much for helping me with this.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. pixelmanjoe

    pixelmanjoe Private E-2

    Thanks so much for all your help. I think I'm good to go. Whew! You guys are awesome!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I forgot to have you rerun RogueKiller and Hitman to see if they were clear. Would you please do so and get me the new logs?
     
  9. pixelmanjoe

    pixelmanjoe Private E-2

    Attached are those files. It looks like Hitman found some items.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and have Hitman fix everything it found, reboot and rescan with Hitman and attach the new log.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    @TimW The trial for Hitman Pro has expired. You will have to remove with OTM or similar.
     
    Last edited: Nov 10, 2014
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In case you already removed it, download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Windows\System32\Tasks\Optimizer Pro Schedule
    C:\Users\admin\AppData\Local\Temp\is1955396272\212A26F2_stp\OptimizerPro.exe
    
    :reg
    [-HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}]
    [-HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}]
    [-HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}]
    [-HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule]
    [-HKLM\SOFTWARE\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKLM\SOFTWARE\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}]
    [-HKLM\SOFTWARE\Wow6432Node\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKLM\SOFTWARE\Wow6432Node\{6791A2F3-FC80-475C-A002-C014AF797E9C}]
    [-HKLM\SOFTWARE\Wow6432Node\{77D46E27-0E41-4478-87A6-AABE6FBCF252}]
    [-HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-18\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-19\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-20\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-21-3090795956-2231270461-4268346497-1000\Software\AppDataLow\Software\Conduit]
    [-HKU\S-1-5-21-3090795956-2231270461-4268346497-1000\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-21-3090795956-2231270461-4268346497-1000\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
    [-HKU\S-1-5-21-3090795956-2231270461-4268346497-1000\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com]
    [-HKU\S-1-5-21-3090795956-2231270461-4268346497-1000\Software\Optimizer Pro]
    
    :Commands
    [purity]
    [ResetHosts]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And then re run Hitman again to see what's left and attach log.
     
  14. pixelmanjoe

    pixelmanjoe Private E-2

    I ran OTM and the log is attached. I also ran Hitman again and the log is attached.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data
    C:\Windows\System32\Tasks\Optimizer Pro Schedule 
    
    :reg
    [-HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}]
    [-HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule]
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Reboot and rescan with Hitman and attach the new log along with the OTM log.
     
  16. pixelmanjoe

    pixelmanjoe Private E-2

    Done. Attached are the logs.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, Hitman is still reporting it, but OTM can't find them. Do a manual search for:
    C:\Windows\System32\Tasks\Optimizer Pro Schedule

    Let me know if you find it.
     
  18. pixelmanjoe

    pixelmanjoe Private E-2

    Yes, I see the file there. Attached is a screen shot.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you right click and delete it?
     
  20. pixelmanjoe

    pixelmanjoe Private E-2

    Yep, I just did that and it deleted.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How comfortable are you with editing your registry?

    First, let's try to delete them again.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now after a reboot, rescan with Hitman and attach the new log.
     
  22. pixelmanjoe

    pixelmanjoe Private E-2

    Those entries don't appear. Attached is the log.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I wanted to have you run another scan with Hitman, please.
     
  24. pixelmanjoe

    pixelmanjoe Private E-2

    Attached is the Hitman log.
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you feel comfortable with editing the registry? If so,right click start / run / type in:
    regedit

    When the registry opens, make a backup. Then search for these keys and right click and delete;

    HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}\

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule

    Tell me if you have success.
     
    Last edited: Nov 13, 2014
  26. pixelmanjoe

    pixelmanjoe Private E-2

    I managed to find them both and delete them. I rebooted and everything seems to be fine. I then searched for the same registry items again and they are gone. What do you think? Am I at the end of this long road? LOL
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good job!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  28. pixelmanjoe

    pixelmanjoe Private E-2

    All done. Whew! Thanks so much for all your help. You guys are awesome. I'm hitting the donate button now.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds