New Windows 8 ;aptop gets infected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ONEEYEMAN, May 24, 2015.

  1. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, ALL,
    I recently got a new laptop with Windows 8.1.
    Its been about 2 month and apparently its already becomes infected. ;-) And that never happened to me before or at least not that fast.

    I installed FF with AdBlock and NoScript extensions and also Avira and ZoneAlarm.

    Anyway what happens is that when I click the link on the page in FF I get re-directed to the "about:blank" page. The only way to not to go there is to click the link while the page is loading. And sometimes I get re0directed to some advertisements page.

    So I ran R&R. The very first program I ran - Rogue Killer - didn't produce the log file anywhere on the machine. So I continued and will attach the logs from the other scanners.

    Also sometimes I see the "You have received a premium offer from Digital More. Click here to learn more" underneath the address bar in FF.

    Thank you in advance for any advice.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it remove what it sees.

    You need to re run RogueKiller and click on the report button if a log does not crop up.

    MGTools did not run correctly. You need to run it again this time ensuring UAC is disabled, that you do indeed right click and run as admin and that protection softwrae is disabled...
     
  3. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel,
    Did that. Thanks.

    I just tried to re-run the RogueKiller. It ran, but again didn't generate the log and the "Report" button is disabled. Running as administrator didn't help.

    I'm running Windows 8.1. The R&R instruction about UAC talks about Vista/7 only. Any updates?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try running RK in safe mode.

    The win7 instructions should be ok for you to run no problem. You getting me the MGlogs.zip is important, its one of the main logs.
     
  5. ONEEYEMAN

    ONEEYEMAN Corporal

    Kestrel,
    Tried it. Same thing happened.

    Here are the instruction from the R&R:

    Problem is - there is no "Change User Account Control Settings" anywhere in the "User Account and Family Safety".
    Any idea?

    Also, will it be enough to run the GetLogsBat or I will need to run something else? It is already unpacked and installed and I don't want to keep running the archve...
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  7. ONEEYEMAN

    ONEEYEMAN Corporal

  8. ONEEYEMAN

    ONEEYEMAN Corporal

    Sorry forgot to put in the attachment
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not familiar with Windows 8... try this...

    • Go to start > type in "cmd"
    • Click on cmd.exe > and paste in the following:

    After you enable or disable UAC, you will have to reboot your computer for the changes to take effect.
    You should receive a success message saying: "The operation completed successfully"
     
  10. ONEEYEMAN

    ONEEYEMAN Corporal

    Kestrel,
    Command was executed successfully.
    However, running MGTools.exe still crashes, right after the last instance of:

    finding all instances of the <program/library>

    I guess we need the author of this software to chime in... ;-)

    Thank you.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try running this for now as Chaslang may be busy...

    Now please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exactly do you mean by crashes?
    And are you sure about "finding all instances of the <program/library>" text because there is no such string in MGtools.
     
  13. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, guys,
    2Kestrel,
    Log is attached.
    It's a tar.gz archive which was just renamed az zip to satisfy the rules of the site for an upload.

    Apparently the log generated was bigger than the upload limit for the text file so I had to archive it.

    2chaslang,
    What I mean is that the DOS window just close itself and that's it. Just like the usual crash of the program.

    And this happens either after the last line of:

    or during the execution of the last one.

    And yes, I'm sure of that line. I fact there couple of them on the screen which said:

    That's what I meant by saying <program/library>. Or I probably should've said "<program|library>" using OR notation.

    Thank you.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Windows will not let me open that zipped file :(
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a ZIP file. It is a tar gz file ( TGZ ) which was renamed to .zip just for uploading. It should have been just created as a ZIP file to begin with to avoid this issue. However you should have 7zip installed which will allow you to open tgz, tar, zip....etc. But in this case, you will have to download the file and then rename it back to tar.gz first.

    ONEEYEMAN,

    But my original point is that it does not say "finding all instances of ...."
    It says "Finding copies of ..." When we are trying to debug problems, we must have exact information!

    It would be better if you ran GetLogs.bat from an Administrator command prompt so we can better tell exactly where you are getting to an what error may be occurring. Try the below.


     
  16. ONEEYEMAN

    ONEEYEMAN Corporal

    Kestrel,
    Attached please find the properly archived OTL.txt (using WinRAR).

    Let me know if you have any issues.
     

    Attached Files:

    • OTL.zip
      File size:
      129.7 KB
      Views:
      4
  17. ONEEYEMAN

    ONEEYEMAN Corporal

    Chaslang,
    The very first command: "SN64" ran for a while and then it says:

    This is running it from "Administrator Command Prompt".

    Should I be logged in as "Administrator"?

    Thank you.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that your Windows have permissions changed/set to block access. We will try to run Windows Repair down below to change this.

    No! That will not change anything.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.
    Now after reboot, try running the same steps as requested last time from the Administrator command prompt and tell me what happens this time.
     
  19. ONEEYEMAN

    ONEEYEMAN Corporal

    chaslang,
    I successfully ran the repair and then rebooted.
    However, when I re-run the SN64, I got the same results.

    What else can I do?
     
  20. ONEEYEMAN

    ONEEYEMAN Corporal

    chaslang,
    One more thing.

    After I did all this (today) I tried to run MSVC 2010 Pro. It was stuck on the splash screen for a good 5 min and I had to kill it thru the Task Manager.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note a malware issue and neither is the problem with being able to run MGtools properly. Seems like you have some issues with Windows.

    But let's see if there is anymore junkware to cleanup since you did have some.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    • Reboot your PC after running JRT or after attaching the log, but either way, reboot before running the below scan.
    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  22. ONEEYEMAN

    ONEEYEMAN Corporal

    chaslang,
    Logs are attached.

    However, I don't see there a Digital More, whose advertisements and popups are killing my FF session.

    Thank you.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think you have a few bad addons/extensions hooked into Firefox. It may just be best to reset it to defaults to clear all of this up. See the below


    Reset Firefox to Defaults


    Also delete the below folders if the still exist:
    C:\Program Files (x86)\cOolnccheap
    C:\ProgramData\8625049773777809678
    C:\Program Files (x86)\cheaap4alll
    C:\Program Files (x86)\LighterInit
     
  24. ONEEYEMAN

    ONEEYEMAN Corporal

    chaslang,
    Do you see anything else in the logs?

    Apparently, Digital More was available in the "Tools->Add-On->Extensions". So I successfully removed it from there.

    Hopefully its gone for good.

    Thank you.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not really. Everything else was good.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds