Malware, slow computer, pop-ups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AlisenV, Sep 27, 2014.

  1. AlisenV

    AlisenV Private E-2

    We bought this new Dell Inspiron laptop several weeks ago. My son likes to watch tv and movies on it. I'm not sure where he was finding them, but he has complained that the laptop is useless due to all the pop-ups and other issues.

    I've got the laptop now, and yes it has huge issues. I ran all the try these first, and they are attached to this message. Except the one from TDSSKiller - there was nothing found in that, and hence, no log.

    I know things are still there, because when I started it up the two tabs reading Astromenda Search are back. And I'm sure there's more.

    So - any guidance would be appreciated.

    Alisen
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    Re run Hitman Pro and have it remove all that it finds.



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1202519555-1864347106-1467152891-1001\Software\Microsoft\Windows\CurrentVersion\Run | PeenyBee : C:\Users\andrewvallejo\AppData\Local\PennyBee\PennyBeeW.exe -> FOUND
    • [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1202519555-1864347106-1467152891-1001\Software\Microsoft\Windows\CurrentVersion\Run | PeenyBee : C:\Users\andrewvallejo\AppData\Local\PennyBee\PennyBeeW.exe -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these entries on the Tasks tab please...

    • [Suspicious.Path] UpdaterEX.job -- C:\Users\ANDREW~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    • [Suspicious.Path] WSE_Astromenda.job -- C:\Users\ANDREW~1\AppData\Roaming\WSE_AS~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    • [Suspicious.Path] \\UpdaterEX -- C:\Users\ANDREW~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    • [Suspicious.Path] \\WSE_Astromenda -- C:\Users\ANDREW~1\AppData\Roaming\WSE_AS~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.





    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\ProgramData\c2962e0459e73bca
    C:\ProgramData\GetDiscountApp
    C:\ProgramData\RoyaaLShOOpperrApp
    C:\Program Files (x86)\Optimizer Pro
    C:\Windows\tasks\UpdaterEX.job
    C:\Users\andrewvallejo\AppData\Local\PennyBee
    C:\Users\ANDREW~1\AppData\Roaming\UPDATE~1
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. AlisenV

    AlisenV Private E-2

    Hello and thanks for the quick reply!

    I attach the logs as requested. Everything worked except this part -

    ...and the same for these entries on the Tasks tab please...
    [Suspicious.Path] UpdaterEX.job -- C:\Users\ANDREW~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    [Suspicious.Path] WSE_Astromenda.job -- C:\Users\ANDREW~1\AppData\Roaming\WSE_AS~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    [Suspicious.Path] \\UpdaterEX -- C:\Users\ANDREW~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    [Suspicious.Path] \\WSE_Astromenda -- C:\Users\ANDREW~1\AppData\Roaming\WSE_AS~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND


    Those items were not there on the tasks tab to check.

    Otherwise, everything ran. What I'm not sure about is if all is gone - though the more obvious things are not there.

    I don't think it has anything to do with problems - but there are 4 drives listed on this computer - and since I've never used Windows 8 and have been largely Mac lately I don't know if they are supposed to be there - I attached a screenshot.

    Thanks!
    Alisen
     

    Attached Files:

  4. AlisenV

    AlisenV Private E-2

    One more log
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    RogueKiller still shows these...... so. Let's try again to fix.



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1202519555-1864347106-1467152891-1001\Software\Microsoft\Windows\CurrentVersion\Run | PeenyBee : C:\Users\andrewvallejo\AppData\Local\PennyBee\PennyBeeW.exe -> FOUND
    • [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1202519555-1864347106-1467152891-1001\Software\Microsoft\Windows\CurrentVersion\Run | PeenyBee : C:\Users\andrewvallejo\AppData\Local\PennyBee\PennyBeeW.exe -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...same for these on Tasks tab: (or check reg tab in case they are there)

    • [Suspicious.Path] UpdaterEX.job -- C:\Users\ANDREW~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    • [Suspicious.Path] \\UpdaterEX -- C:\Users\ANDREW~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.







    Can you try and manually delete this please?
    • C:\Users\andrewvallejo\AppData\Local\PennyBee

    ...and this:
    • C:\Users\ANDREW~1\AppData\Roaming\UPDATE~1



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Rescan with RogueKiller and attach log.
     
  6. AlisenV

    AlisenV Private E-2

    Before I proceed any further, neither of the two things you said to look for on the registry are there. I took a screenshot to show you, but haven't done anything further yet.

    There are no items in the Tasks tab.

    The items you ask to manually delete aren't there either - see screenshots

    Thanks

    Incidentally should I turn McAfee back on?
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If all is running well yes. Are there any other problems? Or are you ready for final steps?
     
  8. AlisenV

    AlisenV Private E-2

    Well, it's certainly running better - but as you could see in those screenshots there were still mentions of what appear to be unwanted items. I kind of thought if the system was clean there would be nothing there.

    I'm attaching RK report without checking anything (because the things you said to check aren't there) and I guess you can tell from that?

    Sorry to be so dense...
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Alisen
    The only thing wrong in your latest RK report log.txt is that you didn't install MalwareBytes' to its default location, which is the C:\Program Files (x86) directory.
     
  10. AlisenV

    AlisenV Private E-2

    OK then,Doctor! I guess if all is okay, then I am ready for "final procedures"

    Thanks,
    Alisen
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Very welcome!

    My only aim was to put you at ease about the RKlog.txt. I'll back out now and let Kes continue.

    dr.m
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. AlisenV

    AlisenV Private E-2

    Well, I did the above, made sure mcafee was turned on. Then I opened Chrome to come back here to see what was next and the Astromenda was back. Worse than that, I couldn't get to this page. When I clicked on this box [meaning where I am creating this message] I got porn pop-ups. (I am now using my iPad to type this)

    Obviously it's not clean!

    Is there a next step?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Next step is to create a new thread in this forum, and attach all of the requested logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds