help with malware problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bellyn, Jul 3, 2015.

  1. Bellyn

    Bellyn Private E-2

    Hi,
    My sons laptop started having issues with advert pop ups and redirecting ie to a variety of different sites. His laptop reached the point where it was almost unusable. He uses it for playing games and watching game videos etc.

    I first completed the instructions for fixing redirecting problems, when that failed, I completed the read and run me instructions. There are still advert pop ups and warnings. I have attached the logs, any help would be appreciated.

    Thank you,
    bell.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you deliberately set up to use a proxy?
     
  3. Bellyn

    Bellyn Private E-2

    Hi,
    Im not sure what that is, so I looked it up and I'm still not completely sure. If the laptop is set up this way its been like that since purchase or it could have something to do with my internet provider in Australia.
    Thanks
    Bell
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Bell,

    Uninstall the below softwares:

    • Optimizer Pro v3.2
    • mystartsearch uninstall
    • MyBestOffersToday 027.014010017
    • MyPCBU version 2.25


    Re run Hitman Pro and have it remove everything it finds.

    Also re run Malware Bytes and have it remove all that it finds.

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    • Now re run Malware Bytes again (just a scan) and attach new log.
    • Same for Hitman.
    • Same for RogueKiller.

    Now... Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  5. Bellyn

    Bellyn Private E-2

    Hi,
    I couldn't remove the programs [my best offers and my start search], its saying they may have been uninstalled.

    Im not sure if it's worth mentioning but there are two recent programs I can still see, they're bitmaster and crossbrowse. Bitmaster, desktop search and an unidentified program also run on startup.
    There's also two copies of windows host process rundll32, one copy is in syswow64 and im not sure if this is abnormal, I searched the web and came up with conflicting answers. Sorry if all that is irrelevant :-o

    Other than that the popup and voice adverts are gone and the redirection and freezing is gone. Thank You for the help, I really appreciate it.
    Bell.
     

    Attached Files:

  6. Bellyn

    Bellyn Private E-2

    Hi,
    Sorry to post again but I think I may have run malwarebytes as required previously and missed saving the log. I have run it again and attached the log.
    Thank you,
    Bell
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello Bell.

    Web Companion <<< Uninstall this, if you have issues, use Revo Uninstaller to uninstall it (See further down)


    The Malware Bytes log shows you took no action. Can you re run it again and ensure you have it quarantine all that it finds. Thanks. Once done, rescan yet again and attach a hopefully clean log.


    Re run Hitman Pro and have it fix what it needs to on the "repairs" tab please.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{d925bc12-7440-413e-a040-cef15508f0c5} -> Found
    • [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-2945792797-127565924-3154781707-1001\Software\Microsoft\Windows\CurrentVersion\Run | BitMaster : "C:\Users\oscar b\AppData\Local\BitMaster\bitmaster.exe" -tray -> Found
    • [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-2945792797-127565924-3154781707-1001\Software\Microsoft\Windows\CurrentVersion\Run | DesktopSearch : C:\ProgramData\DesktopSearch\DesktopSearch.exe -ros -> Found
    • [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-2945792797-127565924-3154781707-1001\Software\Microsoft\Windows\CurrentVersion\Run | BitMaster : "C:\Users\oscar b\AppData\Local\BitMaster\bitmaster.exe" -tray -> Found
    • [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-2945792797-127565924-3154781707-1001\Software\Microsoft\Windows\CurrentVersion\Run | DesktopSearch : C:\ProgramData\DesktopSearch\DesktopSearch.exe -ros -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these items on the tasks tab please...
    • [Suspicious.Path] FspXBrf91w.job -- C:\Users\oscar b\AppData\Roaming\FspXBrf91w.exe
    • [Suspicious.Path] HeartRate.job -- c:\programdata\{beaf4177-013a-8175-beaf-f417701305dc}\prsetup (--startup=1 --single) -> Found
    • [Suspicious.Path] SmartEssentials.job -- c:\programdata\{2579bb0c-67a4-1d04-2579-9bb0c67aec31}\download.exe
    • [Suspicious.Path] \\FspXBrf91w -- C:\Users\oscar b\AppData\Roaming\FspXBrf91w.exe
    • [Suspicious.Path] \\HeartRate -- c:\programdata\{beaf4177-013a-8175-beaf-f417701305dc}\prsetup
    • [Suspicious.Path] \\SmartEssentials -- c:\programdata\{2579bb0c-67a4-1d04-2579-9bb0c67aec31}\download.exe

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Use Revo Uninstaller please, hopefully it will show them for you to uninstall.


    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.

    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\Users\oscar b\AppData\Local\Temp.dat
    C:\Users\oscar b\Desktop\BitMaster.lnk
    C:\Program Files (x86)\bd7c9084-db25-41af-8cfc-b14b39e0f53b
    C:\Program Files (x86)\c0cd0cd6-20d3-479f-bcef-9ec003a01921
    C:\Program Files (x86)\fa05769e-650e-4cea-9047-5448609933f8
    C:\Program Files (x86)\iwintoolbarforpogo
    C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
    C:\Windows\tasks\FspXBrf91w.job
    C:\Windows\tasks\SparkTrust PC Cleaner Plus Startup.job
    C:\Windows\tasks\SparkTrust PC Cleaner Plus_sch_9EFC7CA1-1EA5-11E5-828E-F8A9637214FA.job
    C:\Windows\tasks\SparkTrust Registration3.job
    C:\Windows\tasks\SparkTrust Update Version3.job
    C:\Windows\tasks\SparkTrust Update Version3_triggeronce.job
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "BitMaster"=-
    "DesktopSearch"=-
    "Web Companion"=-
    [HKEY_USERS\S-1-5-21-2945792797-127565924-3154781707-1001\Software\Microsoft\Windows\CurrentVersion\run]
    "BitMaster"=-
    "DesktopSearch"=-
    "Web Companion"=-
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Run Ccleaner (not the registry scanner! Just the cleaner itself to be rid of a chunk of temp files.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  8. Bellyn

    Bellyn Private E-2

    Hi,
    I completed all the instructions. Revo didn't show the program my start search, I also used revo to remove coupon version 1.0.

    Everything else went smoothly except rougue killer which failed to remove some detections.

    Thank you,
    Bell
     

    Attached Files:

  9. Bellyn

    Bellyn Private E-2

    I forgot to add that everything is running good. Thank you for all your help.
     
  10. Bellyn

    Bellyn Private E-2

    Hi sorry for posting again but I've started to get dpc watchdog violation warnings on a blue screen and the laptop shuts down. So far this happens when on this site.
    Thanks
    bell.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not topic for the malware forum. ;)

    Re run RogueKiller please. Just a scan, and attach log.
     
  12. Bellyn

    Bellyn Private E-2

    Thanks I think I may have found a solution.

    Would it be ok to use revo to remove these programs:
    host app service, idle crawler, forum terminal.
    Thank You.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, once done reboot the machine and again let me know how things are running.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NO to this one! Windows host process (Rundll32) is a required file for Windows to work properly and yes there should be one copy of rundll32.exe in the system32 folder and another in sysWOW64

    Revo could not remove this anyway because it is not an installed program. It is part of Windows. And you should not be trying to touch it either. ;)
     
  15. Bellyn

    Bellyn Private E-2

    Hi,
    Thank you for the advice.

    I ran rouge killer again and attached the log. I rebooted and everything is running great.
    Thank you for all the help,
    bell
     
  16. Bellyn

    Bellyn Private E-2

    forget the log rolleyes
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  18. Bellyn

    Bellyn Private E-2

    Hi,
    Thank you for your help. This site is great, what you do here is very valuable and selfless, thank you!:) I have made a small donation, hope majorgeeks is around for a long time to come.
    Thanks,
    Bell.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are very welcome, Bell.
    Most appreciated, we thank you! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds