Malware on sons laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BlairC, Jul 17, 2014.

  1. BlairC

    BlairC Private E-2

    My son found quite a bit of Malware on his laptop after running MalwareBytes as I suggested. He bought it to me so I could follow through with cleaning. I have attached the logs as instructed on http://forums.majorgeeks.com/showthread.php?t=139681

    MalwareBytes had already been run by him so I grabbed that original log files. But I think he quarantined all that had been found. Even so the other programs still picked things up so I know some are stubborn and didn't leave so easily, as I told him.

    Thanks in advance for helping!
    BlairC
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below:
    • Conduit Engine
    • PageRage Toolbar
    • Slick Savings


    Please do attach the log from Malware Bytes.


    Re run Hitman and have it remove all that it finds.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Program Files (x86)\ConduitEngine
    C:\Program Files (x86)\GUM4817.tmp
    C:\Program Files (x86)\GUT4818.tmp
    C:\Program Files (x86)\Common Files\Spigot
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Slick Savings"=-
    [HKEY_USERS\S-1-5-21-1580492871-2662071226-1932315236-1004\Software\Microsoft\Windows\CurrentVersion\run]
    "Slick Savings"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F190CAFC-7953-4A43-9CB2-C788C7B47817}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. BlairC

    BlairC Private E-2

    Hi Kestrel,

    I ran the programs and have attached all of the files. I am sorry about the original mbam log not being here. It turns out it was an XML file and never uploaded, so I saved that original from 07.15.2014 as a TXT file and it is now uploaded.

    Thank you,
    Blair
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well damn, pretty much the whole fix didn't take... we'll need to go for a round two.

    None of these were uninstalled. Did you have problems?? Let's try with Revo Uninstaller please.

    Use Revo Uninstaller to be rid of these junk programs.

    • Conduit Engine
    • PageRage Toolbar
    • Slick Savings


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    • R3 - URLSearchHook: (no name) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
    • R3 - URLSearchHook: (no name) - {37153479-1976-43c3-a1ee-557513977b64} - (no file)
    • O2 - BHO: PageRage - {9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
    • O2 - BHO: (no name) - {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} - (no file)
    • O3 - Toolbar: (no name) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
    • O4 - HKCU\..\Run: [Slick Savings] "C:\Users\Brenton\AppData\Roaming\Slick Savings\CouponsHelper.exe"


    After clicking Fix exit HJT.



    Download OTL to your desktop.

    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    
    :files
    C:\Users\Brenton\AppData\Roaming\Slick Savings
    C:\Program Files (x86)\ConduitEngine
    C:\Program Files (x86)\GUM4817.tmp
    C:\Program Files (x86)\GUT4818.tmp
    C:\Program Files (x86)\Common Files\Spigot
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Slick Savings"=-
    [HKEY_USERS\S-1-5-21-1580492871-2662071226-1932315236-1004\Software\Microsoft\Windows\CurrentVersion\run]
    "Slick Savings"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F190CAFC-7953-4A43-9CB2-C788C7B47817}]
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not necessarily true. See the date/time of the logs. Quite a few were not updated.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So what happened to cause this? Hopefully they will be updated this time. I'll pay more attention to time and date stamps.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly not waiting for it to finish running before grabbing the log. Or possibly any number of reasons for GetLogs.bat not running like not using run as admin, protection software running, UAC not diabled. Only the first scan ran ( GetUnKeys.bat )
     
  8. BlairC

    BlairC Private E-2

    Hi Kestrel,

    I do not know why things went awry before. I thought I left every program ample time to complete. The mbam file I had attached previously was the one from the very beginning of it all which had been missed from my original post just in case that is confusing things.

    Anyhow, I ran Revo Uninstaller to be rid of these junk programs but the three mentioned were not there to uninstall.
    Conduit Engine
    PageRage Toolbar
    Slick Savings

    I attached the logs requested from running OTL however I did not get 2 separate log files the first time so I tried it again and got the same thing, only 1 type of file. So I just now attached BOTH just in case its helpful.

    Also attached is the latest MLogs zip file.

    I hope now everything looks clean.

    BVlair
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks Chas.

    Now the logs are looking alot better. How are things running, BlairC? :)
     
  10. BlairC

    BlairC Private E-2

    Yes Kestrel, a lot better with no pop-ups or blocking of downloads to upgrade malware fighting programs like Iobit Malware for instance.

    The rest is cleaning up way too many start up programs and upgrading many that have not been upgraded in a very long time.

    So is it good to go now or are there more steps first?

    Blair
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  12. BlairC

    BlairC Private E-2

    Excellent.

    Thank so much Kestrel and Major Geeks! :major

    Blair
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds