Rockettab malware removal disables internet browsing

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ent3rpryze, Sep 20, 2014.

  1. ent3rpryze

    ent3rpryze Private E-2

    hi, i've read the malware removal read-me and am currently proceeding as instructed. however, i already know that after running malwarebytes and quarantining the infected files (ie. the rockettab files) my browsers (firefox, chrome, ie) will stop working. i am only able to restore internet connection by restoring the quarantined files.

    with that in mind, how should i proceed? keeping in mind that if i follow the read-me post exactly i will be unable to reconnect to the internet.

    thanks for the help

    edit: attached report log from malaware scan without executing any changes.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just continue on with the other procedures, and once we have all the logs, we will decide what to do. :)
     
  3. ent3rpryze

    ent3rpryze Private E-2

    i'd love to except i wouldnt be able to post the logs after malaware scan and quarantine. should i just do the scans and post the logs without executing any changes?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So just skip the Malware Bytes part for now and do everything else. ;)
     
  5. ent3rpryze

    ent3rpryze Private E-2

    so, i ran the remaining scans as instructed and am attaching the files here.

    thanks again for the assistance.

    nb: MG won't allow me to re-upload the malaware scan log. it is attached in the first post of this thread.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would need to run a new scan! And fix what it finds. Then save a new log to attach. But since you say it disables the internet, just skip it for now.

    Your log from MGtools is very incomplete. Did you have a problem running it? Did you shutdown protection software before running it and did you wait for it to tell you it was finished running before grabbing the log to attach? We need this complete log to continue properly.
     
    Last edited: Sep 20, 2014
  7. ent3rpryze

    ent3rpryze Private E-2

    i reran mgtools until the command prompt window closed on its own. last time i closed it early thinking that it was finished. i hope this is complete.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is still incomplete. The window only closes on its own when something goes wrong. Otherwise it will prompt you to hit a key after it tells you where the log is.

    Did you shutdown protections first?
    Did you disable UAC as requested ?
    Did you use right click and select Run As Administrator ( if running Vista, Win 7, or Win 8) ?
     
  9. ent3rpryze

    ent3rpryze Private E-2

    yes to all of the above. what do i do now?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Interesting! Let's try the below.


    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  11. ent3rpryze

    ent3rpryze Private E-2

    otl scan log up.

    btw, i took a peek at the logs. you guys are superheroes.;)
     

    Attached Files:

    • OTL.Txt
      File size:
      267.1 KB
      Views:
      4
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please begin by uninstalling Avast temporarily. I think it could be causing the problems with running MGtools and also your internet connection issues. We will reinstall it later when finished with your cleanup.

    [b} You need to free up space on drive C as shown by the below. I recommend always having greater than 10% free space.[/b]
    Drive C: | 170.74 Gb Total Space | 6.20 Gb Free Space | 3.63% Space Free | Partition Type: NTFS

    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts.
    • Double-click OTL.exe to run. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    :OTL
    MOD - [2014/09/20 14:47:45 | 001,422,048 | ---- | M] () -- C:\Program Files (x86)\RocketTab\Client.exe
    IE - HKU\S-1-5-21-785746635-2831294751-3954034908-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-21-785746635-2831294751-3954034908-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:49352;https=127.0.0.1:49352
    O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
    [2014/09/20 15:25:53 | 000,000,000 | ---D | C] -- C:\Users\Cubicle\AppData\Local\RocketTab
    [2014/09/20 15:20:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RocketTab
    
    
    :Files
    C:\Program Files (x86)\RocketTab
    C:\Users\Cubicle\AppData\Local\RocketTab
    C:\Users\Cubicle\AppData\Local\Temp\ct2504091
    C:\Windows\System32\Tasks\RocketTab Update Task
    C:\Users\Cubicle\AppData\Local\Temp\SopCast.zip
    C:\Windows\System32\Tasks\RocketTab
    C:\Users\Cubicle\AppData\Local\Temp\*.*
    
    ipconfig /flushdns /c
    
    
    :Reg
    [-HKEY_USERS\S-1-5-21-785746635-2831294751-3954034908-1001\Software\APN PIP]
    [-HKEY_USERS\S-1-5-21-785746635-2831294751-3954034908-1001\Software\Conduit]
    [-HKEY_USERS\S-1-5-21-785746635-2831294751-3954034908-1022\Software\APN PIP]
    [-HKEY_USERS\S-1-5-21-785746635-2831294751-3954034908-1022\Software\Conduit]
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the [​IMG] button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. ent3rpryze

    ent3rpryze Private E-2

    I ran the fix on otl and was prompted to reboot. When windows restarted an error box appeared informing me that rockettab\client.exe file couldn't be found. Ok. Ran the mgtools getlog.bat file and the command prompt window closed on its own again mid scan.

    Opened firefox and I'm getting "the proxy server is refusing connections" error for all tabs. I'm using my phone now to access MG.

    Log files attached.
     

    Attached Files:

  14. ent3rpryze

    ent3rpryze Private E-2

    In case it helpps I screen grabbed the last line of the mgtools command screen before it closes.
     

    Attached Files:

  15. ent3rpryze

    ent3rpryze Private E-2

    also just discovered that when i connect to a proxy via ChrisPC Free Anonymous Proxy the browser can reconnect.

    hopefully the last two posts provide helpful clues.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you using a proxy? It actually looked like you had malware for a proxy which is why I removed it. If you need it then you may have to reinstall it.
     
  17. ent3rpryze

    ent3rpryze Private E-2

    i just happened to stumble upon it here at MG. I thought it would be a simple way to watch jon stewart on comedy central's website. :-o uninstalling now.

    the rockettab trouble started happening several days before i downloaded the proxy. i didn't think it was causing any trouble.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and run Autoruns and keep the Everything tab selected, then slowly scroll down thru the Image Path column. Do you see anything related to this Rocket Tab startup showing up? If you do, you should be able to right click on it and select Delete to stop that error from showing at startup.

    ChrisPC Proxy is not considered malware. But personally I would not want all of my data going thru some one else's networks. You could be routing your data thru who knows where.​
     
  19. ent3rpryze

    ent3rpryze Private E-2

    Under the scheduled tasks tab "rockettab" and "rockettab update task" were found and disabled. After restarting the error box went away but browsers still don't work.
     
  20. ent3rpryze

    ent3rpryze Private E-2

    semi-resolved. i reran malwarebytes and quarantined the remaining rockettab files. browser works again. the only issue i immediately noticed was another error window, screenshot attached.

    assuming i didn't do anything wrong, are there any additional steps i should take to ensure everything is ok?
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a malware problem. You have some issue with Glary Utilities. You can discuss in the Software Forum but perhaps a reinstall will help.

    Just final instructions since malware cleanup is finished.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds