Spigot.A PUP persistent after removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Cunning, Mar 25, 2015.

  1. Cunning

    Cunning Private E-2

    Issue #1 Spigot.A keeps popping up in MBAM sporadically. I scan with MBAM, HitmanPro, RogueKiller, and AVG. I get hits only on MBAM, but they keep coming back after quarantine.

    Issue #2 At startup after the black screen with windows logo (Win7), the system (in what I can only describe as) goes to sleep. The monitor doesn't recognize a connection, nor does the mouse, keyboard, or pojector. It lasts about 2 minutes and then the pretty light-blue loading screen pops up and I enter my pw. Everything is fine. I have looked into the BIOS and chatted with my friend that helped me build this rig, we have no idea why there is a 2 minute dead space at startup. If I need to report this in hardware or software, please let me know, I'm not sure where to post it.

    No TDSS report, nothing was found. If it made a report regardless and you need it, please forgive me, I couldn't locate it. Tell me where it saves to and I will attach it post haste.

    Many thanks,
    -Cunning
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Reset Google Chrome to defaults

    Let me know if that helps.

    Software forum should do. ;)
     
  3. Cunning

    Cunning Private E-2

    Finished the chrome settings reset. I ran MBAM and got the Spigot.A again.

    Issue unresolved :(

    What's next?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Next is:

    Uninstall all of the below using Revo Uninstaller.

    • Google Chrome
    • Google Talk Plugin
    • Google Toolbar for Internet Explorer
    • Google Update Helper

    Now do this... Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. Cunning

    Cunning Private E-2

    Finished uninstalling.

    Ran Getlogs.bat, here is the .zip:
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Google Update Helper <<< Did not uninstall apparently so... let's use
    Revo Uninstaller to do the job.

    Also delete this if it shows:
    C:\Program Files (x86)\Google

    Now go back to installed programs and let me know if Google Update Helper still shows or not.
     
  7. Cunning

    Cunning Private E-2

    I assumed Google Updater had been uninstalled because it doesn't show up on Revo anymore.
    -Screenshot atached.

    I deleted the Google folder in Programs(x86)

    I also ran GetLog.bat again just in case. It is also attached.
     
  8. Cunning

    Cunning Private E-2

    I think I closed the upload window too early, here are the files:
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have seen people have problems like this when using Googles DNS servers. I suggest that you remove the 8.8.8.8 Google DNS server settings and use your ISP's DNS or try switching to OpenDNS and see if that removes your redirection issue. You can always change back if this winds up not being the problem.

    See the below if you don't want to use your ISPs DNS server

    https://www.opendns.com/home-internet-security/opendns-ip-addresses/
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds