just a man asking for some directions toward freedom

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LobLues, Oct 30, 2014.

  1. LobLues

    LobLues Private E-2

    majors,

    they just get better and better. ive checked off the list, and this isn't my first rodeo, but ive never been the clown in the barrel before. feeling very helpless w this issue. "they" have taken over. many thanks ahead of time if assistance is possible. my HJT log is attached, if I added it in correctly. trying to figure out how to copy and save my hitmanpro log as well, as I speak.

    - Lo bLues
     

    Attached Files:

    Last edited: Oct 30, 2014
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. LobLues

    LobLues Private E-2

    ...appreciate you taking a look at my post.

    far as I know, I already went through the list. I was attempting to get the log from Hitman but I cant find the right option to do so & im using the free version which might be why , I was just mentioning my actions atm . last time I asked for assistance w malware issues (couple years back) , it was strictly HijackThis at the time.

    anyway, I did read the "read this first" post on the forum. i don't think I'm missing anything at this point far as what I should have done before I posted on the forum. I'm definitely taking advantage of some of those support options.

    very grateful for this site in general, never failed anytime I had an issue. many times I could have lost very important data if the pro's weren't giving me the input at the time. long as im here im tryna keep up on following the rules & show my appreciation. ive donated to this site in the past, and will continue to do so , but at the moment im wary about any site opened on my laptop...wont do it til I know nobody else is watching :highfive

    thanks again, looking forward to your response!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well if you want me to check for malware it's going to take more than a HJT log. ;)

    I need logs from you running:

    • TDSSKiller
    • Malware Bytes
    • Hitman Pro
    • RogueKiller
    • MGTools

    Fair bit more than you were expecting I guess, but that's what I need. :)
     
  5. LobLues

    LobLues Private E-2

    i stand corrected. i just started running the programs n getting these logs i need. i'll be back momentarily. after looking at the forum a bit i think i have the same com surrogate rundll problem most others are having. i appreciate you taking the time out for me im sure yall are busy at the moment. thank you ahead of time, once this problem is out of my way, i'll be sure to donate to the site. if you (kestrel13) could personally get the donation, i'd be satisfied.

    ...i'll be back momentarily.
     
  6. LobLues

    LobLues Private E-2

    heres the logs. the mgtools program i couldnt get to work at all even after restart. hopefully this helps
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • SN64 <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.


    Attach the MGlogs.zip
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Forgot to say: I think that's wonderful that you wish to donate. :)
     
  9. LobLues

    LobLues Private E-2

    hitmanpro log added. trying your mgtools suggestion now. thank you
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Where did you download this from?

    C:\Users\kiddo\Downloads\FRST64.exe
     
  11. LobLues

    LobLues Private E-2

    the suggestion you made regarding MGtools isnt working for me. i got it to download earlier but it wouldnt "run" . now, when attempting to download mgtools, the DL fails every time n every way i try to make it go through. any way i can get the support i need without mgtools? appreciate your assistance. if it wasnt for this backdoor/trojan/whatever it is etc. i'd have donated already but my research tells me im being watched so i cant do it til its all cleared up. again, if there was a way to donate to you directly, let me know.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    There's no way to donate to me directly. The website as a whole would very much appreciate it though.



    Do this instead of MGTools then:

    Now please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)



    Also answer me about where you downloaded FRST64.exe from, please. ;)
     
  13. LobLues

    LobLues Private E-2

    attaching OLT log now.

    to answer your question, if your talking about the farbar recovery scanner tool...i definitely downloaded it from majorgeeks.com download section. nobody told me to, and i havent actually ran the program. before i posted to the forum i was looking into how to fix it myself n decided not to, leading me back to this thread i started in the first place.
     

    Attached Files:

    • OTL.Txt
      File size:
      200 KB
      Views:
      2
  14. LobLues

    LobLues Private E-2

    omit the last OTL log. im attaching the right one here. goto this one instead of the one i posted earlier. thanks again!
     

    Attached Files:

  15. LobLues

    LobLues Private E-2

    if it means anything ..after further thought, i may have actually loaded the farbar RST file when i first downloaded it . this issue started on the 28th of october it was most likely then. does that change things for me at all ?
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning. :)

    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    [2014/11/02 02:21:03 | 000,000,000 | ---D | C] -- C:\ProgramData\EeyoKuvlu
    [2014/11/01 12:49:01 | 000,000,000 | ---D | C] -- C:\ProgramData\JirxIradp
    [2014/10/28 22:23:02 | 000,001,104 | -H-- | M] () -- C:\ProgramData\@system2.att
    [2014/10/28 22:22:46 | 000,001,368 | ---- | M] () -- C:\ProgramData\@system.att
    [2014/10/26 16:03:06 | 000,000,028 | ---- | M] () -- C:\Windows\SysWow64\u
    [2014/10/26 16:01:43 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\yiqvnim.dll
    [2013/12/23 22:55:57 | 000,000,308 | ---- | M] () -- C:\Windows\tasks\Digital Sites.job
    [2014/10/28 20:40:14 | 000,001,368 | ---- | C] () -- C:\ProgramData\@system.att
    [2014/10/28 20:39:19 | 000,001,104 | -H-- | C] () -- C:\ProgramData\@system2.att
    [2014/10/26 16:03:06 | 000,000,028 | ---- | C] () -- C:\Windows\SysWow64\u
    [2014/10/26 16:01:43 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\yiqvnim.dll
    @Alternate Data Stream - 205 bytes -> C:\ProgramData\Temp:E6E3D650
    @Alternate Data Stream - 163 bytes -> C:\ProgramData\Temp:FB1B13D8
      
    :commands
    
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    • Now re run OTL like you did the very first time, and attach log.
    • Explain how things are running.
     
  17. LobLues

    LobLues Private E-2

    logs as requested. thank you.
     

    Attached Files:

  18. LobLues

    LobLues Private E-2

    also if it means anything , after looking at others posts w/ similar sounding issues as mine, aside from the syswow64 folder in my c:/windows folder, the other significant files i noticed that were never there before are "Tor" related files in just about every folder i open. again, i appreciate your help thus far hopefully im in the right direction w these scans,logs.
     
  19. LobLues

    LobLues Private E-2

    to explain how things are running...

    pc seems to be running smoother, not as many popped up new browser windows, but i still see the rundll32.exe and multiple svchost.exe files in my task manager window. also, windows update isnt working it wont let me update the actual windows update. other than what ive mentioned, i dont know how else to check if anythings wrong besides malwarebytes scans & whatever you tell me to do.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good afternoon.
    Where? I'm not seeing these at all. Can you give an exact file path or zip a file or two up for me and attach it here for me to look at?



    Please let Adwcleaner remove what it finds on a re-run.


    Delete this, let me know if it deletes okay.

    • C:\Windows\tasks\Security Center Update - 608556496.job



    SystemLook

    Please download SystemLook from the FIRST link below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      SecurityCenterServer
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt




    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     
  21. LobLues

    LobLues Private E-2

    it was earlier this morning when i first started doing what you asked w/ the windows repair and systemlook etc. im pretty sure i either deleted the file you mentioned, or the file wasnt there at all, if my memory is serving correct. the "tor" files i mentioned, when going to look, the first one i found was in c:\programdata & the files are named "decrypt_installation" , "Install_TOR" , and "wrnhoah.tmp" ...any folders files like this are in, have the same couple of "TOR' related files. before i started doing all these scans it was more prevalent, but its still there. almost like when it started, this "TOR' fileage was bound to every folder.

    hope im on the right track, and thanks again !
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    I'm afraid it sounds like you have been infected by a ransomeware infection called cryptowall. There is nothing that can currently be done to reverse the effects of this. I am so sorry we spent days on this without me noticing. :(

    Please see this article.
     
  23. LobLues

    LobLues Private E-2

    long as im infected with ransomware, and i can still use my pc....what exactly do i need to worry about? my latest malwarebytes scan and spybot came up with nothing whereas before there were trojans/backdoors listed. also, before i asked for help in the forum, i had deleted something in my control panel/user accounts&family safety/credential manager .

    there was a login/password generated in the credential manager that would pop up in the generic credential window and would come back upon restart. eventually it didnt come up and hasnt since. i imagined that was the "allowed gateway" into my computer that the hackers would use? am i understanding any of this wrong? basically im wondering how my pc is now at risk & based on what i've mentioned, maybe i can live with it for now ? if i backup my data , far as downloads that arent trojan bound, will they come up again if i put them back after a reformat? ( if i have to )

    thanks for all your help .
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    @Kestrel13!, The initial logs showed signs of Poweliks. I suggest that you run a scan with FRST in normal boot mode and get the FRST.txt and Addition.txt logs.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks Chas, you're right, I some some similar files which seem to be connected to poweliks. I also neglected to get them fixed with RogueKiller.
     
    Last edited: Nov 7, 2014
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No Kestrel13! That is the wrong way to run FRST for Poweliks. See my threads. Also I sated in my last message " in normal boot mode ". :)
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I know how to run it, I don't know why I laid that boiler plate down!

    Sorry Loblues... do this instead please and disregard my previous FRST instructions.

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds