Pls Help. Ads in background. Logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ComputersH8me, Apr 9, 2014.

  1. ComputersH8me

    ComputersH8me Private E-2

    Hello. Although I try to be super careful on my computer, I have apparently caught that ads in background malware. I have followed the instructions in the read & run me first thread. Unfortunately, the problem still exists. :(

    Some notes I took while running the programs:
    RogueKiller - found and killed [termproc] svchost in c:\windows\system32\svchost.exe

    Malwarebytes - I followed instructions to the letter, but found it interesting that we weren't checking scan for rootkits. Anyway, I did everything as specified. It did not find anything, although ironically, the ads were playing in the background as it ran.


    I would be most grateful for any assistance. My computer is incredibly slow because of this issue, and actually rebooted by itself while I tried to create this thread.

    Logs are attached.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    We still need to see the MGlogs.zip from running MGTools.exe please.
     
  3. ComputersH8me

    ComputersH8me Private E-2

    Ugh. I was so proud of myself for being thorough and I still messed up. Sorry about that. Here is the mg zip.
     

    Attached Files:

  4. ComputersH8me

    ComputersH8me Private E-2

    Additional info:
    I was rebooting my computer and this junk started before I even logged into windows this time. Not sure if that helps with the troubleshooting, but I thought I'd list every piece of info I can.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :files
    C:\Windows\SysNative\cwubo.wbw
    C:\Windows\SysNative\hufqdbf.wrd
    C:\Windows\SysNative\wtan.lqr
    C:\Windows\SysNative\zuhbum.rrb
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.





    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. ComputersH8me

    ComputersH8me Private E-2

    Hello,

    thanks for the tips. I attempted to run the steps you indicated. And I made sure I had account access off and my mcafee scanner and firewall off. OTM ran with no problems. When I ran JRT, it had an error pop up.

    error saving file
    c:\windows\erunt\jrt\bcd !
    continue with the next file?
    [regcreatekey ex: 5 - access is denied]

    In fact the error popped up a few times because after clicking yes to continue it was the same message with a 7 instead of a 5. The program seemed to run though.

    Unfortunately, the problem still exists, although I am not hearing the ads as often. In fact, I thought the issue had been cleared up, but then the next time I booted up, I heard the ads.

    this seems to be a very insidious malware. Sometimes I feel like my computer is running okay. It doesn't play ads, and it doesn't seem overly slow. Other times, it's either playing ads/being slow, or just being painfully slow.

    I am attaching the 3 logs. I hope there are some other things we can try. I am sorry my computer is still a problem. I know it's a lot of work helping others out with their problems, but rest assured it is most appreciated. Thank you!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Stubborn... does Mcafee not detect these?

    Please download Combofix to your desktop. Please refer to these instructions prior to running my script below.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    File::
    C:\Windows\SysNative\cwubo.wbw
    C:\Windows\SysNative\hufqdbf.wrd
    C:\Windows\SysNative\wtan.lqr
    C:\Windows\SysNative\zuhbum.rrb
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. ComputersH8me

    ComputersH8me Private E-2

    I have one question about the latest instructions.

    For my McAfee, I have turned off the firewall and the realtime scanning, is that sufficient? It still shows up in the system tray on start up, but I don't think it's doing anything other than loading the security center interface. Is that okay, or do you think it interfere with the programs you wish me to run?

    I don't see a way to turn that off.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Find the red "M" icon for the McAfee anti-virus program in the system tray and right-click it.
    • Look for an option in pop-up menu that says either "Exit" or "Disable" and click on it.
    • Click "Yes" when asked if you are sure you want to disable the McAfee anti-virus program. Double-click on the McAfee desktop icon or re-start the computer entirely to enable the program again.
    • Locate the red "M" icon in the system tray at the bottom-right corner of the desktop. Double click on it to open the Security Center program.
    • Click on the "Advanced" tab and then choose the option labeled "Configure."
    • Click on the "Files" button on the top toolbar. Click on the "Disable" button at the center of the screen.
    • Enter in a time for the program to automatically turn back on in the text field at the right or restart the computer to turn McAfee Security Center back on.
     
  10. ComputersH8me

    ComputersH8me Private E-2

    I ran the combofix per your instructions and I did receive a few errors similar to what I indicated in an earlier post in this thread. They are along the variety of:

    error saving file
    c:\windows\erdnt\hiv-backup\bcd!
    [regcreatekey ex: 5 - access is denied]

    The program did seem to run when I acknowledged the errors, although I don't know if it ran completely or properly given that it couldn't save 7 things it was trying to. At any rate, the mgtools log is is attached.

    I did try to complete you mcafee instructions before running combofix. Unfortunately, when clicking the red M, there was no option to exit or disable it. All I can do is open securitycenter, check for updates, scan, or change settings. I picked change settings, but it just gave me the options to do the same things I already completed (disable scanning and the firewall).

    I would hate to have to remove mcafee from my machine, as I am not sure I could ever find the program I had (I've had it for years, updating the definitions of course, and paying for my subscription). Do you think I need to?

    Again, my continued apologies for the errors and inability to run things exactly as detailed.
     

    Attached Files:

  11. ComputersH8me

    ComputersH8me Private E-2

    Sorry if this is a duplicate post...my browser seemed to crash on me when I was posting.

    I ran the combofix per your instructions and I did receive a few errors similar to what I indicated in an earlier post in this thread. They are along the variety of:

    error saving file
    c:\windows\erdnt\hiv-backup\bcd!
    [regcreatekey ex: 5 - access is denied]

    The program did seem to run when I acknowledged the errors, although I don't know if it ran completely or properly given that it couldn't save 7 things it was trying to. At any rate, the mgtools log is is attached.

    I did try to complete you mcafee instructions before running combofix. Unfortunately, when clicking the red M, there was no option to exit or disable it. All I can do is open securitycenter, check for updates, scan, or change settings. I picked change settings, but it just gave me the options to do the same things I already completed (disable scanning and the firewall).

    I would hate to have to remove mcafee from my machine, as I am not sure I could ever find the program I had (I've had it for years, updating the definitions of course, and paying for my subscription). Do you think I need to?

    Again, my continued apologies for the errors and inability to run things exactly as detailed.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  13. ComputersH8me

    ComputersH8me Private E-2

    Hello.

    I didn't see the exact mcafee options, so I just removed it from my system and rebooted. I have rerun combofix per instructions (interesting, I got the same errors as I reported in my earlier post in this thread despite not having any virus protection software at all).

    Anyway, The mgtools log is attached. I could not find anything named combofix.txt.

    Please advise.

    Also, if you want me to start over with the first steps now that I don't have any virus protection, let me know that as well. Thanks!
     
  14. ComputersH8me

    ComputersH8me Private E-2

    Sorry, I forgot to attach the log. here it is.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. Now that you have Mcafee removed, just try again to run the combofix script. If you have a problem with it again or it does not produce a C:\combofix.txt post back and let me know.
     
  16. ComputersH8me

    ComputersH8me Private E-2

    I reran the win 7 read and run me 1st, as well as the programs indicated in other posts in this thread with NO virus protection programs running. Unfortunately, I am still hearing the ads. I'm attaching the logs.

    Could the failure have anything to do with the errors combofix is giving? It seems like it's not being allowed to do something.

    At any rate, I appreciate the continued assistance...
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes the malware is probably blocking us.

    Are you able to see these files? Are they visible to you? Are you able to delete them? Let me know. I will try running another tool if they fail to delete manually.

    • C:\Windows\SysNative\cwubo.wbw
    • C:\Windows\SysNative\hufqdbf.wrd
    • C:\Windows\SysNative\wtan.lqr
    • C:\Windows\SysNative\zuhbum.rrb
     
  18. ComputersH8me

    ComputersH8me Private E-2

    Hello.


    I can't seem to find the sysnative folder at the path you indicated. When I do a general search on sysnative. I see a couple instances of it from OTM (see screenshot).

    I therefore ran a search and I was able to find cwubo.wbw and hufqdbf.wrd from the search window. I right-clicked them and selected delete and my computer put them in recycle bin (which I then emptied).

    When I rebooted, however, they seem to still be there. :( (see screenshots).

    As for wtan.lqr and zuhbum.rrb, I can see them but can't delete them (see screenshots for locations, even when booting in safe mode. The computer says they are open in the DCOM Server process launcher.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What happens when you just try to right click on combofix.exe and run it as admininstrator? Does the program start to run?

    Next try this:

    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. ComputersH8me

    ComputersH8me Private E-2

    Hello.

    I downloaded and ran the avenger per instructions. My machine did tell me the 1st stage was completed and that it wanted to reboot, which I let it. I didn't see anything running when it rebooted, and I don't see any log in my c: drive. (even when running a search on *.txt since I wasn't sure what the log would be named).

    As for your other question about combofix. When I run it as administrator, I'm getting a series of errors along the lines of:

    error saving file
    c:\windows\erunt\jrt\bcd !
    continue with the next file?
    [regcreatekey ex: 5 - access is denied]


    when I click ok, then usually another location such as c:\windows\erunt\jrt\sys ! or something like that will show.

    In other words, it looks like there are usually about 7 files combofix is trying to edit/create that my machine won't let it do. After clicking through the error messages, the program does run. I wonder if it is really doing anything if it can't edit/create those files, however.

    I'm hearing the ads as I type this, so the malware is definitely still present.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Right, let's do this:

    [​IMG] For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  22. ComputersH8me

    ComputersH8me Private E-2

    Hello there.

    Sorry for the delay. I was out of town. I will purchase a flash drive today and complete your instructions. I'll report back tomorrow.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, I'll be here. :)
     
  24. ComputersH8me

    ComputersH8me Private E-2

    Hello.

    I ran farbar recovery scan tool. Log is attached. Thanks!
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another fix will be needed after the below because your rpcss.dll system file is infected and will require replacement from a backup. As part of the below fix, it will search your PC for backups that can be used.


    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
     
  26. ComputersH8me

    ComputersH8me Private E-2

    Hello.

    I saved the fixlist.txt to my flash drive and ran frst64 through system recovery options as specified.

    frst64 ran and produced a log to the flashdrive, and I then selected reboot.

    Windows no longer seems to boot up. the Machine goes through the post and bios, and when trying to boot normally, the windows splashscreen comes up and later disappears, but it never gets to the desktop (even just letting it sit on the blackscreen for 5 minutes or so).

    I also tried booting to safe mode with networking, and even that didn't come up. I jumped on my laptop so I could reply here. I am attaching the log produced by frst64 to my flash drive.

    My apologies for the continued trouble. I very much appreciate the assistance you both are giving me.
     

    Attached Files:

  27. ComputersH8me

    ComputersH8me Private E-2

    Just wanted to update my thread to indicate that I tried to have windows repair it's launcher or whatever, as when I tried to boot again this morning, it asked if I wanted to have it to try and fix itself.

    I did NOT have it do a system restore. I said no to that option.

    It did not work. Situation is the same as I detailed in my post yesterday.

    Understand you guys are really busy. Not nudging. Just wanted to update with an additional action I took since yesterday. Many thanks for the assistance.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! That's strange and very unexpected. Sorry about this.

    The search option for the problem system file did not work. Please try the below.

    Run FRST as you previously ran it by booting back into System Recovery Options and run FRST.

    Type the following in the edit box after "Search:".

    rpcss.dll

    Click Search button and post the log (Search.txt) it makes to your reply.
     
  29. ComputersH8me

    ComputersH8me Private E-2

    Hi there.

    No need to apologize. I'm grateful for the help I've been given. I ran frst and searched for the rpcss.dll. Log is attached.
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Can you run FRST again as you did in post #24 and attach the log please?
     
  31. ComputersH8me

    ComputersH8me Private E-2

    Hello,

    Post #24 was a response from me, so I was momentarily confused. I first ran the process detailed in post 21, before realizing that you probably meant run the instructions from step 25.

    So, my activity for this morning includes running the steps in both post 21 and 25 (sorry for redoing 21 again, I was confused). At any rate, I can't get a mglogs for you as I still cannot boot windows. I haven't been able to boot to my desktop (normal or safe) since last friday. When I try either of those options, once the windows splash screen ends, I just hang at a black screen...and I've let it sit for 10 minutes or so.

    I am attaching the logs from frst that were saved to the flash drive...

    Thanks for your continued support. I know you'll be as glad as I am when this nightmare is over, lol. I appreciate the help.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the rpcss.dll file appears to have been replace with a good file now so that was going to be my next step to replace it. But it is not necessary now.

    Per you FRST logs, you have the below System Restore points:
    Try booting your PC into the recovery environment again but this time do choose to do a System Restore. Try the 2014-04-10 restore point first. if it fails for some reason, try it a second time. If it fails a second time, try the 2014-04-01 restore point.​
     
  33. ComputersH8me

    ComputersH8me Private E-2

    Hello,

    Success! I was able to restore to 4/1/14, and can now boot to my desktop. Thanks to all who helped! I really appreciate it.

    I do have a few questions:

    Can my computer be trusted now? I'm really paranoid after my computer being so infected. With all of the various programs and fixes you guys guided me through, plus the system restore, is there anyway some other sort of incidious stuff (keyloggers or the like) can be hiding anywhere? I see the OTM icon on my desktop, which we put on there during the troubleshooting, and this surprises me as I thought system restoring back to 4/1 would remove all programs installed after 4/1. (sorry for my ignorance if I"m wrong.

    I suspect the answer is no, but I'm looking for piece of mind :) I'm afraid to log into my email, facebook or any other place that might give nefarious types sensitive information.
     
    Last edited: Apr 22, 2014
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You could go through the complete Read and Run Me First procedures again, attach the logs and we'll take a look! :)
     
  35. ComputersH8me

    ComputersH8me Private E-2

    I ran the read and run me 1st and cleaning process for win 7 again. I don't think I'll ever be free, lol.

    roguekiller definitely found some stuff, but per instructions I didn't fix anything. Just ran the scan.

    hitman pro may have found some stuff, but the background of the scan results wasn't red, so maybe it was innoculous stuff.
    not sure if the others found anything.

    At any rate, logs are attached. I'll await instructions. Thanks for the continued help.
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent news on the System Restore working. ;) Even better is that the restore did not bring back any of the serious malware. Only some minor junk.

    Nope. All okay.


    Yes just some junk that will require running some repeat steps. I will have you download OTM and JRT again just in case you lost them during the restore.


    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java(TM) 7 Update 4

    Now install the current version of Sun Java from:

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Users\Sucker\AppData\Local\Temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\secman.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secman.OutlookSecurityManager.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\secman.OutlookSecurityManager]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\secman.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  37. ComputersH8me

    ComputersH8me Private E-2

    Hello there,

    Glad there wasn't any bad stuff, but that surprises me. I guess I just don't understand what things mean :) I was just concerned when I saw these items through roguekiller:

    [HJ POL][PUM] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
    [HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
    [HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> FOUND
    [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableTaskMgr (0) -> FOUND
    [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
    [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> FOUND
    [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND.

    I thought for sure they were bad things, but I think I'm just gun-shy and paranoid these days. I ran OTM, JRT, and MGTools. Logs are below.

    Let me know what, if anything, is next, and again, I can't say thanks enough.
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    All normal changes that most people make. PUM does not mean it is malware. PUM means Potentially Unwanted Modification. This simply means it has changed from the Windows default when Windows is first installed. If you are like me and almost every other person, you modifiy settings to suit your needs. Thus these are modifications to defaults. Basically RogueKiller is just providing a warning that they have changed so that you can react to them if you did not make the changes and also it can show when the modifications are really a problem due to malware having made a change.

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  39. ComputersH8me

    ComputersH8me Private E-2

    Just wanted to say thanks for all the help with my malware problem. It's been a few days, and things are running well.

    I will definitely make a donation come pay day. Thanks for all of the help!
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) We very much appreciate your desire to donate.
     
  41. ComputersH8me

    ComputersH8me Private E-2

    Sorry to resurrect this thread, but I wonder if my latest problem may be related to my recent malware episode...

    I tried to get the windows IE update, and windows updates seem to fail now. I am getting error code 80070216. When trying to review the net for this issue and why it happens, a couple of hits on my search results seemed to be related to the ads in background malware.

    Sorry to ask for more help, but can anyone please tell me how to fix this issue?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's take a look to see if anything came back.


    Please run the below anti-rootkit tool from Malwarebytes.
    • Download Malwarebytes Anti-Rootkit
    • If you happened to get a ZIP file version instead of an EXE file then unzip the contents to a folder in a convenient location.
    • Open the folder where you saved Malwarebytes Anti-Rootkit to. Now run mbar-1.07.0.1009.exe ( If running Vista, Win7 or Win 8, use right click and Select Run As Administrator )
      • Note: This filename will change as new versions are released, so this is just an example ).
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
      • Internet access
      • Windows Update
      • Windows Firewall
    • If there are additional problems with your system, such as any of those listed above or other system issues, then run the 'fixdamage' tool included with Malwarebytes Anti-Rootkit and reboot.
    • Verify that your system is now functioning normally.
     
  43. ComputersH8me

    ComputersH8me Private E-2

    Thanks for the quick reply. I ran the malwarebytes rootkit (with virus protection off). nothing found.

    Windows update is still failing, and IE is also running quite slowly.

    I am not hearing ads, and in general, the system seems to be working okay (except for the aforementioned windows update and IE stuff).

    Any ideas? And again, sorry to be a thorn in your side again.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Most issues with Windows Updates are related to Windows problems. Let's give the below a run and see if it helps. If not, I will probably send you to the Software Forum.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     
  45. ComputersH8me

    ComputersH8me Private E-2

    Same problem after running windows repair. As before, windows update finds the updates, but when it tries to create a restore point before installing, it fails.

    Since the logs you had me create looked clean, I guess the situation is that I no longer have malware, but perhaps some functions have been corrupted/disabled, is that correct?

    How do you think we should proceed?

    thanks!
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Correct and it is possible that malware was not the cause too.

    I suggest that you uninstall ALL of McAfee and then reboot. After reboot, also run the below just to be sure it is gone.

    http://www.majorgeeks.com/files/details/mcafee_consumer_product_removal_tool.html

    Then rerun the Windows Repair program and then run the below FixIt tool from Microsoft

    http://support.microsoft.com/mats/windows_update/

    Then reboot again and try Windows update again.

    If it still does not work then reinstall your protection software and post in the Software Forum for help with Windows Update.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds