privitiseVPN and safesaver plugin removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by catspaw, Jul 25, 2013.

  1. catspaw

    catspaw Private E-2

    Hello,

    I am having problems with my firefox browser and internet connection that I believe are related to "privitiseVPN" - I did not download this, I suspect my son would of when using the computer to play games.

    I have carefully followed the instructions for Windows XP malware removal to step 3 - but I can tell this malware is still on my system.

    I am getting rogue ads on webpages from a "safesaver plugin" - rogue ads as popups - rogue ads on mouse rollover of suspect links while browsing- and the internet and wifi connections crash intermittently. One of my search engine options on firefox is "Search the web (privitise)".

    Attached are the log files from the scans performed.

    Thankyou in advance!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue, you need to use MSCONFIG to put the machine into normal start up mode.


    Delete this folder:
    C:\Documents and Settings\Cate\Local Settings\Application Data\Babylon



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.iprimus.com.au:8080

    After clicking Fix exit HJT.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )


    Now re run RogueKiller, just a scan and attach the log please.

    Describe how things are running.
     
  3. catspaw

    catspaw Private E-2

    Thanks so much for responding Kestrel13!

    I have followed your instrustions:
    1. Ran msconfig to put my computer into normal start up mode
    2. Deleted the Babylon folder as instructed
    3. Disabled my AVG antivirus
    4. Ran Hyjackthis and fixME.reg as instructed
    5. Then ran JRT and Roguekiller scans - files attached

    the privitise Search engine is now removed from my search engine options in firefox - and firefox settings appear to be reset to default

    however the safesaver plugin ads still appear on websites i.e. there is one their banners on the google start page, and facebook

    also new windows/tabs still appearing with rogue ads

    so making progress but there is still malware there

    cheers,
    Cate
     

    Attached Files:

  4. catspaw

    catspaw Private E-2

    privitiseVPN is still on my machine...

    while away from the computer, waiting for further instructions, wifi connection on our devices again disconnected

    on the computer privitiseVPN appears to be attempt to dialup a connection (see attached screenshot) and the internet connection had also failed

    so no improvement really
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this 1 detection:

    • [PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Has that done the trick?
    Rescan with RogueKiller and let me know whether that entry reappears.
     
  6. catspaw

    catspaw Private E-2

    Hi,

    Run Roguekiller but could not find that entry - see attached

    Also have attached the RK log

    Cheers,
    Cate
     

    Attached Files:

  7. catspaw

    catspaw Private E-2

    Rebooted computer and ran RK again, found that entry under the 'Proxy' tab NOT the Registry tab - should I delete it from there?

    see attached jpeg + RK log

    Cheers,
     

    Attached Files:

    Last edited: Jul 25, 2013
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, go ahead! :)
     
  9. catspaw

    catspaw Private E-2

    just woke up, got my coffee, read your post, ran RK, highlighted the ProxyEnable key and hit delete - forgot to uncheck the items under the registry tab ..... grrrrr@myself

    RK logs attached - 2 from before computer reboot, and 1 after

    ProxyEnable key is still there
     

    Attached Files:

  10. catspaw

    catspaw Private E-2

    OK - I decided to read the RK tutorial and this time hit the 'Fix Proxy' button instead of the 'Delete' button - appears to have done the trick

    RK logs attached: 2 before reboot and one after
     

    Attached Files:

  11. catspaw

    catspaw Private E-2

    still have rogue ads opening in new windows though
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which browser do you have excessive pop ups appear in?
     
  13. catspaw

    catspaw Private E-2

    Firefox - the ads open up in a new window when I open the browser. They also appear embedded in websites I visit - see attached jpegs. The Ads are labelled "ads not by this site" and are from the safesaver plugin.

    I don't use IE - but just tried it out and did not see any ads appearing there.

    But it does seems that the connection issues I was having are solved - we are not being bumped off the internet as before.

    Cheers,
    Cate
     

    Attached Files:

  14. catspaw

    catspaw Private E-2

    looking at my firefox plugins, the only suspect one I can see is

    Pando Web plugin 1.0.0.1
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall it and see if there's any difference.
     
  16. catspaw

    catspaw Private E-2

    Success

    Uninstall the Pando Web plugin from Control Panel - Add/Remove Programs, however that didn't remove the ads.

    Discovered an extension in Firefox called 'Maagniiipiiic' or something like that, an obvious derivation of Magnipic that I know is associated with PrivitiseVPN. I disabled this and the ads are now gone.

    Yay!

    Thanks heaps for your help
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it's all back to normal. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. catspaw

    catspaw Private E-2

    No more issues and have done the clean up

    Thanks so much Kestrel13! - you are awesome

    :)
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Between us, we got there. ;) Take care and safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds