Still infected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ugean, Mar 16, 2014.

  1. ugean

    ugean Private First Class

    Hello,

    Working on my uncles computer here. Don't know how long it has been infected or much about it just that it got to the point it was unusable so he brought it to me. I ran the read&run me first. Hope I did everything right and didn't miss anything. Attached are my logs. Still getting popups every time I click on anything in a browser. Currently using firefox. Also getting fly-in adds. Any help is greatly appreciated. I also do not know what he did to clean it out before I got it.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you deliberately set up to use a proxy?
     
  3. ugean

    ugean Private First Class

    Not that I am aware of. He just has regular DSL.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    Uninstall the below softwares please.

    • SavingsBull
    • VideoPlayer v2.0.6


    Re-run Hitman Pro and have it delete everything it finds.

    Also... on the "repairs" tab, please have it fix the proxy server entry.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [V1][SUSP PATH] AllmyappsUpdateTask.job : C:\Users\Fran\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe - check startup [7][x] -> FOUND
    • [V1][SUSP PATH] SaveSense.job : C:\Users\Fran\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> FOUND
    • [V2][SUSP PATH] AllmyappsUpdateTask : C:\Users\Fran\AppData\Roaming\Allmyapps\Allmyapps.exe - check startup [7][x] -> FOUND
    • [V2][SUSP PATH] GC_Informer : "%LOCALAPPDATA%\GCC\Controller.exe" - --Informer [x] -> FOUND
    • [V2][SUSP PATH] GC_Scheduler : "%LOCALAPPDATA%\GCC\Controller.exe" [x] -> FOUND
    • [V2][SUSP PATH] SaveSense : C:\Users\Fran\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> FOUND
    • [V2][SUSP PATH] UP_Scheduler : "%LOCALAPPDATA%\GCC\Controller.exe" - --Update [x] -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these 2 items under the Browser Add ons Heading.


    • [FF][PUP] 341dg5wb.default-1375622420610 : Special Savings
    • [][PUP] Default : SpecialSavings.com

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - (no file)
    • O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
    • O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
    After clicking Fix exit HJT.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :files
    C:\ProgramData\Allmyapps
    C:\ProgramData\VisualBee
    C:\Program Files (x86)\Advanced System Protector
    C:\Program Files (x86)\Mobogenie
    C:\Program Files (x86)\SweetIM
    C:\Windows\tasks\AllmyappsUpdateTask.job
    C:\Windows\tasks\SaveSense.job
    
    :reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SaveSenseLive.exe]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{891BA19C-CA0B-4C6D-A3E4-D26392FB493B}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BAC8AC11-F4A4-4C1C-B9B7-CFD7D02F5294}]
    
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Re run Malware Bytes and attach the new log for me to look at.
    And Re run RogueKiller, and attach that log too please.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. ugean

    ugean Private First Class

    Sorry it took me so long to run all this. Thank you for the help. I think I ran everything. I'm still getting popups. The only thing I missed was with OTM "Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply."

    I rebooted before copying the results window. Hope this doesn't mess anything up.
     

    Attached Files:

  6. ugean

    ugean Private First Class

    more logs
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just so you know, I haven't looked at the logs yet. Pop ups in which browser please?
     
  8. ugean

    ugean Private First Class

    In FireFox. Take your time. Thank you for the help.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome.

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except we will use Revo Uninstaller rather than the standard method) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bookmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    ==================

    Have the pop ups stopped?
    I want you to rescan with RogueKiller now and attach the new log for me to see please.
     
  10. ugean

    ugean Private First Class

    Ok I haven't used it much but the popups appear to have stopped. Should I be worried about any other browsers? He also has Chrome and IE on this.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I assumed there was only an issue with Firefox. What happens in other browsers? More pop ups? If so which browsers are affected?
     
  12. ugean

    ugean Private First Class

    I haven't used them. I guess I was under the assumption what infected one would infect them all. I'll try to use them a little tonight and see if they have popups too. So far so good with the firefox.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it. Let me know about other browsers tomorrow. :)
     
  14. ugean

    ugean Private First Class

    Chrome is completely broken. I can open it but can't get to any websites. No popups other than these notifications on the side saying I was missing extensions like that savingsbull. Evertime I try to go to a website I get this http://search.conduit.com/
    But it doesn't actually load.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you uninstall Google Chrome using Revo uninstaller and then reinstall it and let me know how it is.
     
  16. ugean

    ugean Private First Class

    I uninstalled and reinstalled it but it still wont go to any websites. The popups are gone though.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you use Revo Uninstaller?

    If the pop up's are gone, then I think you might have to post about this in the software forum.
     
  18. ugean

    ugean Private First Class

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  20. ugean

    ugean Private First Class

    It won't even go to the settings. Same blank page as when I try to go to any sites.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall it again with Revo please, and then do this:

    (Do NOT reinstall Chrome until I say)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  22. ugean

    ugean Private First Class

    ok it is uninstalled and here are the new logs.
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why am I still seeing this installed? :confused

    • SavingsBull
     
  24. ugean

    ugean Private First Class

    Not sure I don't see it in programs anymore
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does Revo see it?
     
  26. ugean

    ugean Private First Class

    no I do not see it there
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, let's do this please:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Next...

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  28. ugean

    ugean Private First Class

    Ok it did it successfully.
     

    Attached Files:

  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Any improvement?
     
  30. ugean

    ugean Private First Class

     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh I'm sorry, yes please do so. :)
     
  32. ugean

    ugean Private First Class

    Nope Chrome is still not working. I talked to my uncle he said he never used chrome. It may not have worked before. He is fine with leaving it uninstalled. Do you think I can go that route or is something deeper wrong?
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, that's fine. I don't like the fact that conduit is tied into it still, but if he really doesn't use it, fair enough. What I do need to know though, is how are OTHER browsers? Is Firefox ok? No more ads? What about IE?
     
  34. ugean

    ugean Private First Class

    Firefox and IE are working fine. No popups, no redirects everything seems fine.

    Thanks
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds