Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by orlemanski, Jan 18, 2015.

  1. orlemanski

    orlemanski Private E-2

    I've been having pop-ups, slow processing, browser hijacking, in-text ads, and funny noises from my computer. :cry

    I attached my logs. Please help! Thanks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We need to uninstall your protections software to avoid having them get in the way of our cleanup procedures. So while I finish preparing a fix for you, please start by uninstalling all of the below:

    Avast
    Spybot
    SUPERAntiSpyware

    Then reboot your PC. By the time you do this, I should have posted another message with a fix.
     
  3. orlemanski

    orlemanski Private E-2

    Thank you! I am in the process of uninstalling those that you listed.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50118;https=127.0.0.1:50118
    O1 - Hosts: 54.225.95.126 hjjjegfhiceggepdokloeepnhlfnedkk

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Users\orlemanski\AppData\Local\APN
    C:\Windows\System32\Tasks\SpeedUpMyPC Maintenance
    C:\Windows\System32\Tasks\SpeedUpMyPC Startup
    C:\Program Files (x86)\Browser Warden
    C:\Program Files (x86)\Bench
    C:\Windows\system32\tasks\Safer-Networking
    C:\Windows\system32\tasks\SpeedUpMyPC Maintenance
    C:\Windows\system32\tasks\SpeedUpMyPC Startup
    C:\Users\orlemanski\AppData\Local\Temp\*.*
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Prod.cap]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\speedupmypc]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpeedUpMyPC Maintenance]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpeedUpMyPC Startup]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASMANCS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividMediaBar_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iLividMediaBar_RASMANCS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS]
    [-HKEY_USERS\S-1-5-21-1457024004-3548368242-3248763628-1000\Software\Conduit]
    [-HKEY_USERS\S-1-5-21-1457024004-3548368242-3248763628-1000\Software\ilivid]
    [-HKEY_USERS\S-1-5-21-1457024004-3548368242-3248763628-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKEY_USERS\S-1-5-21-1457024004-3548368242-3248763628-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{78421147-330B-4076-BE93-7F7D204B85B7}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "Tabs"="res://ieframe.dll/tabswelcome.htm"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 
    "ProxyServer"=-
    [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 
    "ProxyServer"=-
    [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 
    "ProxyServer"=-
    [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 
    "ProxyServer"=-
    [HKEY_USERS\S-1-5-21-1457024004-3548368242-3248763628-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NlaSvc\Parameters\Internet\ManualProxies]
    @=""
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet\ManualProxies]
    @=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
    "DefaultConnectionSettings"=-
    "SavedLegacySettings"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxySettingsPerUser"=dword:00000000
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. orlemanski

    orlemanski Private E-2

    Thank you so much. I've followed all of your instructions and attached the logs here. It looks like I'm still getting in-text advertisements. Do I need to do more?
     
  6. orlemanski

    orlemanski Private E-2

    Oops, apologies. Here are the files in case they didn't attach to my last message!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to double underlined keywords seen on many websites where an advertisement comes up when you move your mouse over the keyword? If yes then there is nothing wrong. These are normal sources of revenue that many websites use in order to offset costs of running the free websites.
     
  8. orlemanski

    orlemanski Private E-2

    Thanks for all of the help so far. I'm just wondering if this is all I can do for the virus, or if there are more steps to come.

    At the moment, my comp is still running 40-50 processes in the background (shown when I open Task manager) and I only have chrome and a word doc open.

    :/

    Sorry, I don't know much about these things.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So was my comment about the double-underlined keywords correct?

    You did not have a virus. You just had some junkware.

    This is quite normal.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  10. orlemanski

    orlemanski Private E-2

    Ok, thanks for these final instructions! Your point about the double-underlined text is correct. But the reason I think it is a virus and not just paid advertising is that when I re-install Google Chrome they don't appear. Only after using Google Chrome another 3-4 times does it start to deteriorate and the double-underlined words reappear. Then I just re-install Chrome and start fresh again. Not ideal obviously. But I think things are running a bit better anyway. Thanks so so much!
     
  11. orlemanski

    orlemanski Private E-2

    Chaslang, thanks for all of your advice and instructions. My comp is up and running better than ever.

    One quick thing: I need to re-download a connection to my University's wireless printing network. It seems to have been removed in the in clean-up process.

    I am having trouble tho, and I am wondering if it has to do with a setting on one of the scan/malaware programs I downloaded.

    Here is the website: http://ruwireless.rutgers.edu/?page=printwin

    And when I try to open the .exe file an error message appears that says: "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access them."

    Does this have anything to do with my protection settings?

    Thanks for any thoughts!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    I do not see where anything related to this was removed.

    I don't think so.

    Are you saving the file locally to your PC first? Or are you running it from the download site? Save it to your PC and right click on it and select Run As Administrator. If that does no help then try the below.

    Right click on the file and then choose 'Properties'. In the properties window, at the bottom see if there is a security notice which says "The file came from another computer and might be blocked to help protect this computer". You will also see a 'Unblock' button next to it. Just click on 'unblock' and then 'Apply' and then click 'OK' to close the properties window. Then see if you can run it.
     
  13. orlemanski

    orlemanski Private E-2

    Thanks Chaslang, that worked!!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds