Laptop slow, McAfee keeps popping up warnings. Lots of DLL failures

Discussion in 'Malware Help (A Specialist Will Reply)' started by mondola, Mar 16, 2015.

  1. mondola

    mondola Specialist

    Logs attached, but Hitman Pro keeps hanging at 7%. Even in Safe Mode.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    A lot of junk.

    First, use add/remove programs to uninstall:
    deal4ume
    PriceDownloader
    saVernett
    saviNGtoyou
    Symbaloo
    topbuyoer

    Now rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry : 31 ¤¤¤
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} -> Found
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1} (C:\PROGRA~2\SETTIN~1\smdmf\x64\smdmfbho.dll) -> Found
    [Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | ConvertAd : C:\Users\Marretta\AppData\Local\ConvertAd\ConvertAd.exe  -> Found
    [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3779173747-3284792333-1535095292-1001\Software\Microsoft\Windows\CurrentVersion\Run | ZohecKiqun : regsvr32.exe "C:\ProgramData\ZohecKiqun\ZohecKiqun.dat"  -> Found
    [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3779173747-3284792333-1535095292-1001\Software\Microsoft\Windows\CurrentVersion\Run | {77505B79-CA77-0B73-4F05-CC2645734D22} : C:\Users\Marretta\AppData\Roaming\Ydywi\vufan.exe  -> Found
    [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3779173747-3284792333-1535095292-1001\Software\Microsoft\Windows\CurrentVersion\Run | ZohecKiqun : regsvr32.exe "C:\ProgramData\ZohecKiqun\ZohecKiqun.dat"  -> Found
    [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3779173747-3284792333-1535095292-1001\Software\Microsoft\Windows\CurrentVersion\Run | {77505B79-CA77-0B73-4F05-CC2645734D22} : C:\Users\Marretta\AppData\Roaming\Ydywi\vufan.exe  -> Found
    [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CltMngSvc (C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe) -> Found
    [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\F06DEFF2-5B9C-490D-910F-35D3A9119622 (\??\C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc2.cfg) -> Found
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Users\Marretta\AppData\Local\ConvertAd
    C:\Users\Marretta\AppData\Roaming\Ydywi
    C:\ProgramData\ZohecKiqun
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-1.job
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-11.job
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-2.job
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-3.job
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-4.job
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-5.job
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-5_user.job
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-6.job
    C:\Windows\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-7.job
    C:\Windows\system32\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-11
    C:\Windows\system32\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-2
    C:\Windows\system32\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-3
    C:\Windows\system32\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-4
    C:\Windows\system32\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-5
    C:\Windows\system32\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-5_user.job
    C:\Windows\system32\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-6
    C:\Windows\system32\tasks\d5cf7322-75fb-4ee7-81d9-3c202bbf7ffe-7
    C:\Users\Marretta\AppData\Roaming\BPPRMFF.exe
    C:\Users\Marretta\AppData\Roaming\NXCUKP.exe
    C:\ProgramData\5e4f0e12942d5c26
    C:\ProgramData\6795665835683568678UL
    C:\ProgramData\DealsFactor
    C:\ProgramData\greatsaving
    C:\ProgramData\saveitkeep
    C:\ProgramData\{F66CB4EE-546F-4D54-9332-216DE189AAB0}
    C:\Program Files (x86)\deaal2dealit
    C:\Program Files (x86)\safoerweb
    C:\Program Files (x86)\saveroon
    C:\Program Files (x86)\saviNGtoyou
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ZohecKiqun"=-
    "{77505B79-CA77-0B73-4F05-CC2645734D22}"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "ConvertAd"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "ConvertAd"=-
    [HKEY_USERS\S-1-5-21-3779173747-3284792333-1535095292-1001\Software\Microsoft\Windows\CurrentVersion\run]
    "ZohecKiqun"=-
    "{77505B79-CA77-0B73-4F05-CC2645734D22}"=-
    
    :Commands
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now reboot.

    Rescan with RogueKiller and try to run Hitman. Attach the logs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip
     
  3. mondola

    mondola Specialist

    Thanks!

    McAfee still pops up a warning about Internet Optimizer, and I still can't run Hitman Pro - stops at 9% after saying there are proxy setting set.

    (127.0.0.1:51055)

    Log files attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you attach a log from McAfee?
     
  5. mondola

    mondola Specialist

    Hi there, MGTools Logs and McAfee Logs and output attached.

    McAfee fails to remove Internet Optimizer and the laptop can't connect to the internet.

    :)
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :files
    C:\ProgramData\Internet Optimizer\InternetOptimizer.dll
    C:\ProgramData\Internet Optimizer\InternetOptimizerSvc.dll
    C:\Users\All Users\Internet Optimizer\InternetOptimizerSvc.dll
    C:\ProgramData\Internet Optimizer
    C:\Program Files (x86)\Optimizer Pro
    C:\Program Files (x86)\ver3BlockAndSurf
    C:\users\marretta\appdata\local\temp\nsp8d44.tmp
    C:\Users\Marretta\AppData\Local\StormWatch
    C:\Program F\iles (x86)\Settings Manager\smdmf
    C:\Users\Marretta\AppData\Local\Temp\nsj7179.tmp
    C:\Users\Marretta\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpjkecnjfmgneijfljandenedleocdo
    
    :Commands
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Tell me how that worked.
     
  7. mondola

    mondola Specialist

    Thanks again.

    That seemed to work, and McAfee has calmed right down. Hitman Pro still won't run to completion though and still reports the proxy problems.

    Log attached.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you not get a log from Hitman?

    Now please download OTL by OldTimer.

    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened

    • Attach OTL.txt to your next message. (How to attach)
     
  9. mondola

    mondola Specialist

    No, it just gets stuck (see attached file) and all I can do is cancel it.

    :(

    OTL log attached also.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware.

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :otl
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:51055;https=127.0.0.1:51055
     
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:51055;https=127.0.0.1:51055
    :files
    @Alternate Data Stream - 220 bytes -> C:\Users\Marretta\OneDrive:ms-properties
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista ,Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip
     
  11. mondola

    mondola Specialist

    :hyper

    Logs attached.

    :major
     

    Attached Files:

  12. mondola

    mondola Specialist

    HitmanPro 9% screenshot again:
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. mondola

    mondola Specialist

    Here you go kind sir!

    :cool
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things running now?
     
  16. mondola

    mondola Specialist

    Well prior to running the online scan, McAfee started popping up warnings again, but it seems to have calmed down again.

    There is internet connectivity once again. ;-)

    The browsers are clean once again (following a google chrome reinstall).

    Windows Updates are working and up to date as is McAfee updates once again.

    The mouse keeps getting stuck but it seems to be mostly a function of this laptop being not very fast and so the CPU hits 100% when McAfee live scanner kicks in as it's doing something else.

    So, all in all, it seems pretty good I reckon!

    :)
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds