Browser Issues: Malware Issue Files Attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Laney2001, Apr 16, 2018.

  1. Laney2001

    Laney2001 Private E-2

    I'm usually very cautious and consider myself tech savvy but there's always a weak moment. I know exactly when and thought I was wise but I really didn't need to download a copy of Safari for Windows 10 to fix Chrome. Things just got worse!
     

    Attached Files:

  2. Laney2001

    Laney2001 Private E-2

    Adding more files.
    I have followed the Read & Readme first Malware Removal Guide for this issue and successfully for other people in the past. Today, I need help.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please re-run Malwarebytes' and clean all detections - upload a fresh log.

    Next activate Hitman Pro's 30day trial license, then fix the Malware and Potential Unwanted Programs detections. Re-run the tool afterwards and upload a new log.

    Then run RogueKiller and delete all Tasks. Upload the RKreport[2].txt to your next message.

    Tell me how the PC is running, now.
     
  4. Laney2001

    Laney2001 Private E-2

    Creating these files has taken forever, but I've done it.

    Malwarebytes: I believe there were around 500 items in question that were quarantined and deleted.
    Hitman Pro
    : Signed up for 30 days. I had to do 2 reboots/rescans > extra logs.
    RogueKiller:
    This one took soooo long.


    As far as how this computer is running. It's been slower to boot, but I'm not getting the same warnings... Have been working on this much too long today. will see tomorrow if I can evaluate better.

    Thanks for help,
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please follow my instructions more carefully, as the above logs don't show the fixes were performed. Re-scan with those applications and upload only those new logs so I'll know how to proceed.
     
  6. Laney2001

    Laney2001 Private E-2

    I apologize. I will re-scan. I must be more careful with naming the files.
    Chromium browser, which I didn't download popped on start-up even though I believe it's one of the programs than was part of the initial problem. It came up on one of the logs.
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Don't re-name the files - let each program create the filename. I will deal with removing that browser once I have current information. ;)
     
  8. Laney2001

    Laney2001 Private E-2

    I've just gotten back to my computer.
    Here are the files that ran this morning.
    Thank you
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    That looks better - please download and run
    GeekUninstaller 1.4.5.126 to un-install Google Chrome.

    Also to empty your temporary files, click Start/ run and type in
    %temp%
    When the window opens .. click on Edit > select all and then Delete.

    Re-boot and tell me of any other malware issues.
     
  10. Laney2001

    Laney2001 Private E-2

    Have uninstalled Google chrome .
    Deleting temp files I've run into a roadblock with Chromium using files.

    Chromium is not on the list of programs to uninstall. It does not show itself running in task manager either.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    It is listed in your newfiles.txt > Uninstall Programs list. Where doesn't it show? GeekUninstaller? Windows 10's Programs & Features?

    Edit:
    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
      • First press the "Scanner" button. Be patient, the scan may take awhile.
      • Do NOT fix/repair anything yet! Please upload that logfile with your next reply.
     
  12. Laney2001

    Laney2001 Private E-2

    Good Morning,
    MalwareBytes ran this morning & file is attached. Two more files in quarantine. What do I do with all the files in quarantine? Do I delete them?

    Chromium just showed up after the Browser Threat disappeared. It prevented me from deleting files from the temp folder. I could not find "Chromium" in the task manager in order to close it nor was it in the Geek Uninstaller. Nor is it in the Windows10 Programs & Features / Browsers.

    I'm now going to run the Zhpcleaner.
     

    Attached Files:

  13. Laney2001

    Laney2001 Private E-2

    Bon jour
    My French is limited.
    I don't know how to get a file from this program. Here is a screenshot.
     

    Attached Files:

  14. Laney2001

    Laney2001 Private E-2

    I thought "nothing ventured, nothing gained".
    Looked below the screen shot I sent you and thought that perhaps the message might have something to do with this issue.

    Longer than a screen shot I copied the the French text and created a file in Dropbox which I'm able to send you, now, from my tablet.

    Hope this is helpful.
     

    Attached Files:

  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You have this message because you are viewing a ZHPBrowser window as indicated by the first line of text. Please close it and run the ZHPCleaner.exe application - you should see the below GUI. Follow the steps I gave in post #11 to produce a log.
    And yes - have Malwarebytes quarantine the new detections. You can then delete all quarantined items by clicking on "Quarantine" on the Home GUI, ticking the boxes before each item and selecting the Delete button at the bottom right corner. (see thumbnail).

    ZHPCleaner GUI.png Malwarebytes Quarantine GUI.png
     
  16. Laney2001

    Laney2001 Private E-2

    The ZHPbrowser window opens when WHPcleaner finishes leaving the original window behind it. That window is no longer inactive. I've right & left clicked everywhere. That is why I thought the results or log came in the WHPbrowser window.
     

    Attached Files:

  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Again - close that window... perform a system-wide search if necessary for the produced log - ZHPCleaner.txt - it should be in C:\Users\youraccountname\AppData\Roaming\ZHP directory, upload that log please.
     
  18. Laney2001

    Laney2001 Private E-2

    I found it on my desktop and in folder as you suggested. It is now attached.
     

    Attached Files:

  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please re-run ZHPCleaner
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • Then press the Repair button
    • A logfile will automatically open after the scan has finished.
    • Upload that logfile in your next reply.

    Next download Farbar Recovery Scan Tool (FRST) and save it to your Desktop.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run from.
    • The first time the tool is run, it also makes another log (Addition.txt).
    • Attach both logfiles to your next reply.

    *Tell me how your PC is running.
     
  20. Laney2001

    Laney2001 Private E-2

    I Re-ran ZHPCleaner trying to repair but the program had a glitch and stopped running. Got a windows error message. So I just started another scan & repair. This is the result. Looks like it did it's job.

    A logfile did not automatically open. Again I had to search for it.
     

    Attached Files:

  21. Laney2001

    Laney2001 Private E-2

    Your Farbar link is broken at BleepingComputers, but I was able to find the program. Here are the two files.

    My computer seems to be working quite well, thank you.
     

    Attached Files:

  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Thanks -

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.
     

    Attached Files:

  23. Laney2001

    Laney2001 Private E-2

    I discovered that the desktop that I see is not the desktop that my "user" directory has. I knew that the FRST.exe was on my desktop as well as that fixlist.txt because that was where I saved them. But I had to find them using Windows Explorer C:\Users\linda\desktop. Is this one of those peculiarities of Windows 10?

    Anyways here's the fixlog.txt
     

    Attached Files:

    Last edited: Apr 18, 2018
  24. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Perhaps these links will help explain.

    https://answers.microsoft.com/en-us...d-public/377febb8-1238-4a78-baf5-6236cb05df20
    https://social.technet.microsoft.co...-users-desktop-folder?forum=win10itprogeneral

    That completes the malware cleanup -
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8/8.1/10 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work through the below link:
    Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds