Qytrew Back Again!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ventanias, Jul 2, 2020.

Tags:
  1. Ventanias

    Ventanias Private E-2

    Hello all

    Need help with this virus. It's inside the bloody PC and won't get out. Cleaned with all available tools - SpyHunter, Rogue Killer, nothing works.

    It has an erratic behaviour, either opens one new browser window or 7 or whatever, at irregular intervals. also show up when using Office. It prints QYTREW in Word and alters the text format....and opens new windows. a drag.

    How can I clean this mess without having to format C:?

    Windows 10 (2020)
    Intel Xeon

    Thanks all
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow the Read and Run First Instructions and attach the requested logs.
     
  3. Ventanias

    Ventanias Private E-2

    Here it goes. Nothing suspicious. But QYTREW is still inside. I'm attaching a Malwarebytes repost also
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach ALL the requested logs.
     
  5. Ventanias

    Ventanias Private E-2

    Hitmanpro states "Inicializing" but doesn't scan. I'll keep trying and will post if it does scan
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to remove all your Temp files. What browser are you using when this happens? I see you have Zemana installed....have you run it to get a log?

    I would like you to run one more scan:
    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  7. Ventanias

    Ventanias Private E-2

    Thanks Tim (Palpatine)
    I have no idea what Zemana is. I'm using Microsoft Edge. Uninstalled Chrome and Firefox.

    Hitmanpro started, went to 99%, only discovered itself and doesn't finish... I also can't close HMpro without opening task manger and killing the process there...

    Reports attached
     

    Attached Files:

  8. Ventanias

    Ventanias Private E-2

    Hitmanpro say the Trial has expired so it doesn't pass to the Log page...I'll uninstall and reinstall maybe?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK....first, please run CCleaner to remove any leftovers from Chrome and Firefox. Then when you have finished that ( Make the back up when prompted for the Registry cleaner ) do the following:

    Restore Default Settings in Microsoft Edge
    Launch Microsoft Edge and then click the More Actions menu then click Settings.

    reset edge 1
    Scroll down to Clear browsing data then click Choose what to clear.

    By default, Browsing History, Cookies, saved website data, and Cached data files are checked, but you can choose from additional data options in the list. The Show more collapsed menu reveals other options to select.

    To reset the entire browser, check all options, then click Clear.

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    Next, reboot!!

    Now please run this:
    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't bother....we will work it another way. :)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this a desktop computer? IF so, just for the halibut, do you have a spare keyboard you can try??
     
  12. Ventanias

    Ventanias Private E-2

    No, sorry, just this HP keyboard. I can't find any fixlist.txt so. So far I got these. FRST64.exe doesn't reboot or fix anything. what am I missing?
     

    Attached Files:

  13. Ventanias

    Ventanias Private E-2

    Also these...all form today, 07/07/2020
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The Fixlist.txt is at the bottom of my message #9. I will attach it again. Please go back to message #9 and repeat the instructions. ( I just want to know that you ran CCleaner ).

    Yes....rerun Zemana...and please try to find another keyboard to try.

    What do you use FEEM for? Are you sharing files with someone?
     

    Attached Files:

  15. Ventanias

    Ventanias Private E-2

    Sorry, didn't see it. Can't recall why I installed FEEM so uninstalled it. Rerun Zemana. it cleaned Hosts file.
    Sending Fixlog.txt and Zemana report from 16:20 local time
    Rerun CCleaner.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK.....please tell me how things are running now.
     
  17. Ventanias

    Ventanias Private E-2

    What was this GWXTriggers?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sorry.....what?
     
  19. Ventanias

    Ventanias Private E-2

    In the fixlist.txt file:
    fixlist content:
    *****************
    Start
    GroupPolicy: Restriction ? <==== ATTENTION
    FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    Task: {C9F44F7D-F4B5-4F2D-AC3A-E03EB2CB6266} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {D9403BB3-EC65-4130-8458-9AEF1124AC02} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    ...
    what were these \GWX and \GWXTriggers directories?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  21. Ventanias

    Ventanias Private E-2

    No sign of QYTREW so far...Thanks TIM!
    Where was it hiding, any idea? what did it change, the policies? the Hosts file? (didn't look there before asking for help....)
     
  22. Ventanias

    Ventanias Private E-2

    Looks like it's still here....just opened a few Edge windows with REW written. Interesting enough, it opens the same URL's from time to time...
    Another idea, can it be hiding in Edge Chromium extensions?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I gave you instructions to totally reset Edge. Did you follow them?
     
  24. Ventanias

    Ventanias Private E-2

    Yes, first thing. I'll reset again.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Choose the everything option, please.
     
  26. Ventanias

    Ventanias Private E-2

    I did. Can it be an extension? it first showed up with google Chrome so I uninstalled it. Can I install chrome again and use my Google account?
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes. It very well could be an extension. What google account? Gmail? I am confused. ( I would still be very interested to see what happens using a different keyboard. )
     
  28. Ventanias

    Ventanias Private E-2

    Hello again TIM

    Went away for a few days and it's back. This time it showed up when using WORD. Suddenly typed QYT....rew, opens the document format window and starts opening Edge windows like crazy.
    Even opens new Word documents....
    T
     
  29. Ventanias

    Ventanias Private E-2

    It hijacked the letters QWERTY of the keyboard. Had to disconnect it and reconnect to regain keyboard control. Every time I press any of these letters, it activates new browser windows and Word empty documents.
    I'm buying a new keyboard ASAP as you mentioned before. Can this virus damage the keyboard?
    It opens the attached image frequently.
     

    Attached Files:

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try two things: please uninstall all your browsers ( Exept Edge ), make sure you have reset Edge to defaults again and then run CCLeaner to remove all traces of files or reg keys left over.

    Now follow these instructions to disable autoruns:
    https://www.techrepublic.com/article/how-to-disable-autoplay-and-autorun-in-windows-10/

    Next:
    Please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Download a new installation of either FireFox or Chrome and see if you still have the issue. ( Are you saying that these pop up just happen by themselves or after typing a certain letter(s)?
     
  31. Ventanias

    Ventanias Private E-2

    Hello, just a touch base.
    The PC have been running without virus activity for the last week or so!
    Thank you very very much for your help Tim!
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing.
     
  33. Ventanias

    Ventanias Private E-2

    Hello again Tim. And it's back...
    It seems to be related to Google Chrome. After a few weeks free of hassle only on Microsoft Edge, I decided to reinstall Chrome. After a few days, it restarted to open random windows.
    I'll follow the procedure again?
    Can this be an extension or maybe the virus is hiding in my Google data?
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall Chrome but also delete these folders:
    C:\Users\User Name\AppData\Local\Google\Chrome
    C:\Program Files (x86)\Google\Chrome

    Reboot.

    Re-install Chrome from MG's download site.
     
  35. Ventanias

    Ventanias Private E-2

    C:\Users\User Name\AppData\Local\Google\Chrome is refusing to be deleted.
    A windows says I need a permit from my own account which is FUJITSU-Server\MNG (BTW the account I'm logged in)
    The other directory is gone
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you using an Admin. account?
     
  37. Ventanias

    Ventanias Private E-2

    I think I only have one account to enter this PC, which is the Microsoft Account
     
  38. Ventanias

    Ventanias Private E-2

    upload_2020-9-1_17-52-7.png it says Administrator
     
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    LOL....didn't really need the pictures!!

    Ok, try this:

    To delete a folder using command prompt of windows, follow this procedure.

    1. Open a command prompt (Press the windows icon key and R to open the run window). Type cmd and hit enter from the keyboard.
    2. On a command prompt, enter the following command and hit enter from the keyboard.
    Syntax:

    rmdir /s <complete path of folder suppose>
    When your path contains spaces, then the path must be enclosed in quotation marks.

    Example:

    rmdir /s "C:\Users\karim\Desktop\My Dumps"
     
  40. Ventanias

    Ventanias Private E-2

    Access Denied!
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try again in an elevated cmd prompt:

    cmd /c del /F >>> full path here <<<< ( remember the spaces ).
     
  42. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If this still is not working, go back to run.....type in cmd and then press Ctrl+Shift+Enter ...you will have an Admin. control prompt so you can try the script again.
     
  43. Ventanias

    Ventanias Private E-2

    Nope, nothing. The folder is locked. I can see another folder inside called SwReporter but cannot open or delete it.
     
  44. Ventanias

    Ventanias Private E-2

    In fact, that SWreporter folder is Hidden and even that attribute cannot be changed from within Windows.
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if this works:

    1. Go to the directory: [Drive]:\Users\[Username]\AppData\Local\Google\Chrome\User Data\SwReporter\
      • Replace [Drive] and [Username] with your hard drive letter and user account name, respectively.
    2. Select the folder(s) present on the screen, right click on them, and select "Properties". The properties window should open.
    3. Go to the "Security" tab and click on "Advanced". A new window should open.
    4. Click on "Disable Inheritance". A new window should open. Select "Remove all inherited permissions from this object."
    5. Click "Ok" or "Apply". Access to the software reporting tool folder(s) should be disabled now, so they won't run.
    Then try the Admin. command prompt to delete it.
     
  46. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are still not having any luck, I would download Revo Uninstaller, re-install Chrome and then let Revo uninstall it....completely. Then have CCleaner remove any leftovers.
     
  47. Ventanias

    Ventanias Private E-2

    Did that. Still there....Swreporter is still there and still locked. We'll have to call the Army!
     
  48. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  49. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  50. Ventanias

    Ventanias Private E-2

    Downloaded the AVG Anti-Virus tool, scanned, nothing found. Where do I find the log? nowhere to be found...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds