Suspect I Have Virus/malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by John Bryant, Nov 23, 2020.

  1. John Bryant

    John Bryant Private E-2

    Hello,

    I recently upgraded from Win 7 to Win 10 and my brother tried re-installing a copy of Acrobat XI that I suspect was not a friendly... Immediately after, websites were being hijacked and other issues. The computer will also freeze up every now and then for about a full 30 seconds. Also, the day this happened, I saw an email pop up in my inbox confirming a BestBuy order and right before my eyes, I saw the email disappear from my inbox. My Paypal account had a $870 charge. I changed all PWs using a different computer and got that order canceled. Scary.

    I ran Malwarebytes, Adaware, Spybot. They all found things and I removed what they found. I still suspect that I have something and ran through the 'Read and Run Me First' steps. Attached are all of those logs.

    I may have screwed up big time. The instructions for obtaining the log for HitmanPro clearly say not to delete, replace or quarantine any items and to just save the log file. I clicked the Next button thinking it would give the option to download the log file and it ended up deleting all the items found. I hope you can still help me and I didn't make a mess of things.

    I appreciate any help you can provide.

    Thanks,
    John
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGTools.exe did not run to completion. Please check the instructions and run it again. While I have you>

    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  3. John Bryant

    John Bryant Private E-2

    I let MGTools run overnight and it is left with "Running analyse.exe" as the last entry and a lot of blank space below it in the cmd screen. Attached is the log zip file. I'm not sure if it ran to completion though.

    I'm having trouble installing the Zemana tool. I run it as Admin and it gives the following error "InstallSDK Failed! Filepath =C:\AntiMalware_Setup.exe".
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have to agree to the Hijack this ..... twice. You need to clean out your temp folders.

    Having numerous open ports to Pirate Bay is probably not a great idea...and can you tell me what these are:

    2020-11-19 06:00:24 C:\Program Files (x86)\BFtIKUqQhhPtC
    2020-11-19 06:00:24 C:\Program Files (x86)\ctcfHNAKU
    2020-11-19 06:00:24 C:\Program Files (x86)\DWVGJfIvLIE
    2020-11-23 16:16:54 C:\Program Files (x86)\DYMO
    2020-11-19 06:00:24 C:\Program Files (x86)\EtivEeQLQcpU2
    2020-11-19 03:45:01 C:\Program Files (x86)\fjkw1lb5cxpb
    2020-11-19 06:00:24 C:\Program Files (x86)\QTPdmVqkWnIuwMrGhHR
    2020-11-19 06:00:24 C:\Program Files (x86)\xhyCiluHhzUn
     
    Tater likes this.
  5. John Bryant

    John Bryant Private E-2

    I just ran Ccleaner and Disk Cleanup on all drives. Temp folders should be cleaned.

    I don't get any options to agree to Hijack This when trying to install Zemana. Attached is a file with all the screenshots as they pop up when I try to install it.

    The only one of those programs that I recognize is Dymo which is a label printer that I am now having trouble printing to and was trying to install the drivers for.
     

    Attached Files:

  6. John Bryant

    John Bryant Private E-2

    Oh, and do I close the ports open to Pirate Bay?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, you would have gotten that message when running MGTools.exe.

    I suggest you remove those random named files/folders. As to Pirate Bay, Try these tips....you will find the ports that are open in the RunKeys log of MGLogs.zip.
    https://windows.tips.net/T013105_Closing_an_Open_Port.html
     
  8. John Bryant

    John Bryant Private E-2

    OK, I finally got MGTools to complete successfully by closing all apps and letting it run. Then, the HijackThis 'agree' popup was there. I've attached that log zip file.

    I was able to get Zemana to run. I rebooted the pc prior to it running and not sure if that mattered. Attached is the log file from that.

    I tried to follow the Windows Tips link to close the ports open to Pirate Bay, but I was always getting 'Access is Denied' when I try to create the Rule. The reboot seemed to also help with this and I was able to create the rules to Block the connections. I'm not sure if I did this properly because I still see those listed in the runkeys.txt log from the MGTools zip I created after trying to block the ports. Attached is a screenshot of the Inbound Rules from Windows Defender in case that shows something.

    Thanks again for all you do!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please right click the start button and click on Run....then type in %temp% and delete all it finds.

    Please use file explorer to find:
    C:\Program Files\Private Internet Access\pia-service.exe
    C:\Program Files\Private Internet Access\pia-wgservice.exe
    And delete them.

    As to Pirate Bay, I suspect you are allowing uTorrent to remain open which will create a listening port to pirate bay. If it is in your notification area next to your clock, exit it.

    Let me know what you find.
     
  10. John Bryant

    John Bryant Private E-2

    I deleted all from the %temp% search.

    I deleted the two Private Internet Access program files.

    I did not have any uTorrent showing in the notification area and Task Manager showed no processes related to that running.

    I ran MGTools again and attached the latest zip in case its useful.

    Thanks
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In your search box, type in network connections....then click on the result...which is a control panel. You will see different connections, but look at this one:

    Unknown adapter Local Area Connection 4:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Private Internet Access Network Adapter

    Click on it and then click on disable.

    Let me know how that goes.
     
  12. John Bryant

    John Bryant Private E-2

    I disable that connection as instructed. Shows 'Disabled' in the Network Connections control panel.

    I ran MGTools again (zip attached), but still see the ports showing 'Established' to thepiratebay.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Probably due to uTorrent. What malware issues are you still having.
     
  14. John Bryant

    John Bryant Private E-2

    The only issue that seems to be lingering is the computer will freeze every now and then for about 30 seconds. The last time it froze, but the bluetooth mouse tracking worked, but clicking wouldn't, except for clicking in the browser address bar. The bluetooth keyboard wouldn't work except for typing in the browser address bar. Alt-tab would work. When it unfroze, all of the alt-tabs keyed in before would then process all at once. Could this be a software conflict?
     
  15. John Bryant

    John Bryant Private E-2

    Correction: Alt-tab wouldn't work. When it unfroze, all of the alt-tabs keyed in before would then process all at once. Could this be a software conflict?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes... something that you should pursue in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds