Am I Able To Get Help From A Specialist? Re Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Newellsfc39, Mar 15, 2018.

Tags:
  1. Newellsfc39

    Newellsfc39 Private E-2

    Hi anyone,

    I went through removing malware, virus and trojan instructions with malwarebytes, roguekiller, hitmanpro and mgtools.

    Does the majorgeeks feature of having a specialist look at my log files by posting them still exist? I still receive the BSOD but only after another 30 minutes of running my bootcamp from my mac os.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, Newellsfc39

    You've upload two MGlogs.zip files, rather than including the HitmanPro log.... please do so. Also, did you have Malwarebytes delete its detections? If so include that updated log, as well as the AdwCleaner log.
     
  3. Newellsfc39

    Newellsfc39 Private E-2

    Dr. Moriarty,

    Thanks for your response. Here are the files you are looking for:
    1. -AdwCleaner ... AdwCleaner[S0].txt
    2. -MalwareBytes ... mb.txt
    3. -HitmanPro ... the result of this scan did not detect any threats and did not show that it produced a log file. I searched through my c:/ drive, including googling 'hitman pro scan result file' and searching on that, and could not find anything
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Your uploaded "mb.txt" log is identical to the "threatScan" log from this morning, and still shows that you took no action on the detections. Please run Malwarebytes' again and quarantine the findings, upload that new log.

    Also - please click Start/ run and type in
    %temp%
    When the window opens .. click on Edit select all and delete.
     
  5. Newellsfc39

    Newellsfc39 Private E-2

    Have been very busy, sorry for not being able to respond.

    ...I ran the scan again this morning and it detected no threats. See newly created log file from scan attached.

    I ran %temp% as you asked and I just want to give you an idea of what it contains before I delete. I see a bunch of apm-install node_modules, .tgz file folders, .dll file folders, git cache folders, vmware file folder, .dat files, .gz files, .log files and .tmp files.

    Is it still ok to delete all those without removing needed functionality in their respective applications?
     

    Attached Files:

  6. Newellsfc39

    Newellsfc39 Private E-2

    .... and there were items quarantined from my previous scan a few days ago. here is a screen shot of the q... items. will a "restore" or "delete" action is required from any of these?

    thank you again for any help
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome

    It's okay to delete the temp files as I instructed and also Malwarebytes' quarantined contents.

    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan may take some time.
    • Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.
     
  8. Newellsfc39

    Newellsfc39 Private E-2

    I am running zhpcleaner and it asked me if I installed this server "68.87.61.226 68.87.73.242"
    yes or no.

    I do not know what that server references, I am just thinking ..... I do some backend development that gives me a live developer server in pl/sql and Django and nodejs. that is the only thing I can think of.

    you know if that means I have installed a server? zhpcleaner is just hanging there til I respond.
     
  9. Newellsfc39

    Newellsfc39 Private E-2

    I looked up the servers, they are Comcast dns's. shall I respond "no" in the dialog box?

    btw, in previous post I miss typed the first, the ".61" should be ".71".
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Correct
     
  11. Newellsfc39

    Newellsfc39 Private E-2

    Thank you. See uploaded zhpcleaner txt file.
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re-run ZHPCleaner per previous instructions
    • After the scan has completed - choose to Repair these items:

      Registry
      FOUND key: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pinetreecreative.com [] =>PUP.Optional.PineTree
      FOUND key: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sp.pinetreecreative.com [] =>PUP.Optional.PineTree
      FOUND key: HKLM\SYSTEM\CurrentControlSet\Services\OracleMTSRecoveryService [] =>Hijacker.Browser
      FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{24796009-73D5-4A8E-8C98-AB5BB9D22511}\\DhcpNameServer [Bad : 68.87.71.226 68.87.73.242] =>Hijacker.Browser
      FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D2BDE7EB-67BE-4A5B-96AB-111301F1E5FB}\\DhcpNameServer [Bad : 132.183.181.173 8.8.4.4] =>Hijacker.Browser
      FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 68.87.71.226 68.87.73.242] =>Hijacker.Browser
      FOUND key: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A303BBA2F90DF5F230AA200542CC36A [C:\Program Files (x86)\Windows Kits\10\Source\10.0.10240.0\ucrt\stdlib\lsearch.cpp] =>PUP.Optional.LinkiDoo​
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
    Tell me how your PC is running now!
     
  13. Newellsfc39

    Newellsfc39 Private E-2

    Ugh, I think I screwed up...

    -I searched only the "Key" section of Repair and selected several that were on your list. There were two or three items that were not in the key section. Instead of looking through all the other sections for those missing items, I pressed Repair. At which point all the other sections that had items checked were also repaired.

    -There were about 10 other items scattered throughout the other sections. I just so happened to take a photo of the application page listing the sections and number of threats/items per section. see attached image

    -No log file popped up.

    - In a slight moment of dread, I scanned the system again to see if I could reproduce the circumstances and after the new scan was complete, no items were found as threats.

    -Upon further investigation, I saw that the log files were being produced on my desktop. The most recent scan that produced "no threats detected" was the latest log file and wrote over the other log file on my desktop ... so I inadvertantly wiped out the results of the previous log file which contained the results you might be interested in.

    -In addition to all this, I still experience the BSOD after about 45 minutes. Would the error code be any of use to you?

    -I don't know if you can tell through the log files, or if it matters, but I run Windows "Bootcamp" on a MacBook Pro.

    What a night.

    See attached image and log file.
     

    Attached Files:

  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I don't think any harm was really done.

    BSOD's would be an issue for our Software forum. Otherwise, I think we're finished with the Windows OS cleaning.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. After doing the above, you should work through the below link:
    Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds