Chrome issues - all logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by patrcarl, Nov 10, 2014.

  1. patrcarl

    patrcarl Private E-2

    Thank you in advance for your help with this!

    I have been having an issue with Chrome and Firefox....something continues to install various add-ons to these without my permission. I continually delete them, then the next time I open one of them they're back but sometimes with different names.

    I have attached the five requested logs, most notably to this novice user I see [Tr.Zeus] mcshield.exe in the RKreport. And, thanks again!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. patrcarl

    patrcarl Private E-2

    Attached is the MGlogs.zip

    Should I follow the RK instructions to remove the Zeus now? Or wait for your next reply?

    The instructions at adlice just say to use the RK to take care of it automatically (after it finds it, click to have it taken care of). But, in the RK report, there are 8 registry issues found and 5 antirootkit found (all in firefox ... but there are also 5 "web browser" found which are all add-ons that I do want so maybe the 5 antirootkit are related?). Should I do anything for those? Or just the Tr.Zeus?

    Thanks again!!!!
     

    Attached Files:

    Last edited: Nov 10, 2014
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The listings in RK are fine! Leave them alone.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • SN64 <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Now attach the newfiles.log it should have created or just attach the updated MGlogs.zip.
     
  5. patrcarl

    patrcarl Private E-2

    Hi Kestrel - I ran those two cmd and got the following error:

    "SteelWerX WhoAmI application has stopped working"

    I let that finish trying to work, then when it stopped trying I clicked to cancel that window and the command prompt started going again.

    When it finished, I got the attached file and the following info from the cmd:

    zipping newfiles.txt
    zip warning: new zip file left as: C:zia13872
    zip I/O error: File exists

    zip error: Could not create output file (was replacing the original zip file)
    Finished zipping newfiles.txt
    zipping ffdata.txt
    finished zipping ffdata.txt
    zipping winfiles.txt
    finished zipping winfiles.txt
     

    Attached Files:

  6. patrcarl

    patrcarl Private E-2

    By the way, the MGlogs.zip file was attached on my last message from yesterday (#3 above).
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uh huh - it sure was. However it was missing a newfiles.log, (also it was missing another log - runkeys.txt) hence we went thru these latest instructions to gain one. ;) Reviewing the logs now....
     
    Last edited: Nov 11, 2014
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below using Revo Uninstaller.

    • CoolSaleCoupon
      [*]LowPricesApp
      [*]topbuYer

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: topbuYer - {4BD42D14-0348-A242-61F3-87543FFCDD27} - C:\ProgramData\topbuYer\IqrtfL.dll (file missing)
    • O2 - BHO: SSaverAddoun - {9EA1FF25-5C42-5054-18A3-7D788780D9E2} - C:\ProgramData\SSaverAddoun\w.dll (file missing)

    After clicking Fix exit HJT.




    Re run Hitman Pro and have it remove all that it finds.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\Program Files (x86)\less2pAy
    C:\ProgramData\topbuYer
    C:\ProgramData\SSaverAddoun
    C:\Program Files (x86)\Optimizer Pro
    C:\Users\Patrick\AppData\Local\Temp\i4jdel0.exe
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  9. patrcarl

    patrcarl Private E-2

    Ok - got it all! I've attached the four files...let me know if I did everything right :).

    And, thanks again!!!!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Adwcleaner and have it remove all that it sees.

    Everything still running nicely?
     
  11. patrcarl

    patrcarl Private E-2

    Hey Kestrel - everything's running great! This is a 6-month old Dell XPS laptop and I think it's running faster than when it was brand new :). BTW, the last adwcleaner just found a few bookmarks (or something like that) in chrome. Thank you for all your assistance!

    A few questions:

    1) why does it take all these 6-8 programs to do everything that needs to be done to clean like this? I'd expect by 2014 there would be a program that could take care of it all ... clearly there's not, but why?

    2) Also, right now I am just using the McAfee LiveSafe that came with the computer and nothing else. I know that McAfee is bloated but I was told by a few people to keep it since it was free with the laptop as it's just as good as anything else out there. So, should I keep it or go with something else? And, is there anything else I should add to the arsenal? Feel free to point me to a sticky thread in the forum :)

    3) There were a number of programs that I downloaded through this process to get rid of all the issues ... can I delete them all now and turn on the User Account Control?

    Thanks again!!!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So glad to hear that. ;)

    I don't usually like answering a question with a question but here goes: Why don't anti virus softwares take care of everything? Sadly they don't, and sadly, malware and junkware like to hide so deeply sometimes that extra tools are required.
    Personally I like to use Microsoft Security Essentials. I used avast prior to that but encountered a big blip I didn't like so switched...
    Yes you can follow these instructions:


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:


    Download OTC
    • Close all programs.
    • Start OTC program.
    • Click the CleanUp! button.
    • Select Yes when asked "Begin cleanup process".
    • If you are asked to reboot, select Yes.
    • If any logs remain on the computer you can remove them.

    You can also remove Adwcleaner, JRT and any files/folders they generated.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds