Chrome Security Warning Scam - Tinba?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by vvgomez, Dec 25, 2018.

  1. vvgomez

    vvgomez Private First Class

    Hi,

    I couple of days ago I got the chrome security warning scam while navigating, and immediately, I was notified by my internet provider that a trojan named Tinba was detected from my network. I ran all the antiviruses and killed some bugs detected by defender, but now I would like to be sure that nothing else still in the system lurking in the shadows.

    Please, find the logs attached.

    Thank you for your help.

    vv
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please re-run RogueKiller and delete these detections:
    ¤ Services ¤
    [PUP.Slimware (Potentially Malicious)] SWDUMon (0) -- \SystemRoot\system32\DRIVERS\SWDUMon.sys -> Found
    ¤ Registry ¤
    [PUP.Slimware (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SWDUMon -- C:\WINDOWS\system32\DRIVERS\SWDUMon.sys (missing) -> Found

    When it is finished, there will be a log on your desktop named RKreport[2].txt - upload it to your next message.

    Now copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4"). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double-click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.
     
  3. vvgomez

    vvgomez Private First Class

    Hi Dr. Moriarty,

    Thank you for your soon response. I deleted both detections as advised, but not RKreport[2].txt was created in my desktop, so I saved both reports, the scan and delete report, manually.
    Also, the second running added more detections.

    I got the success message for the registry.

    Thanks,
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I noticed that you still have Zemana Antimalware installed - please update and run it; upload a fresh log.
     
  5. vvgomez

    vvgomez Private First Class

    It took a while, but here is the log
    Thx
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    How's your machine running, now?
     
  7. vvgomez

    vvgomez Private First Class

    It is running ok. Didn't have evident symptoms before excepting for the chrome security scam site that showed up when navigating. Probably, a little slow in the start up, comodo didn't want to update (now it does) and malwarebyte delayed too much opening when I doble cliked on the icon, but now seems ok.
    Do you think the machine is finally clean?
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I believe so!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it...just move on to the next step.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, do the below:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8/8.1/10 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing!
     
  9. vvgomez

    vvgomez Private First Class

    I'll wait a couple of more days to be sure I don't have any weird behavior and then I'll process with the final steps.
    Thank you so much for all your help in the middle of the holidays. Very kind of you!
    Wish you a happy new year!
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome and "Happy New Year!".
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds