FLV Player

Discussion in 'Malware Help (A Specialist Will Reply)' started by IBleed4Thee, May 6, 2014.

  1. IBleed4Thee

    IBleed4Thee Private First Class

    I finally had to get a new computer due to the end of support for Windows XP. The computer is a month old and it was being sluggish.

    Before I transferred anything from the old pc to the new I ran MalwareBytes and AVG on everything. I've downloaded nothing online and the only installs are from the software that came with the computer.

    I'm always pay close attention when downloading as to not install garbage that I don't want or stuff that could cause issues. But is seems something managed to get installed.

    The only clue was that being online was slow and that shouldn't be for a new computer. So I decided to come here for help.

    My antivirus found nothing, MalwareBytes never picked it up or did SuperAntiSpyrware. I ran HiJackThis and it didn't find anything out of the ordinary. I didn't run Fix It just Analyze.

    But Hitman Pro has.

    Need help getting it off the computer.

    As always your help is greatly appreciated.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it remove what it finds.

    The MGlogs.zip that you attached is corrupt somehow. Can you either attach it in the correct format or rerun MGTools.exe again to produce a fresh MGlogs.zip to attach for me please.
     
  3. IBleed4Thee

    IBleed4Thee Private First Class

    Kestrel13!
    Thanks so much for replying.

    I am unable to have Hitman Pro remove what it finds. It's asking for a activation code which I do not have.

    Not sure what was wrong with the MGlogs.zip that I orginally uploaded, it's the one that appeared in my files after it completed the process. I have ran it again and uploaded it. Hopefully this one is successful.

    I've also attached a new log of Hitman Pro just incase it changed from the first one posted.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below using Revo Uninstaller.

    • BeeCoupons Smartbar



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
    
    :reg
    [-HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}]
    [-HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}]
    [-HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}]
    [-HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowserSafeguard_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowserSafeguard_RASMANCS]
    [-HKU\S-1-5-21-1851843949-576978046-2803166877-1001\Software\Microsoft\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4]
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "HOSTS Anti-Adware_PUPs"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    • Now re run Hitman again and attach log.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. IBleed4Thee

    IBleed4Thee Private First Class

    Just attempted to download OTM and keep getting a warning message that the site is blocked by Trend Micro due to malicious software or might have been involved in online scam or fraud.

    Is there a issue with the website before I click on go there anyway?
    Thanks.
     
  6. IBleed4Thee

    IBleed4Thee Private First Class

    Not sure what was going on but I finally got it to download and run. And the move was successful.

    BeeCoupons Smartbar is unistalled.

    Everything else ran without issue though Hitman Pro has still found a few things.

    So far it seems to be running much quicker so that's a plus.

    Thanks.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :)

    Run this Reset Google Chrome to Defaults

    How confident are you in the Windows Registry? Can you delete these yourself?

    • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4
    • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
    • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467

    Now rescan with Hitman again and attach the new log.
     
  8. IBleed4Thee

    IBleed4Thee Private First Class

    Greetings

    I've only had the computer a short while and haven't had to do it. Still learnings Windows 8.1 so I'm not sure how to go about it.

    I did find the Registry Editor but not sure where to look for those files in the catagories listed.

    If you can steer me in the correct directions I'm sure I can delete them.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We'll do it this way instead ;)

    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Don't forget to reset Chrome....


    Now re run Hitman - attach log.
     
  10. IBleed4Thee

    IBleed4Thee Private First Class

    :(

    Following your instructions exactly and its still there. Grrr!

    Reset Chrome.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Log onto each user and repeat the process on each account. Let me know how you get on. Attach new Hitman log once done.
     
  12. IBleed4Thee

    IBleed4Thee Private First Class

    I'm the only user. There is only my account.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What are these? There's a sandra user and also an S user....
     
  14. IBleed4Thee

    IBleed4Thee Private First Class

    I'm clueless.
    I'm Sandra.
    But how there is a Sandra and a S that I don't know.

    How do I even find/get to those to run it on both like you suggested.

    And is there a way to just have Sandra.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Foolow these instructions just to the part whwre it says:

    In the users list, who do you see? Does the S account show from here?
     
  16. IBleed4Thee

    IBleed4Thee Private First Class

    Yes. It shows.
    How two were created I'm clueless.

    Can the S be deleted without causing any issues?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Last edited: May 8, 2014
  18. IBleed4Thee

    IBleed4Thee Private First Class

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So are you able to delete it from there? :confused (Unfamiliar with Windows 8)
     
  20. IBleed4Thee

    IBleed4Thee Private First Class

    Well this is that option and when I click on delete it scans all the files in the folder and then a screen pops up stating that it can't complete because the file is open.

    So I closed the folder but that closed down the deletion process.

    Grrr.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  22. IBleed4Thee

    IBleed4Thee Private First Class

    Followed your instructions and according to my Settings there, there is only one account. Sandra. Administrator.

    It's not showing the "S" account.

    This is crazy.

    Thanks for your help and spending so much time on this.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When Chaslang gets chance he will pop in and take a look. He will be able to shed more light on this than me. Hang in there. :)
     
  24. IBleed4Thee

    IBleed4Thee Private First Class

    Okay.

    Again thanks so much for your time and patience.

    :)
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! Avenger is does not support x64 and probably not Windows 8 either.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per TDSSKiller
    Per Hitman the PC name and username are: MYSTERIA\S

    Per RogueKiller: User : S [Admin rights]

    Per MGtools you have two user accounts:
    And the one you have been using ( logging in with ) and posting logs for is the C:\Users\S account.
    The Sandra user account has not been used since 4/12/2014 per your logs
    Code:
    d-----w                 0 2014-05-06 16:12:48  C:\Users\S
    d-----w                 0 2014-04-12 01:10:01  C:\Users\Sandra
    These are user accounts you created. You should not delete the account that you have been logging in with because it may be the one that you really want. You will have to figure that out by trying to login with the Sandra user account to see what the difference is. This is not a malware problem. The accounts are both yours. Please see the below or post in the Software Forum for help with Windows

    http://www.pcworld.com/article/2065137/how-to-logoff-in-windows-8.html
     
  28. IBleed4Thee

    IBleed4Thee Private First Class

    Yes, it was determined that their are two accounts.

    How two were created that is what I don't understand.

    When I set the new computer up it was set up as Sandra.

    If I go to Settings it only shows one account.
    If I go into the Control Panel it shows two.

    This "S" account appeared on the desktop after Windows Updated as did the icon of This PC...neither of those were there when I set the computer up.

    When I log into Windows I log in to the account that is showing in Settings...Sandra.

    Update: I just followed the link you provided. Click on start and clicked on name/image. The name beside the image is SLyons but if I click to log out the name is Sandra. There are no other user names listed there. I signed out and signed back in. Grrr!


    Yes, I'd like to get to the bottom of it but isn't the bigger issue getting rid of the files that we've been unable to.

    I'll do what you suggested to get to the bottom of the user accounts. I also posted that in the Microsoft forum to see if anybody has any suggestions.
     
    Last edited: May 9, 2014
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not major items but let's try the below to scan for more info.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  30. IBleed4Thee

    IBleed4Thee Private First Class

    Ran OTL as you suggested noting the settings.

    There are two reports. OTL.txt and Extras.txt.

    Should I attach both?

    I just attempted to attach OTL.txt and it states the file is too large to upload. So I zipped the file. I hope that was the correct thing to do, if not let me which method you prefer.

    Thanks.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your OTL log is clean. I don't think there are really any major malware issues on your PC to be concerned with. Are you actually having any malware problems?
     
  32. IBleed4Thee

    IBleed4Thee Private First Class

    The computer appears to be running fine.

    I just ran Hitman Pro to see if it picked up anything. Especially those 4 files that wouldn't clean out despite using the programs that were suggested.

    Is OTL showing they are removed as Hitman Pro is still picking them up.

    Attached.

    Thank you for checking and your times. Appreciated as always.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is the main point I was looking to clarify. Those items in Hitman are not really problems. They are just leftover dead registry keys and one folder. You can manually delete the below folder

    C:\Users\Sandra\AppData\Local\Google\Chrome\User Data\Default\Web Data

    Removing the registry keys may be more trouble than its worth due to possible registry key permissions within Windows. We could try to do it manually but it could be potentially run into being a lot of work and if you are not really proficient with Windows and the Registry Editior, it could also be dangerous. I suggest you ignore them because they are not really actively doing anything.

    No. OTL does not happen to scan for malware. It is just an information provider ( like MGtools ) and just happens to look/list whatever it is designed to list.
     
  34. IBleed4Thee

    IBleed4Thee Private First Class

    Thanks for replying.

    Having never used OTL before I wasn't exactly sure what it's purpose was. Thanks for explaining.

    At this point I'm not feeling comfortable playing with the registry keys and have always valued your experience and suggestions on how to proceed. You or your staff have never steered me in the wrong direction and always have the person in need of help best interest in mind.

    If they can't do any harm and it's dangerous to delete them then I agree its better to leave them there. No sense taking the chance of doing more harm than good.

    If all is good should I proceed with finishing up the Read and Run process?
     
  35. IBleed4Thee

    IBleed4Thee Private First Class

    chasling

    I have a question but not sure if it should be posted here or elsewhere.

    I was curious and looked at the logs from OTL.

    I had used the software that came with the new pc to transfer files/folders to my new computer.

    I had spent some time deleting those files/folders that weren't needed or use or I knew wouldn't be compatible with Windows 8.1. But from the OTL logs it appears there were some I missed.

    I went to Control Panel and saw the ones listed that were of no use and deleted those. They were listed in Programs. I had looked in Uninstall but didn't see them listed but then I'm just learning Windows 8.1 so I could have missed them. So I deleted them from the Programs folder.

    Then I wanted to make sure they were gone so I went back to Control Panel and did search for them in "C" and files assoicated with the programs I deleted are still there.

    So my next thought was Revo and they aren't listed there.

    Am I going about this the incorrect way to get rid of them.

    If I should have posted this in another place can you steer me in the right direction.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really do not know exactly what items you are referring to but since they are not malware issues I will refer you to the Software Forum for questions like this.


    Run the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  37. IBleed4Thee

    IBleed4Thee Private First Class

    Thank you for replying.

    I did spend some time on those programs and was able to deleted them without any issues. If any most appear that I can't removed I'll post in the software forum.

    Have completed the final steps and as always thank you for your experience and time spent on this issue.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds