Help Me Remove Some Nasty Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by barats, Aug 4, 2020.

  1. barats

    barats Private E-2

    I have attached all the logs except Malwarebytes. It could be the malware at place but it does not let me install it at all. It restarts my computer about 3x after the install and then I get an error saying it could not be installed. I did the other logs, though. Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run ADW and remove:
    Trojan.Agent C:\Windows\System32\drivers\WinmonProcessMonitor.sys

    Adware.CloudWeb HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F4FD63-6108-4422-8357-8086AD91AB86}
    Adware.CloudWeb HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ScheduledUpdate
    Adware.ICLoader HKLM\SOFTWARE\MICROSOFT\Speedycar
    Adware.ICLoader HKLM\Software\MICROSOFT\TechnologyDesktopnew
    Adware.Linkury HKCU\Software\mtMbappert
    Adware.Linkury HKLM\Software\Wow6432Node\mtMbappert
    PUP.Optional.Conduit HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

    Then re-run Hitman and RogueKiller and remove everything they found.

    Reboot and rescan with all three and attach the new logs, please.
     
  3. barats

    barats Private E-2

    Before I remove what Hitman Pro removed, can you explain what these are? Osloader.exe sounds important and it saw it as suspicious but it has it as Ignore. Should I ignore both of these? Thank you Tim!
     

    Attached Files:

  4. barats

    barats Private E-2

    Here are the updated scans. I do have a feeling the malware is causing the 2 errors of osloader.exe and the other one. Both RK and Hitman detected them but ignored them by default. I click on them and it said the digital signature on both is invalid. Any help on that? Thanks!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both of those files could be corrupt or affected by malware. Let's do two things;

    First open an elevated command prompt ( CMD with Admin. privileges ) and type in:

    sfc /scannow ....... note the space. Let me know what it tells you.
     
  6. barats

    barats Private E-2

    Here you go
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to Run and type in msconfig....then go to the start up section and tell me what is there.
     
  8. barats

    barats Private E-2

    Here you go. And quick question. I was messing around with this last night before I posted here. A lot of stuff was happening at the startup and I went and killed them on startup to try and get a handle on things. There are a handful of processes that look to be apart of the malware we are removing. Why are they still showing up here? Even with being disabled to startup. We removed a lot. Shouldn't those be gone?
     

    Attached Files:

    • 1.PNG
      1.PNG
      File size:
      27.8 KB
      Views:
      9
    • 2.PNG
      2.PNG
      File size:
      17.4 KB
      Views:
      9
  9. barats

    barats Private E-2

    Piggybacking off that, I went into my Programs folder in the C drive and did find these programs I asked about still having folders.
     

    Attached Files:

    • 1.PNG
      1.PNG
      File size:
      33.4 KB
      Views:
      9
    • 2.PNG
      2.PNG
      File size:
      33.7 KB
      Views:
      9
    • 3.PNG
      3.PNG
      File size:
      22.5 KB
      Views:
      9
  10. barats

    barats Private E-2

    I found these, too in the x86 folder. The previous ones were the non x86 folder
     

    Attached Files:

    • 1.PNG
      1.PNG
      File size:
      10.2 KB
      Views:
      8
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They don't look legit:

    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  12. barats

    barats Private E-2

    Should I delete the folders? I haven't did anything yet just in case. But those folders were created right when the malware came about so no way are they legit. I ran the Zemana you had me do. I also got Malwarebytes to work after we did the initial scans.So I have also attached that log along with Zemana.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please allow MBAM to remove everything it found!! Reboot and rescan with MBAM and attach the new log and tell me how things are running now.
     
  14. barats

    barats Private E-2

    I think things are good now! Did a re-scan and found nothing. I have attached the logs.

    Should I still be worried about the 2 items RK and Hitman found as suspicious but ignored? The one that worries me is osloader.exe. I have read about people not being able to start their computer with this missing or damaged.
     

    Attached Files:

    • MB.txt
      File size:
      1.2 KB
      Views:
      7
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those two items are legit files. However, you can double check by doing this:

    Click on the following link and use the below steps to scan a file: Virustotal

    Click the Browse... button.
    Navigate to the file FileToBeScanned

    Where FileToBeScanned is the actual file to be scanned. Like C:\WINDOWS\System32\vdmt16.sys
    [/LIST]
     
  16. barats

    barats Private E-2

    It came back clean. I guess my question was more should I worry about HitmanPro picking up the legit file as being suspicious and now a digital key being invalid? My windows starts up just fine. I had to restart yesterday countless times after doing all these scans. I looked in the file where it is located and the last date modified for osloader.exe was right at the time when this malware happened. Is that a concern? I am not too familiar with osloader.
     
  17. barats

    barats Private E-2

    RogueKiller does not pick it up any longer. Neither did any other scan we did. And i also have SuperAntiSpyware and it didn't either.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It sounds like all is good. If you are booting up without incident and everything is coming back clean. I think you are good to go.

    aIf you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     
  19. barats

    barats Private E-2

    Awesome! Just did those steps. Thank you so much for your help, Tim. Have a great evening.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds