Help Needed...malware Wont Go Away...

Discussion in 'Malware Help (A Specialist Will Reply)' started by MinorBlake, Mar 31, 2016.

  1. MinorBlake

    MinorBlake Private E-2

    I downloaded & installed a YouTube video downloader, even unchecked all of the crapware boxes, but it still put something on my pc that slows my web searches and interferes/slows with my browsing. I tried running all of your tools (and ADWCleaner) and it still comes back after restarting and re-opening IE or Chrome, as you will see in the scan files attached. Thank you!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What comes back? There are no problems showing in the logs; however your log from MGtools is very incomplete. It looks like you did not wait for it to finish running before you attached the log. You must wait for it to tell you it is finished. Please try again, but I'm not expecting that much will be found since the other logs are all clean.

    What real problems are you currently having?
     
  3. MinorBlake

    MinorBlake Private E-2

    Again, slow/unresponsive web page loading & searches. This is what keeps showing up when I scan:
    ¤¤¤ Registry : 2 ¤¤¤
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{c59c27ce-a480-4d09-9675-65c09fd4831e} | DhcpNameServer : 172.20.10.1 ([X]) -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{c59c27ce-a480-4d09-9675-65c09fd4831e} | DhcpNameServer : 172.20.10.1 ([X]) -> Found
    ¤¤¤ Files : 1 ¤¤¤
    [Hidden.ADS][Stream] C:\Windows\SysWOW64:Win32App_1 -> Found
    I can delete them, but as soon as I open another browser and re-scan, they show up again.
    I re-ran MGTools (to completion this time) and am attaching that log. (The first time I ran MGTools I saw "The operation completed successfully" at the bottom of the command window, with no progress indicator, so I assumed it was done.) Thanks for all your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's did a little deeper.

    I thought the DhcpNameServer lines could be related to some software that you may use. Perhaps something related to Apple products?

    Please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  5. MinorBlake

    MinorBlake Private E-2

    The FARBAR files are attached. Thanks again!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well based on these logs it looks to me like the ADS and other settings mark in the FRST logs with <====== ATTENTION

    Are due to your use of BitDefender's AntiCryptoWall and CryptoPrevent from Foolish IT LLC

    I cannot say for sure but perhaps these are contributing to your problems. I'm not really seeing any obvious signs of malware. I think the Win32App_1 ADS could be from having used BitDefender. They have been known to mark files and folders with ADS in the past. But the Win32App_1 ADS info did not even show in your FRST log file.

    Let's run a couple of junk cleanup programs to see if it helps with your slowness.

    Please download AdwCleaner by Xplode and save to your Desktop.


    • Right click onAdwCleaner.exe and select Run As Administrator unless running Windows XP where you should just double click to run the tool.
      Vista/Windows 7/8/10 users right-click and select Run As Administrator
    • Accept any prompts for permission to run and then click the I agree button to accept the Terms of Use
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, you may just see a popup stating that no malicious programs were found. Just click OK to continue.
    • Now click the LogFile button and the report will open in Notepad.
      (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

    Now please download Junkware Removal Tool to your desktop.


    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, Win7, 8 or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Make sure that your antivirus is disabled. See the below link for help on disabling it.

    How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs


    • Please download ZOEK and save it to your desktop (preferred version is the *.exe one - upper left corner).
    http://hijackthis.nl/smeenk/


    • Attached to the bottom of this message you will find a file called zoekscript.txt
    • Download it too and save to your desktop - _it needs to be in the same location as the ZOEK tool
    • Drag zoekscript file and drop it onto ZOEK icon - this should launch the program:
    • The scan may take a while and may need a reboot.
    • Upon completion a file zoek-results should appear.
    • Attach it to your next reply.
     

    Attached Files:

    Kestrel13! likes this.
  7. MinorBlake

    MinorBlake Private E-2

    The logfiles are attached. "Searchscopes" seems unwanted in the ADWCleaner log. I've deleted it in the past and it's here again. I did not remove it yet again. Is this an indication of an unwanted program? Many thanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those searchscopes are not major issues. It's just basic junk. You can clean them up with AdwCleaner. You forgot the log from ZOEK.

    Also is there any change to your issues?
     
  9. MinorBlake

    MinorBlake Private E-2

    ZOEK log is attached this time. Only issue is the SearchScopes keeps coming back, even though ADWCleaner gets rid of it temporarily. SearchScopes does not show up on any other of my three computers, all Win 10. Thanks...
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume that you mean the web data items. These are not really major issues but if you really want to clean them up you may have to reset Chrome to default settings of possibly even uninstall Chrome and then manually delete the related files/folders. They are embedded in files for Chrome. AdwCleaner may not be able to remove them for any number of reasons. For example:
    • You still had Chrome open and running
    • Your antivirus program is running and blocking the changes
    • You forgot to run AdwCleaner as Adminstrator
    You could try repeating with AdwCleaner in safe boot mode but still use Run As Administrator.

    To try a Chrome reset, see the below:

    Reset Chrome to Defaults
     
  11. MinorBlake

    MinorBlake Private E-2

    Actually, I was referring to the registry items that ADWCleaner found regarding Internet Explorer:
    ***** [ Registry ] *****

    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
    Key Found : HKU\S-1-5-21-3901262571-1060324949-2415803118-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

    ADWCleaner deletes them, but they return after re-boot and re-opening IE.

    Also, did the ZOEK log show anything? Thanks again for holding my hand through this!
    And, yes, I will try to reset Chrome...
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh those! Those are part of Norton Safe Search.

    It cleaned up a few more misc junk items but no real major issues.

    What exact slowness are you referring too? Is it only when browsing? If yes then perhaps you should not be opening so many tabs in Chrome. It looks like you always have around 25 tabs open.
     
    Last edited: Apr 7, 2016

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds