Help with Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Clinton, Jan 24, 2013.

  1. Clinton

    Clinton Private E-2

    I need help with Malware removal. I've attached my log files. I have a paid version of Malwarebytes and I ran a scan and deleted what it found prior to finding this forum. I have attached the log from that scan as well. I ran a second MB scan per your instructions and it is also attached. Thank you - please advise.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please attach the MGlogs.zip from running MGTools.exe Thanks. :)
     
  3. Clinton

    Clinton Private E-2

    Sorry I missed that one. Here it is...
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=ba8f6c2d-a77b-49a6-bbd9-181447880f18&searchtype=ds&q={searchTerms}
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=ba8f6c2d-a77b-49a6-bbd9-181447880f18&searchtype=ds&q={searchTerms}
    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://feed.snap.do/?publisher=Tigh...c2d-a77b-49a6-bbd9-181447880f18&searchtype=hp
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=ba8f6c2d-a77b-49a6-bbd9-181447880f18&searchtype=ds&q={searchTerms}
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=ba8f6c2d-a77b-49a6-bbd9-181447880f18&searchtype=ds&q={searchTerms}
    • O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)

    After clicking Fix exit HJT.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\ProgramData\0x0304A000.sfl
    C:\ProgramData\blekko toolbars
    C:\ProgramData\Roaming
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Re run Hitman now and have it delete Potential Unwanted Programs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. Clinton

    Clinton Private E-2

    Thanks for your response...

    I ran analyse.exe and deleted the 6 items you requested.

    I then ran OTM per your instructions. A log file is posted.

    I've also attached a 2nd Hitman log and deleted 4 (Yontoo) items.

    After the I ran the GetLogs.bat file and have attached the MGlogs.zip, as you requested.

    After the scans - I noticed that when I opened firefox to send you this response and I clicked on the forum link, a new browser window was opened by TidyNetwork and there was some random ad in the window. I closed it and re-ran the scans, but nothing showed up... So the logs I have attached came from the first scan. Also...in the forum itself, there are some words on the page that have hyperlinks. If I hover over the link, a TidyNetworks bubble pops up. For instance, near the top of the page, under the horizontal navigation bar (UserCP / FAQ / Members List / Calendar / Casino / New Posts / Search / Quick Links / Log Out), there is a line that says, "Malware Removal Malware Removal Forum. Please see the READ AND RUN ME FIRST thread before you post...." The first "Removal" is a hyperlink to a TidyNetwork bubble. Don't know that this is normal, because when I first noticed I had some spyware on this machine, I noticed the TidyNetwork name. (I am also attaching a screenshot of the TidyNetwork bubble)

    Hope you can help! Let me know if there is something else I need to do on this end...
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  7. Clinton

    Clinton Private E-2

    JRT log is attached. Still seeing the TidyNetwork links/bubbles. :(

    Thanks!
     

    Attached Files:

    • JRT.txt
      File size:
      3.3 KB
      Views:
      2
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    Also..

    Run this and attach the results.

    Using ESET's Online Scanner
     
  9. Clinton

    Clinton Private E-2

    Scans run and logs attached.

    I did notice again today that when I clicked to send this reply, another browser window opened with an ad. :( Still seeing TidyNetwork ad links (bubbles) on this page.

    The OTL log was too big to send as a txt file, so it is zipped.

    Thanks again for your help!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does this only affect Mozilla Firefox, or other browser(s) too?
     
  11. Clinton

    Clinton Private E-2

    Hmmm...don't see it in IE. One other thing I'm noticing is that each time I log into the forums, the links are not always the same, but they are always from TidyNetwork.

    Curious to hear your ideas!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  13. Clinton

    Clinton Private E-2

    And that worked! Thank you so much for all your help!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Kes would have had you do the same thing.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds