Help With Virus That Keeps Restoring Itself

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gps08, Nov 10, 2016.

  1. gps08

    gps08 Private First Class

    Hi,

    I've been getting these weird things on my browser, where sometimes pop-ups and proper redirects happens when I click anywhere on the screen. Then I noticed my skype started to spam links to other people and had a email from gmail saying that someone from Poland tried to access my account.

    I did a scan and Malwarebytes found these PUP.optional.revizer.PrxySvrRST and also this weird named extension installed into my SRW Iron browser with lots of random letters, however I can't see this anywhere in my extension list nor is it in the browsers' task manager. (which I think is from this PUP mentioned above)
    I also noticed this weird behavior where the page seems to refresh every time I double click on any part of the window whenever it doesn't prompt me a pop-up or redirect.

    I've used Malwarebytes to delete this as well as adwarecleaner and JRT, but it seems to always restore itself.
    I read somewhere that these things also put in schedules to re-build back the virus but I don't understand the scheduler interface that well to identify if indeed it's set to schedule to run and restore every time changes are made.

    I've recently just formatted my disks and install a better version of windows 7 to my rig, and took me so long to organize my 8TB disks and stuff, I'd really like to avoid purging my disk to get rid of this annoying pest, please share with me your expertise and help me solve this!

    Please tell me what info you need to help me.

    Thank you for reading.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    gps08 likes this.
  3. gps08

    gps08 Private First Class

    Hi,

    Thanks for your reply!

    I've been following every step, however, I'm unsure about something so I thought I'd ask before I mess up.

    Step 2: Disabling User Account Control
    For Windows 7 and Win 8 users - to turn off UAC ( UAC = User Account Control )
    1. Click Start, and then click Control Panel.
    2. In Control Panel, look under System and Security and select Review your computer's status.
    3. In the Action Center window, select Change User Account Control settings in the left column
    4. Then move the Slider all the way to the bottom to Never Notify
    5. Click OK and then Yes to the popup warning that you are turning off UAC
    6. If it is already unchecked, then you should also notice a red shield with an X in it located in your system tray. Ignore any mesages about UAC being disabled.
    7. Click Restart Now to apply the change right away. (Restart even if you did not make the above change, we need to be sure that a reboot has occurred since the first time that UAC was disabled.)
    8. Keep UAC disabled until malware cleanup is complete and you have been given the okay to enable it.

    So when I went to check, the slider was all the way down already, so no changes needed. However, it says that if it was unchecked, I should notice a red shield with an X on my system tray, which is not there. I even went to customize tray to see if it's hidden but no. How can I tell it's properly disabled? It says to ignore if on win 10, but I'm using 7.
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    If the slider is all the way down to "Never notify" and you have rebooted, proceed with the guide's remaining instructions. ;)
     
    gps08 likes this.
  5. gps08

    gps08 Private First Class

    I've finally done everything in the list.

    Here are the relevant logs.

    Thanks
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    You can re-run Hitman Pro and have it remove all that it finds.

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run JRT.exe by double-clicking it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.
    Next download AdwCleaner by Xplode and save to your Desktop.
    • Right- click on AdwCleaner.exe and select Run as Administrator.
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
    Download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
    • Do NOT fix/repair anything yet! Please upload that logfile with your next reply.
    Then download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
    Tell me how your PC is running now.
     
    gps08 likes this.
  7. gps08

    gps08 Private First Class

    Browser is still acting weird. Redirects when clicking anywhere on the window still happens as well as pop-ups. Opening a new tab (set as blank page on options) still opens the same unknown fake yahoo link. Double-clicking on the window anywhere will still refresh when it does not redirect or pop-up.

    Here are the requested logs.

    Thanks
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    With which browser are you having problems?

    Re-run ZHPCleaner per previous instructions
    • After the scan has completed - press the Repair button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
     
    gps08 likes this.
  9. gps08

    gps08 Private First Class

    I'm having this issue on SRW Iron browser.

    I'll run ZHP now and post the log afterwards.
     
  10. gps08

    gps08 Private First Class

    Here it is.
     

    Attached Files:

  11. gps08

    gps08 Private First Class

    Though the log said it was successfully repaired, I'm still experiencing the same issues as before but at a smaller rate. I'm also getting these ads popping out the sides of my window.
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your browser's window or while using Windows Explorer?

    Since SRW Iron is based on the "Chromium" Sourcecode try using the following to reset to Defaults:
    Reset Chrome to Defaults

    If the problem isn't resolved after the browser reset, I suggest that you backup your bookmarks and re-install SRW Iron. Keep me advised on any progress, please.
     
    gps08 likes this.
  13. gps08

    gps08 Private First Class

    The reset Chrome to Defaults didn't really work, however a clean re-install seems to have done the trick so far. Browser behavior seems to be very normal now. Is there a way to confirm this was completely removed, as in, I'm scared it will restore itself again like it has done before.

    Thank you for your time.
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Frankly, only a repeat of your surfing habits should cause the problem to reappear.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    gps08 likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds