Here are my logs, please check

Discussion in 'Malware Help (A Specialist Will Reply)' started by jtu50, Dec 26, 2013.

  1. jtu50

    jtu50 Private E-2

    Downloaded ImgBurn. Seemed to install other stuff which I think may be malware. Ran scans as instructed. Logs attached. Please review.

    Thanks for your help!

    Jeff R
     
  2. jtu50

    jtu50 Private E-2

    Not sure logs got attached. I am resending. BTW. what do I do with the RK Quarantine folder?

    Jeff R
     

    Attached Files:

  3. jtu50

    jtu50 Private E-2

    Have noticed that in search window on Firefox and IE that there are options that seemed to be placed there by rogue installation - Conduit search and Search Protect. They are still there after having run scans and following all initial instructions.

    Jeff R
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can delete it at the end when we are finished.


    Re run Hitman Pro and have it delete the Potential Unwanted Program (Rocketfuel item)



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Processes
    explorer.exe
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "OutfoxTV"=-
    [HKEY_USERS\S-1-5-21-1529727249-3285956696-592652452-1006\Software\Microsoft\Windows\CurrentVersion\run]
    "OutfoxTV"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2be0c0de-834f-4bf0-8128-ecf5620255ad}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{745c0be4-ebd7-4e3b-a712-fb6938af805a}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2be0c0de-834f-4bf0-8128-ecf5620255ad}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{745c0be4-ebd7-4e3b-a712-fb6938af805a}]
    
    :files
    C:\Program Files\OutfoxTV
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. jtu50

    jtu50 Private E-2

    Kestrel13,

    Here are my latest logs after following above directions. I still note that the search window (next to address window) in Firefox and IE shows Conduit and Sear Protect Search as options. I think these were part of the unwanted software installed.
     

    Attached Files:

  6. jtu50

    jtu50 Private E-2

    Internet Explorer now messed up. Tool Bar, Favorites Bar, Menu Bar all black with small icons. Couldn't insert screen shot, but attached it
     

    Attached Files:

  7. jtu50

    jtu50 Private E-2

    solved the IE issue by uninstalling and reinstalling
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.


    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "OutfoxTV"=-
    [HKEY_USERS\S-1-5-21-1529727249-3285956696-592652452-1006\Software\Microsoft\Windows\CurrentVersion\run]
    "OutfoxTV"=-
    
    :files
    C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe
    C:\Program Files\OutfoxTV
    C:\Program Files\Mozilla Firefox\searchplugins\sweettunes_search.xml
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. jtu50

    jtu50 Private E-2

    Kestrel13,

    Here is the OTL log. Same problem showed up again with IE8 as I noted in post above. I'll wait for your suggestions before doing anything else. Also still seeing Conduit and Secure Search in search options on Google tool bar. Any way to get rid of these?

    Jeff R
     

    Attached Files:

  10. jtu50

    jtu50 Private E-2

    Forgot to attach MGLogs.zip. Here it is
     

    Attached Files:

  11. jtu50

    jtu50 Private E-2

    Fixed the black tool bar issue - found a fix - go to Accessibility options in Control panel and toogle "use high contrast" under display tab. Also got rid of Conduit and Secure search in search options. In Firefox there is an option to manage search engines. Also in Chrome. So now if logs are clean, I think I'm good.

    Let me know. And once again, thanks for your help
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Does this help with IE? We'll tackle Firefox next.
     
  13. jtu50

    jtu50 Private E-2

    Kestrel13,

    I guess you missed my last post. Managed to deal with search engine issues and toolbar issues in IE8/Firefox as noted below. Still run the Reg fix?
    -------------------------------------------------------------------------
    "Fixed the black tool bar issue - found a fix - go to Accessibility options in Control panel and toogle "use high contrast" under display tab. Also got rid of Conduit and Secure search in search options. In Firefox there is an option to manage search engines. Also in Chrome. So now if logs are clean, I think I'm good.

    Let me know. And once again, thanks for your help"
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes we cross posted at almost the same time if you see.

    No, not if all is well. :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  15. jtu50

    jtu50 Private E-2

    Kestrel13,

    Everything seems to be working fine! Thanks for all your help and a happy New Year!
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Happy New Year to you too!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds