Hijacked email plus mywebsearch and search conduit infections

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lucia, May 28, 2014.

  1. Lucia

    Lucia Private E-2

    Hi Guys,

    First of all, thanks again for your help on a previous thread; it was much appreciated.

    Unfortunately, I'm back again to help the same friend clear the same machine after clicking on a link in an email that appeared to come from a friend.

    Her email account sent over 150 emails of gibberish in two minutes but the computer itself isn't acting any different. I've attached the logs below and once again, thank you for providing this super helpful resource.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Firstly I need to point out that more than one antivirus is currently installed. I suggest that you uninstall the outdated avg 2011 and keep avast!

    • avast! Free Antivirus
    • AVG 2011

    Was this below software paid for?

    • CyberDefender Registry Cleaner

    If not please uninstall it. It's not recommended.

    Uninstall this as you already have avast:

    • McAfee Security Scan Plus



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :reg
    [-HKLM\SOFTWARE\Microsoft\Windows Media\WMSDK\sources\f3PopularScreensavers]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\FunWebProducts]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts]
    [-HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Re run Hitman again and attach the log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. Lucia

    Lucia Private E-2

    Hi Kestrel

    Thanks for your help.

    Got permission to delete the Cyberdefender so did it.

    McAfee was in the list of programs in Programs and Features but I got a message saying it was already uninstalled.

    AVG was in Program Files but not in the list in Programs and Features so I was unable to uninstall.

    From the moment I started it up today the computer was running extremely slowly, until I ran JRT (it requested a reboot midway and I pressed y. Is that OK) then it speeded up a lot.

    Also when I installed MGTools it was to the desktop (would not let it save to C drive). Seems it was still installed there from the previous infection. I ran C:\MGtools\GetLogs.bat from the C drive so it's from the previous install last year (could not figure out how to get it from the most recent version of MG Tools installed on the desktop). Would that cause any problems?

    Thanks,

    Lucia
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it remove what it finds.

    Use Revo Uninstaller to uninstall avg please. Let me know how you get on.
     
  5. Lucia

    Lucia Private E-2

    Hi

    Revouninstaller was unable to find AVG.

    I've run hitman and removed what it found.

    The computer is still very slow (it was fast after JRT but then slowed down again and running hitman does not seem to have made a difference).

    Thanks,

    Lucia
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go here and download the avg removal tool applicable for your operating system. Choose the 2012 one. Once you have run it, do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. Lucia

    Lucia Private E-2

    Hi,

    I ran the AVG remover tool as requested.

    The MG logs are attached to this post.
     
  8. Lucia

    Lucia Private E-2

    Sorry just checked back abd see they didn't seem to attach. Trying again:
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm not seeing anything else to do here in this forum. You can post in the software forum about any outstanding non malware issues. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  10. Lucia

    Lucia Private E-2

    Thank you so much for your help Kestrel13!


    I will check out the other forum because things are still running slow. One last question: is there anything you would suggest we do with the email account to avoid reinfection. I already told er to change the password; is that enough?


    Many thanks for your help once again,

    Lucia
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. You can also ask questions about the security of the email account in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds