Infected with multi-Malware.

Discussion in 'Malware Help (A Specialist Will Reply)' started by MarkJohnson, May 31, 2014.

  1. MarkJohnson

    MarkJohnson Private E-2

    I was installing WinZip to extract some .rar files and decided against it midway though, as I figured I didn't need yet another app installed and running.

    Anyway, when I aborted it I got a notice from Norton's that it has successfully quarantined a, " uninstall.exe (Trojan.Gen.SMH)" I find it hard to believe it came from winzip. I downloaded it directly from their website.

    After removal I rescanned and it found a few minor thing, I installed MBAM in free mode as Norton's website claimed that it may interfere with Norton's if two live scanners are running at once.

    So today, I fire up my PC and get a monthly report and it post several infections for the month.

    I'm still having weird issues with my PC and think maybe there might be other things wrong.

    Here's Norton's Monthly Report.

    Code:
    Category: Resolved Security Risks
    Date & Time,Risk,Activity,Status,Recommended Action,Path - Filename
    5/30/2014 12:52:10 PM,High,uninstall.exe (Trojan.Gen.SMH) detected by Auto-Protect,Blocked,Resolved - No Action Required,
    5/8/2014 10:47:37 AM,High,a0030582.dll (Bloodhound.MalPE) detected by Auto-Protect,Quarantined,Resolved - No Action Required,e:\system volume information\_restore{eab52c8d-51f8-47a4-9633-424cb051d6f4}\rp957\a0030582.dll
    5/8/2014 10:46:57 AM,High,a0030583.dll (Bloodhound.MalPE) detected by Auto-Protect,Quarantined,Resolved - No Action Required,e:\system volume information\_restore{eab52c8d-51f8-47a4-9633-424cb051d6f4}\rp957\a0030583.dll
    5/8/2014 8:42:12 AM,Low,yontoo.exe (Yontoo) detected by Virus scanner,Quarantined,Resolved - No Action Required,e:\documents and settings\owner\local settings\temp\diq\flashplayer_187\software\yontoo.exe
    5/1/2014 11:44:07 AM,Medium,fkgbgjhgkdlplmnkainlhenlhbfoigal.crx (Adware.Popuppers) detected by Virus scanner,Quarantined,Resolved - No Action Required,e:\programdata\fkgbgjhgkdlplmnkainlhenlhbfoigal\fkgbgjhgkdlplmnkainlhenlhbfoigal.crx
    Also, I keep getting a lot of pups. usually a few a week constanly. Even overnight will show at least one.

    Also, Norton's doesn't do Pups anymore, that's why I installed MBAM free edition (non-trial).

    Thanks in advance for any help in resolving these issues.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks! :)

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide

    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual update Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only RogueKiller and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run the rest of the READ & RUN ME FIRST instructions on the infected account.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. MarkJohnson

    MarkJohnson Private E-2

    Here are the requested log files.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall Speedial


    Re run Hitman and have it remove what it finds.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] Speedial.job -- C:\Users\Mark\AppData\Roaming\Speedial\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    • [Suspicious.Path] \\Speedial -- C:\Users\Mark\AppData\Roaming\Speedial\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Delete this if you see it:
    C:\Windows\tasks\Speedial.job


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. MarkJohnson

    MarkJohnson Private E-2

    Okay, first roguekiller didn't find speeddial at all.

    I think mbam picked it up on boot as it runs live after all. I guess I didn't uncheck free trial.

    although I was able to delete the speeddial from c:\windows\tasks.

    I also missed the first two tasks somehow.

    But I uninstalled speedial and rerun hitman with nothing found.

    Here are the two logs.

    Thank you for all of your help
    -=Mark=-
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nothing attached. :(
     
  7. MarkJohnson

    MarkJohnson Private E-2

    Wierd, not sure how it got aborted without aborting the message.

    anyway, here they are again.

    For some reason I couldn't find some of them so I reran them.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    These are still showing in RogueKiller. Please rerun it and have it fix these entries.



    Now re run RK once more and attach new log.
     
  9. MarkJohnson

    MarkJohnson Private E-2

    okay, I reran it and fixed the entries.

    I rebooted and re-ran RK again and here's the report.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Speedial is still showing as being installed. Please use Revo Uninstaller to remove it and then do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. MarkJohnson

    MarkJohnson Private E-2

    revo didn't find speedial atall.

    Here's my mglogs.zip
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  13. MarkJohnson

    MarkJohnson Private E-2

    hmm, it gave me a virus? First mbam says non-threat pup,so I told mbam to let it through. After install i get one of those fake virus scanners popups and says I hve virus with even scanning. your-uninstallr never comes up.

    It akso seemed to move my home folder to my desktop? I think it may have highjacked everything now. :(

    Something told me to abort the install and ask your advice.

    Okay, I found Your Uninstaller program in all programs and ran it. It still doesn't show speedial. But I now see new ones. Optimizer Pro V3.2, Optimum PC Boost, WebEx Support Manager for Internet Explorer, BCL EasyConverter SDK 3 (Word Version) 64 , and Search Protect.
     
    Last edited: Jun 3, 2014
  14. MarkJohnson

    MarkJohnson Private E-2

    For some reason I couldn't edit my post again.

    I forgot to add that mbam reported PUP.Optional.Conduit.A and some long path to a wsmallstub.exe file when I double clicked the youruninstaller.exe file.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We'll skip Your Uninstaller and Revo and I'll try and do it my way. Sigh. Sorry about this. :(

    Please do the following and I'll have you all squared up in no time.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  16. MarkJohnson

    MarkJohnson Private E-2

    Hmm, I posted a message last night with all new logs I just reran everythng because there was such a big infection. MBAM found like 120 entries already.

    I just ran the getlogs.bat about 10 minutes ago and it hung on SteelWerX WhoAmI Application and it reports it stopped working. I left it running in case it would continue, but after 10 minutes I thinks it has locked up completely.

    I will reupload last nights log results again.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    WebEx Support Manager for Internet Explorer was already installed when you first came here.

    BCL EasyConverter SDK 3 (Word Version) 64 <--- Not seeing this installed from the logs you gave me last. Nor SearchProtect... Where are you seeing this, with Your Uninstaller??


    Do these uninstall normally without using third party software?

    • WebEx Support Manager for Internet Explorer
    • Your Uninstaller! 7
    • Optimizer Pro v3.2
    • Optimum PC Boost
    • WebEx Support Manager for Internet Explorer

    Let me know and answer any other questions I may have asked please. :)
     
  18. MarkJohnson

    MarkJohnson Private E-2

    Search Protect was there, but I think it was removed. Maybe MBAM removed it after I re-enabled the pup threat removal.

    Yes, they all uninstalled and no more popup ads.

    I still get a PUP.Optional.Trovi.A from MBAM, but I didn't remove it yet.

    Other than that, it seem clear.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can have MBAM remove that. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  20. MarkJohnson

    MarkJohnson Private E-2

    So far, so good.

    Everything seems fine. I'll let you know if anything goes wonky over the next few days.

    Thanks again for all of your help. It is very much appreciated.
    -=Mark=-
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds