Junk on my computer from vid player download; Redux

Discussion in 'Malware Help (A Specialist Will Reply)' started by zamorazeke, Aug 29, 2013.

  1. zamorazeke

    zamorazeke Corporal

    Hi Majorgeeks,(again);:-o

    Probably I'm setting a record in asking for help again only a short time after you helped me clean our computer. This evening, I was asked to download a vid player in order to watch a streaming version of the Detroit Lions game and, too late, I realized this was a ruse.

    I am asking (humbly) for review of the posted logs (attached) and directions for the next steps for me to take. It wouldn't surprise me if these new instructions are similar to those given last time around, but I don't want to risk doing something wrong on my own.

    Again, I apologize for the inconvenience to you in my asking for help again, but I will be ever so grateful for your help in this matter.:cry
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Uninstall MixiDJ V42 Toolbar.

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 2 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Documents and Settings\Dan\Application Data\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-220523388-299502267-725345543-1004\[...]\Run : SearchProtect (C:\Documents and Settings\Dan\Application Data\SearchProtect\bin\cltmng.exe [7]) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Re run Hitman and under the heading "Malware" have it fix C:\System Volume Information\_restore{22CFB79A-7522-43B6-ADD6-75A1F78CF63E}\RP235\A0070296.exe
    Also have it delete suspicious files and Potential unwanted programs.

    Delete these if they show:
    • C:\Documents and Settings\Dan\Application Data\SearchProtect
    • C:\Program Files\SearchProtect

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. zamorazeke

    zamorazeke Corporal

    Thanks for your reply and instructions. I used MSConfig utiliity to put machine back into normal startup mode and uninstalled the toolbar, as you directed.

    However, after running RogueKiller, I couldn't locate (determine) which of the entries in the Registry tab are the ones you want me to leave the checkmarks by and then delete. So I have not deleted any of them.

    I'm confused:confused because the two registry detections you asked me to delete don't appear in the latest RK Report (created just now and attached to this post), whereas they were in the first RK Report attached to my post last night.

    Could it be that when I completed the first two assignments from your latest post the third assignment with RogueKiller was already (accomplished) taken care of?

    I am sending this now in hopes that you can confirm the RK task is accomplished and you will give permission to continue with the rest of the assigned tasks.:)
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue on with the other instructions. RK no longer shows any issues. :)
     
  5. zamorazeke

    zamorazeke Corporal

    Hi,

    Am attaching results from rest of the activities: Hitman, Junkware, and MGlogs.

    In running Hitman, it seemed to lock up... after it removed bunches of Conduit program files. After twenty minutes in which it used 100% of the processor's capacity and it appeared to have locked, I did a forced shutdown and restart. Could not get a log of the files that had been removed. I then ran it again and did not do anything but save the last (second) Hitman log (attached). It refers to 7 threats/7traces in the log, but it hadn't shown them as options to remove in the scan.

    Also, one of the problems indicated in the second run of Hitman was a referral to MyPCBackup (start) in which the file was missing, but I didn't opt for it to be repaired at that time. Could it have been referring to the hijackthis line: O4 - Startup: MyPC Backup.lnk = C:\Program Files\MyPC Backup\MyPC Backup.exe? Apparently, there's still stuff that needs attention? But you'll know for sure.

    Received a "success message" on adding Regedit 4 to the registry.

    Also, I'm attaching the Junkware log and MGlogs files.

    Thanks again for your direction and help.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There's a link to it on the desktop, and one in the start menu as you say:

    C:\Documents and Settings\Dan\Start Menu\Programs\Startup\MyPC Backup.lnk

    Uninstall BrowserPlus2 Toolbar. Let me know what issues remain.
     
  7. zamorazeke

    zamorazeke Corporal

    Hi,:)

    Just attaching the latest hijackthis log on fresh startup this afternoon.

    Hope it shows things as being normal...no surprises?

    I couldn't find evidence of the BrowserPlus2 Toolbar when looking around, so I really haven't gone through any procedures for removing it. Do I need to do that, and if so how?

    Are there other things (programs) I need to run for diagnostics and send logs in to you before going on to the final steps?

    Should be able to do more of this on my own, but I don't want to do something wrong and make things worse.

    I really appreciate your help and direction. Thanks!!!
     

    Attached Files:

  8. zamorazeke

    zamorazeke Corporal

    Adding this log from Hitman...thanks!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try using Revo Uninstaller. See if it shows there.
     
  10. zamorazeke

    zamorazeke Corporal

    Thanks...

    BrowserPlus2 Toolbar doesn't show in the Revo Uninstaller when run.

    Do you think it's time to do the final steps in securing a clear machine?

    I'll do whatever you suggest....really appreciate your patience in handling a situation that should not have happened.:wave
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am still concerned about BrowserPlus2 Toolbar being installed. Please try using Your Uninstaller to see if it shows there.
     
  12. zamorazeke

    zamorazeke Corporal

    In the process of installing Your Uninstaller, my home page was reset to the BrowserPlus2 Toolbar

    By the way Your Uninstaller didn't show the BrowserPlus2 Toolbar as installed on the computer, and during the install of Your Uninstaller, my virus software, Avast came up and alerted that it had prevented a virus infection of the computer.

    It was after looking at the programs listed on Your Uninstaller and going back to the browser then clicking to add another tab that the new home page (I assume installed by a rogue) showed up.

    Are we back at square one? Do we have to start all over again?

    Thanks
     
    Last edited: Sep 1, 2013
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Because Browser Plus crap is still embedded in the machine! This is why I wouldn't wrap this up yet, we're not done.

    OK, so it's hiding itself away quite well. I'll think about this.

    There is nothing wrong with YourUninstaller. Did you install something else accidentally when you went thru it's installation process? Perhaps what your AV is detecting is a false positive. Only recently I stopped using avast as it went and flagged practically everything on my machine as infected. This wasn't the case.

    It more than likely came from what you originally posted about, the vid player download.

    Not quite, no. I just need to figure out how to be rid of that junk. Hang in there.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Right, let's try this.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. zamorazeke

    zamorazeke Corporal

    Hi,

    Thank you for your help.

    Completed items from the last post. Got success message and have attached the log asked for.
     

    Attached Files:

  16. zamorazeke

    zamorazeke Corporal

    Also, before you made this last post, I ran all the preliminary programs asked for in the R&R Me First sticky.

    Am attaching these logs just in case you might like to see the (latest) status of the machine before doing the Regedit 4 change.

    Thanks and Cheers:)
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, saw the MGlogs from after you did the reg patch. How is it now by the way? Any better? (If not, I'll scour that complete set of logs you supplied me with, before the reg patch, and see what else stands out)
     
  18. zamorazeke

    zamorazeke Corporal

    I rebooted the computer after doing the Regedit 4 change.

    It appears that I have a "Delta" (Toolbar) problem, at least that is the name of the new home page in Firefox. When clicking to open Firefox I got a request to install an addon... Delta Toolbar 1.5.0, and the webpage is www2.Delta-Search.com, according to the request...which I did not accept. But it already is the homepage when opening my browser (Firefox).

    Might it be instructive to go back to the thread in which I first had problems on August 24? Titled "Junk on my computer from vid player download" ...the sequence of procedures used then seemed to work well...seemingly cleaned up everything at the time.

    Thanks again:)
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am taking a short break to enjoy a coffee. I will review the last set of complete logs you provided me with very soon. There is no need for you to do anything else at this point until I further instruct you. We don't want to make anything worse at this point.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : NTRedirect (C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Dan\Application Data\BabSolution\Shared\enhancedNT.dll",Run [-][7]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-220523388-299502267-725345543-1004\[...]\Run : NTRedirect (C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Dan\Application Data\BabSolution\Shared\enhancedNT.dll",Run [-][7]) -> FOUND
    • [V1][SUSP PATH] EPUpdater.job : C:\DOCUME~1\Dan\APPLIC~1\BABSOL~1\Shared\BabMaint.exe [7] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Rerun Hitman Pro and have it delete Potential Unwanted Programs.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Documents and Settings\Dan\Application Data\BabSolution
    C:\DOCUME~1\Dan\APPLIC~1\BABSOL~1
    C:\Documents and Settings\All Users\Application Data\Babylon
    C:\Program Files\Delta
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserPlus2 Toolbar]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.





    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).




    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  21. zamorazeke

    zamorazeke Corporal

    Ran RogueKiller and I couldn't tell which two of the seven boxes refer to the items you want me to check: the first two appear to refer to redirects of Google update tasks, the next four appear to be HKCU and HKLM resets having to do with Software\microsoft\windows\currentversion\policies\system that reset registration tools, etc.

    I cannot tell which of the items are those you refer to in the directions. So I've attached the latest RK report. The scan results in the tool and report (log) don't appear to be the same as those you show in your post?:(
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just continue on please. There's nothing actually wrong in the last RK log. There was wrong showing in the one before that....
     
  23. zamorazeke

    zamorazeke Corporal

    Should I just delete all of the seven checked boxes in RogueKiller and continue on to the next items? Sorry...
     
  24. zamorazeke

    zamorazeke Corporal

    Okay... Didn't delete anything in the RK scan and I am continuing on with the rest. Thanks!
     
  25. zamorazeke

    zamorazeke Corporal

    Have done the OTM and am attaching logs...
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you complete the rest of my instructions? (everything that comes AFTER OTM) Thanks. :)
     
  27. zamorazeke

    zamorazeke Corporal

    Have completed OTM, Firefox, JRT, and MGtools\GetLogs.bat file. logs for JRT and MGTools are attached. Computer seems happier. Rebooted...took a while to digest the changes, I guess... Hope the attached look okay

    Once again, I'm thankful for the direction and your patience:)
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Surf around a day or so, then report back to me. (And please watch your surfing habits!!) :)
     
  29. zamorazeke

    zamorazeke Corporal

    Will do...on both counts!!! Thanks!!!
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me know how it's going later today. :)
     
  31. zamorazeke

    zamorazeke Corporal

    Hi,:)

    Sorry, I didn't see your post yesterday. Everything is going well...quite well, really.

    I used windows search for 'conduit' and 'delta' and found files in an archived folder of Firefox settings --this was from a previous reinstall of Firefox (before you had me completely remove and reinstall it in this latest effort). I "shredded" this latest found file folder and files just to be safe.

    If you need me to re-run any of the detection tools, they are still on my desktop. I haven't dumped them yet.

    Hope things are going well for you.:wave
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am glad all is running nicely again. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  33. zamorazeke

    zamorazeke Corporal

    Thank you kindly... Will do.:)
     
  34. zamorazeke

    zamorazeke Corporal

    Completed the final steps. Thanks again!!:wave
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are welcome. Safe surfing. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds