Malware Has Air Gapped Me

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Buckleyterp, Feb 10, 2018.

  1. Buckleyterp

    Buckleyterp Private First Class

    Running windows 7 64-bit on a Toshiba laptop with 3 user accounts accessing internet via mobile hotspot (T-mobile).
    Signing into MG on a friend's computer because browsers do not function.
    Specifically,
    FF hijacked by 'prepareupdate.thesafestcenterforcontentsload.trade/...' while streaming video on openload.co [bookmarked]
    malware will not allow any new tabs to open any new addresses
    opened Chrome, no webpage from malware appears, but also cannot connect to the internet. taskbar shows active internet connection with full bars.
    I have MIE on the computer, which I do not use and so far have not opened.
    There are two other user accounts on the computer. One has Administrator privileges.
    None of your go-to diagnostics, I only have Superantispyware in the account.
    Malwarebytes is in the other non-administrator account but not updated for a while.
    I may have roguekiller there but hesitate to open the other accounts.
    Even so, I will not be able to send log attachments out to you.
    As I suspected, opening FF in safe mode gives no advantage.
    Running Avast free.
    What to do?
    I am installing AdwCleaner by usb transfer...
    ...AdwCleaner is stuck on 'checking for update', which it cannot do, and the other programs will not be able to do, either.
    Will attempt to load the other diagnostics.
     
    Last edited: Feb 10, 2018
  2. Buckleyterp

    Buckleyterp Private First Class

    Update: AdwCleaner eventually scannned. Will save log and attempt to load others.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Buckleyterp likes this.
  4. Buckleyterp

    Buckleyterp Private First Class

    Oh, this malware is really wicked. The arrow keys are disabled during bootup so I can't move the highlight off of 'HDD1/SSD1' during boot up.
    Got it. Had to use the number keypad arrows, not the main keyboard arrows.
     
  5. Buckleyterp

    Buckleyterp Private First Class

    I didn't really know how to make much use of the Kaspersky boot USB disk. There was no MSI equivalent that allowed me to install the diagnostics. I shuttled the programs over from the Mac via USB and the reports back the same way. I was using Kaspersky in graphics mode which seemed to prevent me from typing into this forum. I saved the Kaspersky diag. report twice in two different locations as .txt and they are not findable on the Toshiba C:\ drive or the USB Kaspersky folders, whether I boot up from USB or HDD. The available Kaspersky files are in .rpt and .tgz formats, which seem to be not uploadable. So...I will just go ahead and attach the usual suspects.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Let's run one more scan.

    Please download Zemana Malware Removal to your desktop and run it please.
    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
    Buckleyterp likes this.
  7. Buckleyterp

    Buckleyterp Private First Class

    It is not surprising that a problem exists in a firefox profiles directory. That is where I would expect it to turn up, judging by its initial behavior. And the 'r9aj92ks' name was something that cropped up in the Kaspersky report. I just had no way of attaching that to these posts. I am just surprised that Avast allowed it to live in one of its folders. I have not liked Avast very much. I may go back to 360, although I dislike their irritating daily popup newsletter.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. Buckleyterp

    Buckleyterp Private First Class

    Well, that was simple. Thank you so much. Performance is baseline. Afterward, I subscribed to Reimage Repair, that found six serious-looking PUPs that have been dealt with. I think I will set a restore point.
    Thank you again.
    B
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do not download and install Reimage!! It is adware!!

    What is Reimage Repair?

    The Malwarebytes research team has determined that Reimage Repair is a "system optimizer". These so-called "system optimizers" sometimes use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove the issues.
     
  11. Buckleyterp

    Buckleyterp Private First Class

    Reimage Repair is appearing on my screen on banners at the top of more than one Majorgeeks page. Since it was on your site, I trusted it. I wanted to support you for all of the help you gave me but could find no donation links, so I thought I would purchase something from one of your 'advertisers'. Good intentions gone wrong, eh? Do I start all over again with Mbam, RK, Hitman, MG?
    They tried to hit me up for $99 from their off-shore commission-driven boiler room. At first, I let them take control of my screen remotely (!), then it became obvious who they were. Their 'diagnostic screens' show isquite impressive but their manner gives them away.
    buck
     
    Last edited: Feb 12, 2018
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The ads on MG's are placed by google. Do yourself a favor and uninstall it. I doubt they did anything untoward with your system, but just to be safe, run Hitman and RogueKiller and attach the logs.
     
  13. Buckleyterp

    Buckleyterp Private First Class

    Hitman was acting weird. Maybe once it was me, but it stalled twice while saving the log. The log is huge and has 12796 entries and is 43 Mb. Third time worked. The zipfile is still 4.9 Mb, so it won't send.
     

    Attached Files:

  14. Buckleyterp

    Buckleyterp Private First Class

    How is this?
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rerun Hitman and remove these:
    ¤¤¤ Registry : 17 ¤¤¤
    [PUP.Gen0] (X64) HKEY_CLASSES_ROOT\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484} (C:\Program Files\Reimage\Reimage Repair\REI_Axcontrol.dll) -> Found
    [PUP.Gen0] (X64) HKEY_CLASSES_ROOT\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB} (C:\Program Files\Reimage\Reimage Repair\REI_Axcontrol.dll) -> Found
    [PUP.Gen0] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ReimageRealTimeProtector -> Found
    [PUP.Gen0] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ReimageRealTimeProtector -> Found
    ¤¤¤ Tasks : 1 ¤¤¤
    [PUP.Gen1] \ReimageUpdater -- C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe (run_task) -> Found
    ¤¤¤ Files : 8 ¤¤¤
    [PUP.Gen1][Folder] C:\ProgramData\Reimage Protector -> Found
    [PUP.Gen0][File] C:\Windows\Reimage.ini -> Found
    [PUP.Gen1][Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair -> Found
    [PUP.Gen1][Folder] C:\ProgramData\Reimage Protector -> Found

    Then reopen RogueKiller and remove everything under:
    Potential Unwanted Programs

    Reboot and rerun Hitman and RogueKiller and attach the new logs.
     
  16. Buckleyterp

    Buckleyterp Private First Class

    I want to comply but I do not know how to find these items among 12,555 results. The alphabetic and numerical order cycles several times from top to bottom and there seems to be no itemization categorized by PUP, registry, etc.
    B
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  18. Buckleyterp

    Buckleyterp Private First Class

    Not to be a MajorPain, but I already unistalled Reimage Repair using Advanced Uninstaller Pro which obviously isn't advanced or Pro enough. This left nothing for Revo to find. :(
     
  19. Buckleyterp

    Buckleyterp Private First Class

    I have A DCInstall restore point 2 days before the Reimage Repair restore point. Should I restore?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No. Because your restore point may be infected. If Revo didn't find any traces, then you should be ok.
     
  21. Buckleyterp

    Buckleyterp Private First Class

    @TimW: On their website, Malwarebytes says that they completely remove Reimage Repair, so I ran it and it found a bunch. I recognized the registry items that you mentioned. It also listed almost everything in the suspicious root folder 'rei' as well as a few obvious suspects, so I quarantined everything it listed. The system works baseline normally on reboot. In retrospect, I learned to make out the RK descriptions of the items-to-be-deleted that you mentioned. Everything is better, now. Can't Stop being a noob.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good. Let me know if you have any other malware issues.
     
    Buckleyterp likes this.
  23. Buckleyterp

    Buckleyterp Private First Class

    Thank you so much for your knowledge and forbearance.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds