Malware.. I Think

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by zocaz, Dec 14, 2017.

  1. zocaz

    zocaz Private E-2

    hi there,its me again..now i have some issues with my win 10..i dont know what is happening,everything is happening ,i think..you will know better from looking in those logs then if i am explaining to you..i can write only this..several times in last few months when win goes in sleep mode and get back from it ,it changes IP address and i lose access to web..i dont know if that is got anything to do whith....well anything..but my provider says that i have got a virus :) ...also im sorry couse i think i didnt run hitman as i should...and i couldnt run it again...thank you for your time...you are the best...zocaz
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove everything ADWCleaner found. Then rerun RogueKiller and remove these items:

    ¤¤¤ Registry : 6 ¤¤¤
    [PUP.Gen0] HKEY_CLASSES_ROOT\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A} (C:\Users\klinci\AppData\Local\Temp\HYD371F.tmp.1447075551\HTA\3rdparty\OCComSDK.dll) -> Found
    [PUP.Gen0] HKEY_CLASSES_ROOT\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C} (C:\Windows\CouponPrinter.ocx) -> Found
    [PUP.Coupons|PUP.Gen0|VT.Detected] HKEY_CLASSES_ROOT\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} (C:\Windows\CouponPrinter.ocx) -> Found
    [PUP.Gen0] HKEY_CLASSES_ROOT\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146} (C:\Users\klinci\AppData\Local\Temp\HYD371F.tmp.1447075551\HTA\3rdparty\OCComSDK.dll) -> Found
    [PUP.Gen0] HKEY_LOCAL_MACHINE\Software\FFinder LTD -> Found
    [PUM.StartMenu] HKEY_USERS\S-1-5-21-2927496551-225672428-3795322142-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found

    ¤¤¤ Tasks : 1 ¤¤¤
    [Hj.Shortcut] \{C3BDA1B4-80B4-4C21-9B5F-40C112209504} -- "c:\program files\mozilla firefox\firefox.exe" (http://www.skype.com/go/downloading?source=lightinstaller&ver=7.5.0.102&LastError=404) -> Found

    ¤¤¤ Files : 7 ¤¤¤
    [PUP.Gen1][Folder] C:\ProgramData\Trymedia -> Found
    [PUP.Gen1][File] C:\Users\Public\Desktop\Popcorn Time.lnk [LNK@] C:\PROGRA~1\POPCOR~1\POPCOR~1.EXE -> Found
    [PUP.Gen1][File] C:\Users\klinci\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Popcorn Time.lnk [LNK@] C:\PROGRA~1\POPCOR~1\POPCOR~1.EXE -> Found
    [PUP.Gen1][Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time -> Found
    [PUP.Gen1][Folder] C:\ProgramData\Trymedia -> Found
    [PUP.Gen1][Folder] C:\Program Files\Popcorn Time -> Found
    [PUP.Gen1][File] C:\Users\Public\Desktop\Popcorn Time.lnk [LNK@] C:\PROGRA~1\POPCOR~1\POPCOR~1.EXE -> Found

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    It looks like MBAM may have fixed your IP hijack.

    However, try to run Hitman, tell me if you can and leave it open until I get back to you.

    Before you do that, reboot and rerun ADWCleaner and RogueKiller and attach those logs.
     
    Last edited: Dec 14, 2017
  3. zocaz

    zocaz Private E-2

    i did what you told me to and these are the logs...i will try now to run a hitman
     

    Attached Files:

  4. zocaz

    zocaz Private E-2

    i did it..its running now
     
  5. zocaz

    zocaz Private E-2

    finished...by the way..thank you very much for this...you people are the only help that i have...
    i have got some shady folders that popuped during all this...yesterday ...what should i do whit them
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok....if you have Hitman open, delete everything under:
    Potential Unwanted Programs
    and
    Cookies

    Reboot and then rerun Hitman and attach the new log.

    The "shady folders" are a result of running MGTools. They are fine.
     
  7. zocaz

    zocaz Private E-2

    well, last time comp went to sleep mode and it lost ip again..and i didnt have time to sit by comp since then... ill run hitman again..:) and again..
     
  8. zocaz

    zocaz Private E-2

    ok i did it but i couldnt delete anything from hitman so im sending the last log as it is..
    if you want i can run it again and leave it opened for you to see but tomorrow morning or later during the day..but i think that my morning is not yours also so....
    im from Smederevo ,Serbia and its 15:45 pm now ..so my morning will be in 16-17 hours from now
    i hope im not bodering you too much and im sorry for my english..spelling at least :)
    bye and thanks
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Processes
    explorer.exe
    :Files
    C:\rei\ (ReimageRepair)
    C:\rei\AV\Microsoft.VC90.CRT\
    :Reg
    [-HKLM\SOFTWARE\Classes\cpbrkpie.Coupon6Ctrl.1]
    [-HKLM\SOFTWARE\Classes\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4}]
    [-HKLM\SOFTWARE\Classes\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4}]
    [-HKLM\SOFTWARE\Classes\s]
    [-HKLM\SOFTWARE\Classes\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3}]
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}]
    [-HKU\S-1-5-21-2927496551-225672428-3795322142-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}]
    :Commands
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Reboot and rerun both Hitman and run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7,or Win8 or Win10 don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).
     
  10. zocaz

    zocaz Private E-2

    HI, I finally found the time to do this, but Im not sure I did it right with MGTools...I only got a little black window....anyway ..comp is working very nice..thanks :)
     

    Attached Files:

  11. zocaz

    zocaz Private E-2

    what should i do with all this logs and softwares , and those shady things on my desktop ?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use file explorer to find and delete > C:\rei\ (ReimageRepair)

    The shady things on your desktop will go away when you run the final steps:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds