Malware invasion

Discussion in 'Malware Help (A Specialist Will Reply)' started by mfunkygibbo, Aug 1, 2013.

  1. mfunkygibbo

    mfunkygibbo Private E-2

    Hi MajorGeeks,

    So my laptop got infected with malware about 2 weeks ago, just before I went abroad with work for a week, so I did not use my laptop in that time. It seemed to happen after I was looking for some stuff on google images.

    When I got back from abroad it was still in the same state, so I ran the READ ME FIRST, RUN ME FIRST protocol but it still seems to be infected.

    I keep getting pop-up screens such as:
    http://lp.empire.goodgamestudios.co...movies&ce_cid=20jRnv4kjrmHj98T1HuLhE1v4Xre000.

    and adverts on facebook (not posted by facebook) advertising bodybuilding drugs, fat removal, japanese girlfriends etc.

    Please help me fix my computer, it is relatively new and I hate it not being 'clean'. My laptop is an ASUS X53E running on Window 7.

    I've attached the logs as requested.

    Malwarebytes anti-Malware log:
    ------------------
    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Database version: v2013.07.31.06

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 10.0.9200.16635
    Matt :: ASUS-X53E [administrator]

    31/07/2013 21:48:45
    mbam-log-2013-07-31 (21-48-45).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 236581
    Time elapsed: 6 minute(s), 5 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Users\Matt\Downloads\SoftonicDownloader_for_format-factory.exe (PUP.Optional.Softonic) -> Quarantined and deleted successfully.

    (end)


    ------------------

    I hope you can help...Your help would be much appreciated

    mfunkygibbo
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it remove all those items under:
    ¤¤¤ Scheduled tasks : 2 ¤¤¤

    I am not finding any malware in your logs.

    Do you have a pop-up blocker installed on your browser?
     
  3. mfunkygibbo

    mfunkygibbo Private E-2

    Hi TimW,

    Thanks for that. I have re-run the scan with RogueKiller and deleted those tasks highlighted in the log under 'Scheduled Tasks 2' from the registry tab when it comes up with stuff.

    Is there a pop-up blocker I should install? I have checked the box in Firefox (the browser I use) not block pop-ups but is this not sufficient? Apparently not
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. mfunkygibbo

    mfunkygibbo Private E-2

    Hi,

    I've installed the add-on but pop-ups are still managing to get through including the one I have screenshot'ed and attached.

    I am also getting green double underlined text ads on firefox. How can I get rid of these? Is this part of the pop-up problem as well?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall Firefox.

    So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Reboot.

    After reboot, delete the below folders:

    • C:\Program Files\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall Firefox.

    Import your bookmarks file. (similar process to exporting).

    Any better?
     
  7. mfunkygibbo

    mfunkygibbo Private E-2

    Ok. Saved bookmarks. Downloaded Firefox. Rebooted.

    Now in Internet Explorer.
    Automatically a pop-up comes up in IE. Aargh: http://lp.empire.goodgamestudios.co...movies&ce_cid=20jRnv0ceIsz6nHp1HuLhE1v7cjJ000.
    What does this mean?

    Then went to look for the folders to delete.
    So this folder is there:
    C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    But this one (C:\Program Files\Mozilla Firefox) is actually in Program Files (x86). Do this matter?

    Not deleted the folders yet. Will wait for your reply. Will use IE for the time being.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun both RogueKiller and Hitman and attach the logs.
     
  9. mfunkygibbo

    mfunkygibbo Private E-2

    RogueKiller and Hitman logs attached.

    Still getting that goodgamestudios pop-up on IE. and the green double underlined text.
    Didn't delete firefox.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  11. mfunkygibbo

    mfunkygibbo Private E-2

    Ok. Scan run. Log attached.
    Thanks for the support, I hope this will not be too taxing a fix for all parties involved.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  13. mfunkygibbo

    mfunkygibbo Private E-2

    Ok. Logs attached.
    P.S. the licence agreement never came up. It did the first time I ran this in the beginning though. I presume that is fine...
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and
    some other items from our cleaning procedures.

    Now download a fresh copy of MGtools and run the exe.

    Attach a new log and be sure you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).
     
  15. mfunkygibbo

    mfunkygibbo Private E-2

    Hey,
    Log attached. Still no request for licence agreement, I presume from what it said when it was running that it was all clear to run the first time I ran the scan.

    On an aside, I've been on IE all day pretty much (looking for jobs) and no pop-ups have come up. Probably jinxed it now. Only when I came onto MajorGeeks did I get the green text thing one time today.
    Just thought you should know.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good. Let me know if you have any other issues before I give you the final clean up.
     
  17. mfunkygibbo

    mfunkygibbo Private E-2

    Brill. Thanks very much.
    Should I go back into Firefox to check out that system? I prefer using Firefox as my browser. Do I need to do the reinstall of Firefox like you mentioned in an earlier message?
    I've not seen any pop-ups on IE for the last 2 days. And I only get the green text thing on MajorGeeks on my thread with you when it comes up in history on the URL bar i.e. I type 'maj' then go to the thread. Elsewhere on the website it doesn't appear and when I log in and go to the thread it disappears. Not complaining, just seems a bit odd.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you should have followed the instructions for reinstalling Firefox.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ &
      RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall,
      don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking
      on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if
      running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any
      others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and
      deleted.

    After doing the above, you should work thru the below link:



    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  19. mfunkygibbo

    mfunkygibbo Private E-2

    Thanks very much TimW!!

    That's sorted it all out.
    So should I download the app for the firefox pop-up blocker as well after running through the clean up procedure?

    Thanks again for your help, couldn't have done it without you. :)
    May the force be with you.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. And yes, I would download the pop-up blocker for Firefox.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds