Malware Might Be Cause Of Preventing Access To Certain Things?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by futurerush, Feb 22, 2023.

  1. futurerush

    futurerush Private E-2

    This past Saturday I wanted to get a tax form from my health insurance provider's website, but when I opened the lid of my laptop I saw a message (before I could even unlock the computer) that said a file had been fixed. I didn't write down what it said, but I remember seeing the word Crypto. I clicked ok and unlocked the computer.
    Then the health insurance site was stopping me from accessing the site giving me a page that says
    Access denied
    Error 15
    [web address]
    [time and date]
    What happened?
    This request was blocked by the security rules
    Your IP: [IP address]
    Proxy IP: [IP address] (ID 10144-10645)
    Incident ID: 144000900038214157-97051881348535945
    When I try to go log in manually, it would hard stop me again saying it thinks I'm a bot due to certain possible activity I don't think I have happening (i.e. going through the site at super human speed, using a VPN, or some add-on/extension). When I click I am not a bot, and try to proceed, I get the Error 15 page again. I was always able to access this site in the past and don't know what would have changed since the last time.
    When I looked up a fix for getting this error, I found a list of steps to go through one by one until the problem is fixed. The first one was to turn on Set time zone automatically in Settings > Time & Language > Date & Time. But when I went there Set time zone automatically is greyed-out even though I am an administrator. There's only one account on the computer.
    When I looked up how to fix this problem, most of the hits are for Windows 11 and I'm using Windows 10. There were some videos that said Windows 10/11 (also written as Windows 11/10) and the first one had 3 methods. The first two didn't work and the third method doesn't seem to exist for Windows 10. I gave up at this point and decided this was a job for MajorGeeks.
    When I searched for "crypto" in the C drive the only files I could think might have been what that message was about were 1 of these 4 (based on date):
    amd64_microsoft-windows-cryptowinrt-dll_31bf3856ad364e35_10.0.19041.746_none_2ab5d0707a246d19

    wow64_microsoft-windows-cryptowinrt-dll_31bf3856ad364e35_10.0.19041.746_none_350a7ac2ae852f14

    Microsoft-Windows-Crypto-DPAPI%4Operational

    Microsoft-Windows-Crypto-NCrypt%4Operational

    4 logs are attached.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks likeit's this:
    HKLM\SOFTWARE\Classes\Software.OneClickProcessLauncherMachine.1.0\ (BoxoreOU)
    HKLM\SOFTWARE\Classes\Software.OneClickProcessLauncherMachine\ (BoxoreOU)

    please attach the ADWCleaner log.
     
  3. futurerush

    futurerush Private E-2

    ADWCleaner log attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  5. futurerush

    futurerush Private E-2

    FRST and Addition logs attached.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download Zemana Malware Removal to your desktop and run it please.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  7. futurerush

    futurerush Private E-2

    There was a choice between a smart scan and a deep scan and so I chose deep. After it was finished I clicked on reports, which had the bars in the icon, but there was no report there. Please see attached images. (I also turned off Ransomware & Realtime Protection and Browser cleanup from the main screen before starting the scan because this program may conflict with my current AV.) Please advise on this. I want to make sure I'm using this right.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run hitman again and attach that log to be sure zemna got it all.
     
  9. futurerush

    futurerush Private E-2

    Hitman log attached. It looks the same as the first Hitman log.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hmm. interesting. How do you feel about removing those reg keys manually?
     
  11. futurerush

    futurerush Private E-2

    I'm ok with it.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    these two need to go. It's an old piece of malware but it seems to have volved. Have you tried spybot?
     
  13. futurerush

    futurerush Private E-2

    I don't think I have tried spybot.
     
  14. futurerush

    futurerush Private E-2

    I haven't received any instructions after answering that I don't think I have tried spybot. Please continue with assistance. Thank you.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please dowload and run Spybot
     
  16. futurerush

    futurerush Private E-2

    Spybot scan results attached. I'm guessing that I made the right decisions during install/set up.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    are the registry items still gone/
     
  18. futurerush

    futurerush Private E-2

    Do you mean are they still there? Since the instructions on malware removal/cleaning procedure pages all say not to delete anything, just create logs, I only created the log. So I'm assuming they still would be there. I also am not sure if the pre-scan decisions I made during Spybot install/running were right. I'm just guessing since there's no instructions from MajorGeeks I've seen.
     
  19. futurerush

    futurerush Private E-2

    I checked the spybot log myself and those two don't appear in the log, so I ran Hitman again and they are still in the scan results for that. How am I supposed to remove those reg keys manually?
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and thank you for your continued patience.

    I will be helping Tim in assisting you with your issue. Please be patient just a bit longer and allow me to come up to speed. It shouldn't take me long and I anticipate replying again shortly.

    Gary
     
  21. Oh My!

    Oh My! Malware Expert Staff Member

    If you don't mind, please run a new FRST scan and attach both reports to your reply. The previous reports were incomplete and a fresh run will provide me with the most current state of your computer.

    In addition, can you update me on the issues you are currently experiencing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds