malware: PC Optimizer pro & KNCTR popups, mysterious streaming audio

Discussion in 'Malware Help (A Specialist Will Reply)' started by batch, Aug 2, 2013.

  1. batch

    batch Private E-2

    Win 7 64bit

    Months ago (~4/26/13), avira killed "zero access". Don't think this is recurrence b/c internet access is not affected? software works normal other than symptoms described.

    Symptoms:

    - persistent popups (see attached screenshot word doc)
    - mysterious audio stream w/o any apparent application running it (intermittent, only when connected to internet, - if it's streaming through web browser, there's no tab on a webpage other than google). the streaming will start immediately upon connecting ethernet cable to switch.
    - lots of unwanted apps and desktop shortcuts installed (see screenshot doc of add/remove programs - 8/1/13).
    - weather bug, pc optimizer pro, app that called itself "7zip" but was not legit.

    Steps I took that might have made it worse:

    - avira scan said it found and cleaned. But symptoms above remain. (I would attach the avira scan report but I think CCleaner wiped it? But I can attach screenshot of the Quarantine.)

    - I tried uninstalling the unwanted apps from 8/1/13. when i uninstalled "7zip" it wiped desktop to where only the background was showing (no start, no application bar, system tray). only option seemed to be reboot. which i did by cycling power. after appeared no dmg...but..?
    - after that, i decided to follow your procedure and let the experts have a look.

    TIA.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Malware and Potential Unwanted Programs.

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-295163356-329271299-2293230067-1003\$7bdaf6cc8d0b99ffb6ef40ed356bf453\n. [x]) -> FOUND
    • [V1][SUSP PATH] DSite.job : C:\Users\Happy\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE - /Check [-] -> FOUND
    • [V2][SUSP PATH] DSite : C:\Users\Happy\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE - /Check [-] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Re run Hitman and Roguekiller again (just scans) and attach the new logs.

    Let me know how things are running. :)
     
  3. batch

    batch Private E-2

    Thank you K.

    re-ran Hitman and deleted and restart as app requested - saw Hitman run script on s/u so seems to have worked - attached log1.zip.

    re-ran RK - could only find and delete the process ZeroAccess path (the two susp path tasks were not present - presume killed by Hitman?) log1.zip attached

    unfortunately, the popups still there. reran hitman and RK (oldversion see !imaidiot!) scans. attached. log2.zip hitman shows clean.

    !imaidiot!:
    after above, I noticed RK I was using needed update. (i was ignoring that first time b/c ... i'm an idiot. was trying to keep pc off internet until clean.) updated RK (website has lots of "download now" ads but eventually found real update link) and scan w/ updated RK is attached - updated RK has more "hits". sorry. attached log3.zip (includes .jpg of two popups still there.)

    (hitman updated itself so shouldn't be a problem there. I also went back and checked that all the other tools were latest from links on MG forum - compared version in log files from 1st post w/ version in download links. so no further update needed issues.)
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, the logs are good. Which browser are you experiencing pop ups in?
     
  5. batch

    batch Private E-2

    Hi K. I missed the notification you had replied. thanks for quick response. sorry i missed it.

    so w/ your appraisal that the logs looked clean, I was emboldened. i found the pcoptimizer pro and knctr were applications that i was able to uninstall. (not browser pop-ups). uninstalled. and now everything is back to normal.

    thank you!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. :) Glad to hear it!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds