Malwarebytes Reports Traces Of Hicosmea

Discussion in 'Malware Help (A Specialist Will Reply)' started by PaulF1, Jan 9, 2016.

Tags:
  1. PaulF1

    PaulF1 Private E-2

    I have run Malwarebytes over the past few months, and it often reports the following two registry entries as threats:
    Registry Keys: 2
    Adware.Hicosmea, HKCU\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}, Quarantined, [f27ce6506b2eca6c2303457ebc464cb4],
    PUP.Optional.Hicosmea, HKU\S-1-5-21-980850525-1289679630-1920010367-1000_Classes\WOW6432NODE\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}, Quarantined, [0c62d6608613c175ecce821413f0c63a],

    I quarantine or delete the above keys, reboot, rerun Malwarebytes, and they are gone. In the next day or so, they again are reported. I have tried to connect them to appearing after I execute one of my programs, but so far I cannot pin it down to a specific program.

    I posted a thread in a Malwarebytes forum. They had me run a set of tools, which did not report any errors, but the Hicosmea registry entries would reappear usually with the next few days.

    Attached all the scans detailed in the Major Geeks procedures. Can someone can tell me how to keep the registry entries from continuing to appear?

    I noticed Hitman Pro flagged some threats that Malware-Bytes did not, but as instructed, I had Hitman Pro ignore all.

    PaulF1
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, PaulF1

    Please re-run HitmanPro, activate the 30-day Trial License, then fix these detections:
    Potential Unwanted Programs

    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest HitmanPro log.

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Close all open windows and browsers.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Logfile button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Attach that logfile to your next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which are created when running the tool.
    This is mostly caused by an adware add-on browser extension. Let's reset your browsers to their default settings.
    Reset Internet Explorer 9, 10, and 11 to Defaults
    Reset Chrome to Defaults
    Reset Firefox to Defaults
    Reset Opera

    Also if you use a shortcut link or quicklaunch icon to start your browser -
    Right-click on the shortcut and look at the Properties to see if anything unwanted has been forced to load during the execution of the browser.​

    Then upload the below logs:
    • the JRT.TXT log
    • AdwCleaner[S#].txt
    • updated Hitman Pro log.txt
    Make sure you tell me how things are working now!
     
    Last edited: Jan 9, 2016
  3. PaulF1

    PaulF1 Private E-2

    Thank you. I performed the actions and attached logs.

    I will run the computer for a few days and see if Malwarebytes finds any Hicosmea traces and let you know.

    PaulF1
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Now to remove what AdwCleaner detected..

    Using AdwCleaner.exe previously downloaded:
    • Double click on AdwCleaner.exe to run the tool. (Vista, Win7/8 users should right-click and "Run As Administrator")
    • Click on the Scan button.
    • After the scan has finished..
    • Click on the Clean button.
    • Press OK when asked to close all programs and follow the onscreen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
     
  5. PaulF1

    PaulF1 Private E-2

    AdwCleaner log is attached.

    PaulF1
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Ok - let me know if Malwarebytes' detects anything after a couple of days.
     
  7. PaulF1

    PaulF1 Private E-2

    The two pesky Hicosmea registry keys did show up on a Malwarebytes scan today.
    Attached is the scan log.

    PaulF1
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those registry keys are not malware. They are normal and on every PC. @Dr. Moriarty, Check your own Win 7 PC. :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds