Need help removing virus/malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by aaaartist, Jan 13, 2013.

  1. aaaartist

    aaaartist Private E-2

    Hello, I'm here helping my dad get rid of some pesky malware. It began a few days ago when he was trying to download some coupons for the market, which involved him downloading and installing a virtual coupon printer. At one point he was prompted to download an antivirus program, which he thought he was already running, something called "life-" or "liberty-platinum shield," or something similar. He continued to try to download and print coupons, but was receiving error messages saying he could not download/print them because he was not connected to the internet, or that he was using an unsupported browser. He was, however, because he was browsing and downloading coupon files, and switching between google chrome and mozilla firefox. He proceeded to download spybot search and destroy, but it would not allow him to update the database, again claiming that he was not connected to the internet. Over time his searches in google were being filtered and manipulated, and could not get a true search result. He manually updated spybot search and destroy and was deleting things manually, in various system folders and also within regedit.

    I was not here, so I do not know exactly what he has downloaded or what he has deleted. I have followed the "Read and Run me" area, and have uploaded the appropriate log files from the programs requested in that tutorial. He is still having trouble with his internet connection being recognized by Spybot search and destroy. He was running AVG when all of this happened, and has since uninstalled it. He is also running "Superantispyware free edition."

    He also mentioned something called "Fun," and I saw something similar come up in Hitman Pro, but ignored everything that it caught as per the instructions.

    He is running Windows 7 Home Premium SP1 64x
    AMD Athlon II X3445 Processor 3.1GHz
    8GB Ram

    I appreciate any help and insight into this problem. My father is in his 60s. Thank you,
    -Aaaaron
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since the problems began with the coupon programs, let's start by uninstalling them:
    Coupon Companion Plugin
    Coupon Printer for Windows


    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\mbc\AppData\Local\Updater21804\Updater21804.exe
    C:\Users\mbc\AppData\Roaming\Mozilla\Firefox\Profiles\cd9ldzzt.default\searchplugins\funmoods.xml
    C:\ProgramData\AVG
    C:\ProgramData\AVG2013
    C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
    C:\Program Files (x86)\AVG
    C:\Program Files (x86)\Coupon Companion Plugin
    C:\Program Files (x86)\Coupons
    C:\Program Files (x86)\Common Files\AVG Secure Search
    C:\Windows\TEMP\*.*
    C:\Users\mbc\AppData\Local\Temp\*.*
     
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{07156053-C051-4FE5-9109-64BD9F1A2037}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}]
    [-HKEY_USERS\S-1-5-21-2308244632-3307603596-471656762-1001\Software\InstalledBrowserExtensions\215 Apps]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escort.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escortApp.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escortEng.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escorTlbr.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\esrv.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\escort.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\escortApp.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\escortEng.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\escorTlbr.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\esrv.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.txtlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. aaaartist

    aaaartist Private E-2

    chaslang,

    Thank you for your prompt response. I have followed your instructions, and am attaching the requested log files.

    My father is still having trouble with certain programs not being able to connect to the internet. I have also attached a snip of the "route keeler" program not being able to open and the error message saying it cannot connect to the internet. I do not have experience with this program and do not know if this is normal or not. This was an earlier attempt to fix it himself, but he couldn't get it to function properly.

    Also, he claims that his spybot search and destroy is still not updating. He can ope the program, click update--it tells him that 15 files are out of date. He clicks update, and they seem to update, but when clicking update again, it again says that 15 files are out of date...etc. I do not know if this is an error with spybot or due to his malware. There isn't really anything else I can see going wrong, but he is under the impression that "something" is still "there" (malware present).

    Please see logs and screenshot.
    Thank you,
    -Aaron
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any program named route keeler installed. I do see route keeler.exe on the Desktop. What is this and does it require an installation?

    I still see the below in your uninstall list:

    Coupon Companion Plugin
    Coupon Printer for Windows

    Did you have a problem uninstalling them?

    Now let's see if we can fix the broken internet problem.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 13, 2013
  5. aaaartist

    aaaartist Private E-2

    The coupon printer/plugin didn't have any trouble uninstalling, I thought your previous instructions was uninstalling them...I clicked uninstall in control panel, and they said that they appeared to already be uninstalled, so they have been removed from the uninstall list, as of now.

    I will continue with your new instructions, and repost once that has been completed.

    Thank you,
    -Aaron

    EDIT:
    Route keeler doesn't appear to need installation? I think it is something to help remove root files. ? Not sure. In properties the original filename is "softonicdownloader.exe," some sort of download manager. Could also be malware. I am going to delete it.
     
  6. aaaartist

    aaaartist Private E-2

    I have followed your instructions, creating and running the fixme.reg, as well as the windows repair. I have also attached the logs.

    I tried to update spybot search and destroy again. This time the update feature was grayed out, and I was unable to select it or search for updates. I don't know if this is from malware or if it was already updated. I uninstalled it and reinstalled it. It is still not updating the files. I click check for updates, It tells me the files that need to be updated, and then click "update," which sort of just brings me back to the files that need to be updated, without being updated.

    I have attached the update log for spybot search and destroy, as well. I don't know how else to check the internet connection problem, as I am obviously on the internet, it just seems some areas of connection/communication are being blocked?

    Thank you,
    -Aaron
     

    Attached Files:

  7. aaaartist

    aaaartist Private E-2

    I thought I posted this reply, but it isn't showing up...

    I created and ran fixme.reg, and then downloaded and ran the windows repair as per your instructions. It only took maybe 20 minutes or so. I then tried to update spybot search and destroy again, however this time the option to update was grayed out, and not able to be selected. Updates could not be searched for nor downloaded. So, I uninstalled spybot and reinstalled it with a new download.

    But there is the same problem of spybot identifying available updates, and looking like it has downloaded/installed them, but once you check for updates again, they all reappear as not being updated. I am attached the logs requested from MGTools as well as the log from spybot SD's updater.

    Thank you,
    -Aaron
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no such program. Perhaps you have renamed a program like RootRepeal to Route keeler which was not a very good thing to do.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perviously you had issues with various Windows Services that were broken. Part of this was caused by the BFE registry entry being missing. We repaired all this in the last fix and it was successful per your new logs. However I can see that a ping of google still does not work. Are you sure that your network cable is plugged in to your router and that the route itself is powered up? Do you have other PCs that are working on this network ?


    Also do the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: CrossriderApp0021804 - {11111111-1111-1111-1111-110211181104} - C:\Program Files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll (file missing)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    After clicking Fix, exit HJT.
     
  10. aaaartist

    aaaartist Private E-2

    I am sure that the network cable is plugged into the wireless router, and the cable from the router is also plugged directly into his computer.

    I did as per your instructions.

    I am able to ping google.com through command prompt, 4 packets sent/received, 0 lost. I don't know if this is any different than what the programs are doing.

    Spybot search and destroy still does not up update. I am able to check for updates, as well as tell it to update the files that need updating, but once I click check for updates again, it repeats itself; it's not updating.

    I have also removed/replaced some programs. I think we got rid of super antispyware and AVG, opting for avira and possibly malware bytes, though that was already there. Everything seems to be doing okay?

    I am going to run C:\MGTools\Getlogs.bat and post the logs here again.
    I and especially my dad are really grateful for your help. I really appreciate your summarizing what was wrong, fixed, and possibly still wrong in your last response.


    Thank you,
    -Aaron
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay ping looks okay now.

    I suggest that you uninstall it, reboot and then delete all folders related to Spybot. You can then try reinstalling it if you wish, but it is not really worth the trouble.

    No we didn't. I still see it installed in the last log you attached.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds