Need Some Help With Rambler.ru

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sburison, Mar 16, 2017.

  1. sburison

    sburison Private E-2

    I messed up and got the rambler.ru crap on my pc. Ran the roguekiller app and got the following report. Any help would be appreciated.

    I did download malwarebytes - "unable to run because program is in use"

    So far I am getting loads of pop ups blocked by my pop up blocker. I am worried about what else is going to happen.
     

    Attached Files:

    Last edited: Mar 16, 2017
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. sburison

    sburison Private E-2

    1. adwcleaner file attached.
    2. Cant run malware bytes....message is "The requested resource is in use"
    3. Fresh Rogue killer report attached
    4. hitman pro ... message is "The requested resource is in use"
    5. mgtools...many messages asking me if i want to allow program to change my pc. answered yes to all till i judged the mgtools to be in a loop then exited.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's get started with a fix. Run RogueKiller again and allow it to fix only the below items under the specific tabs:

    ¤¤¤ Processes : 2 ¤¤¤
    [VT.Adware.Yelloader] svcvmx.exe(9240) -- C:\Program Files (x86)\svcvmx\svcvmx.exe[-] -> Found
    [PUP.Gen0|VT.Adware.Yelloader] (SVC) windowsmanagementservice -- C:\Users\Steve\AppData\Local\Temp\20170316\ct.exe[-] -> Found

    ¤¤¤ Registry : 8 ¤¤¤
    [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | cpx : "C:\Program Files (x86)\cpx\cpx.exe" -starup [x] -> Found
    [VT.Adware.Yelloader] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | svcvmx : "C:\Program Files (x86)\svcvmx\svcvmx.exe" -starup [-] -> Found
    [PUP.Gen0|PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Dataup (C:\Program Files (x86)\dataup\dataup.exe) -> Found
    [PUP.Gen0|Suspicious.Path|VT.Adware.Yelloader] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\windowsmanagementservice (C:\Users\Steve\AppData\Local\Temp\20170316\ct.exe) -> Found

    ¤¤¤ Files : 2 ¤¤¤
    [PUP.Gen0|PUP.Gen1][Folder] C:\Program Files (x86)\dataup -> Found
    [PUP.Gen1][Folder] C:\Program Files (x86)\regtool -> Found

    Please follow the instructions as written in the READ & RUN ME FIRST. This seems to indicate that UAC is not disabled and also you did not use Right Click and select Run As Administrator. Make sure that you wait for it to finish running and then attach the C:\MGlogs.zip file
     
  5. sburison

    sburison Private E-2

    thanks for the reply. I did get the UAC disabled and ran mgtools. log attached
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [cpx] "C:\Program Files (x86)\cpx\cpx.exe" -starup
    O4 - HKLM\..\Run: [svcvmx] "C:\Program Files (x86)\svcvmx\svcvmx.exe" -starup
    O23 - Service: Dataup Service (Dataup) - Unknown owner - C:\Program Files (x86)\dataup\dataup.exe
    O23 - Service: Network Driver Service (qdcomsvc) - qdcomsvc Inc. - C:\Program Files (x86)\qdcomsvc\qdcomsvc.exe
    O23 - Service: Windows Management Service (windowsmanagementservice) - ct Corp. - C:\Users\Steve\AppData\Local\Temp\20170316\ct.exe

    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of the code box
    • Make sure that you scroll all the way to the bottom of the code box to get the whole fix!
    Code:
    :services
    Dataup
    qdcomsvc
    windowsmanagementservice
    
    
    :Processes
    explorer.exe
    
     
    :Files
    C:\ProgramData\1489683834
    C:\ProgramData\329E209E563q378
    C:\ProgramData\Avg
    C:\Program Files (x86)\cpx
    C:\Program Files (x86)\dataup
    C:\Program Files (x86)\qdcomsvc
    C:\Program Files (x86)\svcvmx
    C:\Users\Steve\AppData\Local\Temp\20170316
    C:\WINDOWS\TEMP\*.*
    C:\Users\Steve\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "AvgUi"="\"C:\\Program Files (x86)\\AVG\\Framework\\Common\\avguirna.exe\" /lps=fmw"
    "cpx"=-
    "svcvmx"=-
    
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "AvgUi"=-
    "cpx"=-
    "svcvmx"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, Win7, 8 or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7, Win8 or Win10, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. sburison

    sburison Private E-2

    ok, followed the steps, attached the files. PC is running well. We are way past the Rambler issues and I suspect you are cleaning out other crap.

    Big gratitude from me to you!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes there were additional things to clean out and still may be more. But the latest MGlog.zip file you attached shows it did not run properly or that you may not have waited for it to finish before attaching the log. Only one file in it has been updated. Can you please run the C:\MGtools\GetLogs.bat program again and make sure it tells you it is finished before grabbing the log. Also please run a new scan with RogueKiller and attach this log too.
     
  9. sburison

    sburison Private E-2

    i was extra patient this time.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for the delay, it still looks like a few items were not cleaned up properly. Could you please attach a proper text file log from RogueKiller like in the first log you attached. Your last post is an XML file which we cannot use.

    Also please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.
    • See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  11. sburison

    sburison Private E-2

    completed
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still attached an xml file log from RogueKiller. You have to save it as a TXT file. But don't bother right now. Let's run a fix with FRST.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds