Potential Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by mark59, Nov 2, 2014.

  1. mark59

    mark59 MajorGeek

    I had a problem on my PC, about which I created a thread on Majorgeeks here.

    I ran the following software (all up-to-date) that’s installed on my PC in order to check for potential problems:
    • Malwarebytes Anti-Malware
    • Microsoft Security Essentials
    • SUPERAntispyware
    • Trend Micro Housecall
    SUPERAntispyware reported I had ten tracking cookies, which the application dealt with.

    To ensure that my PC is not infected I have run the “READ & RUN ME FIRST Malware Removal Guide (incl. spyware, virus, trojan, hijacker)” and attach the logs. I’d be most grateful if the logs could be checked to see if my PC is infected or if it’s not infected.

    The instructions in the READ & RUN ME state that RogueKiller automatically creates a log on your desktop. In my case it didn’t. I had to click on Report in RogueKiller’s console to get a report.

    Information about my PC:
    Make and model: Acer Aspire 5920
    Operating system: MS Windows Vista HP SP2
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I'm not seeing any malware in those logs. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  3. mark59

    mark59 MajorGeek

    Thanks very much, kestrel13!, I appreciate your time and help.:celebrate
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. Safe surfing! :)
     
  5. mark59

    mark59 MajorGeek

    The malware check resulted in finding no malware. Even the checks I ran on Mozilla Firefox itself as discussed in this thread found no problems.

    But, I’ve just logged on to the PC and the problem reported here has returned.

    I’m completely mystified. How has this problem returned? What can I do in order to rectify it?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which browser do you see Trovi on?

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    Now please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  7. mark59

    mark59 MajorGeek

    The browser I see Trovi on is Firefox 33.0.2. Does the solution depend on the browser or shall I continue with the set of solutions you've already given?

    Thanks, mark59
     
  8. mark59

    mark59 MajorGeek

    In order for you to help me you need to know everything I did. Rather than open the web browser on the PC with the problem I downloaded the three tools to a different PC. I then transferred them from the PC on which I downloaded them to the PC with the problem. I did this with a USB flash drive. On the PC with the computer I transferred them from the USB flash drive to the Desktop.

    Your instructions said the AdwCleaner may take some time to complete. Just in case you need to know please be aware that it completed very quickly. It found one item that it wanted to clean. Because the instructions solely asked me to do a scan I didn’t clean the item found by AdwCleaner. The only possible thing I can see listed in the AdwCleaner log file that I would prefer to keep are the users’ Firefox profiles; however, I consider cleaning the PC to be a higher priority, even though losing Bookmarks is very frustrating.

    OTL created two txt files: one called “OTL” and one called “Extras”. I attach both.

    Please find attached four txt files.

    I now think that my other PC has the same infection. I shall run the same checks on that PC and post the files in a different post. Please advise if the three tools you’ve recommended will be sufficient or if I need to run the entire REA & RUN ME Malware Removal Thread.

    I’d be extremely interested to know, if it’s possible, on which user account the infections were introduced on to my PCs.

    As both PCs are infected am I better not using them until they’re fixed? I’d like to know because I’m without a computer until such time as they’re fixed if it’s too risky to use the PCs.

    Thanks, mark59
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You attached reports from another PC and you shouldn't have. It confuses things for BOTH of us. ;)

    I'm going to delete those logs, and we are simply going to focus on the first machine, what we've been working on all along. I can't just start fixing another pc just like that I'm afraid. Thanks for your understanding. You can begin a new thread in Malware Removal for the next machine once we have wrapped up here.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Adwcleaner and have it remove these:
    • Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
    • Key Found : HKLM\SOFTWARE\SearchProtect

    JRT found Trovi related entries. Are you having issues with Trovi still or not now? If you are I may have you do a thorough uninstall of Firefox.
     
  11. mark59

    mark59 MajorGeek

    I apologise for this. I think it's the same infection. I assumed it might have the same solution. (I'm in the process of doing the full malware removal thing on the other PC. I intend to post the results logs in a new thread.)
     
  12. mark59

    mark59 MajorGeek

    I shall run Adwcleaner and get it to remove those registry keys. Then I'll check whether Firefox is OK. I shall report back so you'll know if I shall require further help or if it's solved, thanks mark59.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ok. ;) Let me know.
     
  14. mark59

    mark59 MajorGeek

    I have run AdwCleaner and allowed it to deal with the two registry keys. Firefox now appears to be OK. I've attached the AdwCleaner log from the process just completed.

    Could you please tell me why we didn't get AdwCleaner to delete the service called SPPD and the file/folder C:\Convesoft? I don't doubt your advice, I'm just curious.

    Thanks for the help, mark59:)
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My bad, been extremely busy. With adwcleaner, you have to be careful about what it deems as bad, I had not researched those entries enough. The SPPD one relates to searchprotect you can have it remove it.
    This one relates to something pre installed on acer machines. Nothing to worry about.
    You are most welcome.
     
  16. mark59

    mark59 MajorGeek

    Can I delete the tools that we've used to clean my PC and their logs or should I keep them for a short time?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can delete them. :)
     
  18. mark59

    mark59 MajorGeek

    Thank you, will do.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds