Pro PC Cleaner virus and pop-up ads

Discussion in 'Malware Help (A Specialist Will Reply)' started by billiegtdr, Jan 8, 2015.

  1. billiegtdr

    billiegtdr Private E-2

    Hello,
    Yesterday while accessing a DKos article (a normally trusted site) I had a pop-up that said something about my Flash Player (I think) being out of date. I clicked on update a microsecond before I realized it was a false site. I began having redirected pages on Chrome and near-constant intrusive popups (both ads and software "update" requests). Also appearing is a suspicious program called Pro PC Cleaner that I did not knowingly download. It pretends to scan, find issues, and then a woman's voice says that issues were found. Attempts to uninstall it from the Control Panel only seemed to increase the popup frequency. Computer speed was very bogged down.

    I googled Pro PC Cleaner and found Norton Power Eraser. It found two instances of PPC, and appeared to delete them. I kept working. Shortly thereafter, PPC returned and NPE was no longer able to detect PPC even though PPC showed back up in the Control Panel.

    I came to MajorGeeks (love this site!) for further instructions. I have completed all the malware scanning steps to create logs, and refrained from actually removing anything as per instructions. All 5 report logs are attached.

    I haven't accessed many sites yet, but so far the symptoms have not returned.

    I have one question though. The instructions say not to actually delete anything, yet at the end of the steps it asks if the user is still having problems. Other than quarantining the files found by Malwarebytes, I'm not aware of any actions that were performed to resolve the issue. Did one of the recommended programs do more than I realized?

    Aside from my question above, the main reason I'm posting is because Pro PC Cleaner is still in my Control Panel, and it still refuses to uninstall.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes we want to see an overall picture of what is happening before we begin fixing.... ;)


    Uninstall these using Revo Uninstaller.

    • Pro PC Cleaner
    • Search App by Ask
    • Shopping App by Ask
    • System Checkup 3.5



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\APNMCP ("C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cozaghost ("C:\ProgramData\makulitsidwe\1.1.0.29\cozaghost.exe" /ts2=1) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cozwdhost ("C:\ProgramData\makulitsidwe\1.1.0.29\cozwdhost.exe" -scm) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\APNMCP ("C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cozaghost ("C:\ProgramData\makulitsidwe\1.1.0.29\cozaghost.exe" /ts2=1) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cozwdhost ("C:\ProgramData\makulitsidwe\1.1.0.29\cozwdhost.exe" -scm) -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\APNMCP ("C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\cozaghost ("C:\ProgramData\makulitsidwe\1.1.0.29\cozaghost.exe" /ts2=1) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\cozwdhost ("C:\ProgramData\makulitsidwe\1.1.0.29\cozwdhost.exe" -scm) -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these items on the Tasks tab please...

    • [Suspicious.Path] Digital Sites.job -- C:\Users\DRdv6\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE (/Check) -> Found
    • [Suspicious.Path] Tempo Runner coz32host.job -- C:\ProgramData\makulitsidwe\1.1.0.29\cozaghost.exe (/dgad="C:\ProgramData\makulitsidwe\1.1.0.29\coz32host.exe") -> Found
    • [Suspicious.Path] Tempo Runner coz64host.job -- C:\ProgramData\makulitsidwe\1.1.0.29\cozaghost.exe (/dgad="C:\ProgramData\makulitsidwe\1.1.0.29\coz64host.exe") -> Found
    • [Suspicious.Path] Tempo Runner cozahost.job -- C:\ProgramData\makulitsidwe\1.1.0.29\cozaghost.exe (/dgad="C:\ProgramData\makulitsidwe\1.1.0.29\cozahost.exe") -> Found
    • [Suspicious.Path] \\Check Updates -- C:\Users\DRdv6\AppData\Local\GeniusBox\tasks.exe -> Found
    • [Suspicious.Path] \\Digital Sites -- C:\Users\DRdv6\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE (/Check) -> Found
    • [Suspicious.Path] \\iolo System Checkup -- C:\ProgramData\iolo\scustask.lnk (/toaster) -> Found
    • [Suspicious.Path] \\Validate Installation -- C:\Users\DRdv6\AppData\Local\GeniusBox\uninstall.exe (/ValidateInstall=true) -> Found

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Re run Hitman Pro and have it remove all that it finds.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  3. billiegtdr

    billiegtdr Private E-2

    So far so good! Thanks for the quick response. I understood why you would want to see the complete scans before any actions were taken - actually my question was: why would any problems have gone away simply by running scans? The instructions made it sound like there was a chance that things might already be resolved at that point, so that part seemed superfluous.

    Re: how things are running... I did have a problem with the Validity Sensor causing HP SimplePass fingerprint reader to stop working but that resolved upon reboot.

    And I confess that I did not turn off Norton Security Suite before running the various programs, as I wanted to see if it recognized them all as being safe. It did.

    I'm pleased to see that JRT found and deleted more Vosteran files; I thought I'd removed those a couple of weeks ago.

    As far as I can tell, everything needed is still in order.

    Attached are the 3 log files requested.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually in addition to Malwarebytes, we have you take steps with TDSSkiller too if any issues are found! And also in the main section of the READ & RUN ME FIRST, steps 1, 3 and 5 can make changes too. ;) For the others ( as Kestrel13! stated ) we want to see what is really happening first because not everything that RogueKiller and Hitman show are problems.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re scan with RogueKiller please. (Scan only) and attach log.
     
  6. billiegtdr

    billiegtdr Private E-2

    Re-scanned using RogueKiller. Log attached.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs look good. Ready for final steps? :)
     
  8. billiegtdr

    billiegtdr Private E-2

    Ready for last steps! :)
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds