Slow browsing, and browser hijack. Suspected malware.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Raphee, Nov 7, 2013.

  1. Raphee

    Raphee Private First Class

    A few days ago I installed HotSpot Shield as a VPN Proxy. It ran fine for the first few days.
    But today the computer went extremely slow. I noticed the following problems:

    Slow browsing speed.
    Browser hijack.
    Extremely slow opening of Office Applications.

    I ran Super Anti Spyware. It didn't detect anything but adware. I removed those from the computer using Super Anti Spyware.
    But after that the problem worsened. I ran Malware Byte. It caught over a hundred PUP's. I did not remove those immediately, instead I then followed the MajorGeek instructions.

    I have done the RUN and READ Me First instructions and attached the log files. Please advice, if everything is clean. I do not feel confident that it is. Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Users\Dell\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Run : BackgroundContainer ("C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Dell\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun [7][7][x]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-1429905150-4230708046-3960260400-1000\[...]\Run : SearchProtect (C:\Users\Dell\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-1429905150-4230708046-3960260400-1000\[...]\Run : BackgroundContainer ("C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Dell\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun [7][7][x]) -> FOUND
    • [V2][SUSP PATH] BackgroundContainer Startup Task : "C:\Windows\SysWOW64\Rundll32.exe" - "C:\Users\Dell\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun [7][7][x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Re run Hitman and have it delete Potential Unwanted Programs.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.




    Which browser is being affected by redirection?

    MGTools did not run to completion, please try again, ensuring UAC is disabled, and that you are indeed running as admin.

    Then attach the new MGlogs.zip.
     
  3. Raphee

    Raphee Private First Class

    Hello Kestrel,

    Thanks for the prompt reply.

    I ran RogueKiller as you advised, and deleted three files. I did not get a log report called RKreport[2].txt instead I got two txt files, which I have attached.


    I then ran Hitman. There are a number of files that the scan showed, but Hitman instructed to 'ignore' them. I thus did not delete any of them. I have attached a log of the scan results.

    JRT. txt is also attached.

    I have also attached MGlogs.zip after running a fresh scan.

    All browsers are being affected. When I open a link on anyone it takes me to Internet Explorer, or opera where it opens Anchorfree.us
    I have Chrome, IE, Opera, and Firefox on my PC.


    I must mention that after running the tests above, anchorfree.us is now not opening. So that is good news.

    I also want to inform you of two problems I failed to mention in my thread starter. See below.

    1) Super Anti Spyware automatically launches itself each time I boot up the computer.

    2) HotSpot Shield also connects at startup. Even though my initial setting was to connect on demand.

    Thanks again. Let me know what to make of the scans.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to re run Hitman again and have it delete all of the Potential Unwanted Programs. Conduit related items mostly, even if Hitman by default has them on ignore, you do need to delete them.

    You also need to have it fix all it shows on the repairs tab.

    Once done, re run Hitman and attach the new log.

    With regards to Superantispyware, I think you just need to right click on it's icon in the task tray, open the program up, and in preferences, it will give you an option to choose whether it starts or not when windows boots.

    Same with Hotspot shield, there should be a setting within it's program, if not you could use ccleaner to control it's start up, in the "tools > start up" section"

    So, just to clarify, your browsers are no longer redirecting? :confused (answer this only after getting stuff gone with Hitman)
     
  5. Raphee

    Raphee Private First Class

    Kestrel thanks for the brilliant support so far.

    Ran Hitman. Log attached after deleting all it found. I could not repair and only did a delete. Is that Ok?

    Reference SAS. It is now ok, and did not open on reboot. I did not have to do anything, it has apparently self-corrected.

    Hotspot Shield is also not activating. In fact the program seems to have changed on the PC. The desktop shortcut is no longer taking me to Hotspot. Hotspot is visible in the Programs tab. But is not shown as executable file. Should I uninstall it. Advice?

    Regarding Browsers:

    Chrome seems Ok for now.
    Opera...Ditto.
    Firefox was taken over by Hotspot and was using Hotspot browser. It has now reverted.

    IE...Still shows problem. When I opened it, it showed a message approximately saying 'your search engine has been corrupted by a program on your computer', and that I could revert the search engine settings.
    I tried to do so. Didnt work.

    IE should open at MSN.com instead it is opening at some page called linkzb.com ...> linkzb.com/country/eng/en-default.html

    This is all for so far. Thanks. Let me know next steps.
     

    Attached Files:

    Last edited by a moderator: Nov 9, 2013
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think our Hitman fix included some parts of HSS and broke it. Yes, a reinstall will have to take place. :)

    Does changing the home page not correct it?


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. Raphee

    Raphee Private First Class

    Hello Kestrel.

    Yes, I have changed IE page to msn. Has worked fine so far.

    OTL logs are attached.

    There is a definite improvement in the performance of the laptop. Thanks for your help.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ready for final steps? :)
     
  9. Raphee

    Raphee Private First Class

    All set, Sir.

    Just give your orders.:major
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sir? I'm female. :) No offence taken.... :p

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  11. Raphee

    Raphee Private First Class

    Kestrel Hi,

    I am now satisfied with PC behavior. I have done all the steps. Should I also do a System Restore, and anything else indicated in RUN AND READ ME.

    Thanks.

    PS: You're still boss, irrespective of gender. In fact a female boss sounds better for a change ;)
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Chaslang's the boss! LOL

    No, I wouldn't do a system restore. We're good now. I think the last steps I gave you covered everything. :)
     
  13. Raphee

    Raphee Private First Class

    And just when I had my hopes pinned on you. Well...I'll get infected to meet you up another day :p

    Thanks Kestrel. You've been great.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome, Raphee, take care.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds