1. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Attached Files:

    • Logs.zip
      File size:
      395.7 KB
      Views:
      10
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to attach the correct log from Malware Bytes, you've attached a protection log there.

    Are you deliberately set up to use a proxy?
     
  3. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Ok will get that log - my apology

    Reference Proxy - not sure what you mean or how to check, sorry
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK then the answer is probably no. I am going to create a little fix for you, will post back soon.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove what it sees.

    You need to attach the correct log from Malware Bytes (You've attached a protection log there)



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50696;https=127.0.0.1:50696 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50696;https=127.0.0.1:50696 -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50696;https=127.0.0.1:50696 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:50696;https=127.0.0.1:50696 -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Follow these instructions to reset Firefox, I think Vosetran is embedded in it (garbage)

    Reset Mozilla Firefox to defaults



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    • Re run RogueKiller (just a scan) and attach log.
    • Same for Hitman.
    • Then you should explain how things are running.
     
  6. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Here is the malwarebytes log
     

    Attached Files:

    Last edited by a moderator: May 31, 2015
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK you need to let it remove what it finds as that log does not show that you did.
    Also move on with other instructions afterwards....
     
  8. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    When I re-run Roguekiller, in the restiry tab I don't see what you ask me to remove. I do see them in the log, but not in the tool

    Attached is a snippet of what I see now
     

    Attached Files:

    Last edited by a moderator: May 31, 2015
  9. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Re-Ran Htman Pro and deleted what it said.

    Ran Junk Removal Tool (log attached)

    Removed what Malwarebytes found, re-running now

    Still waiting on how to find the items in Rogue you asked for (see other reply with screenshot).

    I'm working on these things and appreciate all help
     

    Attached Files:

    • JRT.txt
      File size:
      3.5 KB
      Views:
      4
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just simply do scans with both Hitman and RogueKiller and attach them for me, let me see what remains or doesn't. :)
     
  11. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Re-Ran Malwarebytes.. No more items found, attaching new log
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And can you do what I asked for in post#10 please? :) Thankyou.
     
  13. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Working on it as we speak.....
     
  14. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Here is the new HitmanPro and Rogue Scan outputs....
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My apologies, checking logs now... :)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot the machine.... rescan with RogueKiller.... attach new log.
     
  17. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    The merge didnt work - see attached snippit
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't understand why it wouldn't have worked. The SID is correct... hmmm, can you try again in safe mode please?
     
  19. DeputyDawgAtl

    DeputyDawgAtl Private E-2


    Same problem in safe mode - didn't work.

    I pasted:

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"=-
    [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"=-

    [HKEY_USERS\S-1-5-21-793021716-371711806-2749729224-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NlaSvc\Parameters\Internet\ManualProxies]
    @=""
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet\ManualProxies]
    @=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "DefaultConnectionSettings"=-
    "SavedLegacySettings"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxySettingsPerUser"=dword:00000000

    Was I supposed to include the REGEDIT4???

    Anyways I saved as .reg using All files that you mentioned

    I can try to re-do with the Regedit. However, friend just got rushed to the hospital. I will need to go soon. Also with my weekday schedule I may not be able to resume until end of the week/weekend.

    Finally looks like this pc has team viewer on it, if you want to come in and poke around...
     
  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Yes!
     
  21. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    DOH... that did it..

    Now it added successfully

    Attached is the NEW Rogue output

    THANKS !!!
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The proxy is still in place, I am consulting with colleagues about it, hang in there.
     
  23. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    No worries. I appreciate all your help

    Is whatever you are,looking into causing this PC to run incredibly slow

    Btw For the other thread and this one it has improved. However with the HW on this box being fairly new and 8gb of ram I expect it to run much quicker
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes I suspect it probably is...

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"=-
    [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"=-
    
    [HKEY_USERS\S-1-5-21-793021716-371711806-2749729224-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000000
    "ProxyOverride"=-
    "ProxyServer"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NlaSvc\Parameters\Internet\ManualProxies]
    @=""
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet\ManualProxies]
    @=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "DefaultConnectionSettings"=-
    "SavedLegacySettings"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxySettingsPerUser"=dword:00000000 
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now re run RogueKiller and attach log.
     
  25. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    OK this worked sucessfully - see attached OTM Output

    I also re-ran Rouge - output also attached

    Btw I was wondering: This PC seems to have many browsers - IE FF and Chrome. Would it be worth asking my friend which one he really uses and getting rid of the others?

    Thanks
     

    Attached Files:

    Last edited by a moderator: Jun 2, 2015
  26. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    OOps... looks like last Rogue scan didn't attach
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes ask him about the browsers and be rid of ones they don't want. In fact I would like Google Chrome and Google Update Helper uninstalled if your friend doesn't mind as I want to test something. Also uninstall any protection software that may be installed (antivirus or antispyware)

    There is also something installed called "essentials" I'd like to know more about that...

    Once uninstalled (with his or her permission) run this (it takes a long time so go off and do something else for a bit)

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.


    Re run RogueKiller again and attach log.
     
  28. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Thanks, will try that all when I get home from work.

    I did talk to my friend. He prefers I.E. The reason he threw on firefox and chrome was due to the slowdown (which we now know was not related to IE). In fact IE runs a lot better now that its cache and other things have been cleaned up). So he said it was OK to remove FF and Chrome.

    Essentials, I will have to see that on the box when I'm home. I wonder if you mean Microsoft Essentials which came on during the MS updates (which btw he had NONE installed). If so then it's their free security/virus tool I think. I will check on that.

    Thanks !!!!
     
    Last edited by a moderator: Jun 2, 2015
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No I do not mean Microsoft Security Essentials. :)

    So at the same time as uninstalling Google Chrome and Google Update Helper, ensure Firefox is uninstalled too. Use Revo Uninstaller, does a better job.
     
    Last edited: Jun 2, 2015
  30. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    I ran the windows repair. Only thing I will say while it said to close other programs, I forgot to close I.E. (with this thread open). Also when it rebooted windows didn't start. I had to run the startup repair.

    Anyways, I re-ran Rogue and attaching here.

    I also uninstalled Chrome and Firefox.

    I can't find the essentials you are talking about. Where did you see it. Its late for me. I can look more tomorrow
     

    Attached Files:

  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent, the proxy has gone so it must have been tied into Google Chrome or Mozilla Firefox.

    I see "essentials" installed in the newfiles.log.

    Do this now as it's been a while: Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Essentials relates to Kodak. ;) So that's fine, but I would still like to see a fresh MGlogs.zip please.
     
  33. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Yeah he has a Kodak printer so that one stays.

    I will take care of the other stuff when I get home.

    I defiantly think progress is being made and very much appreciate all your time and help on this.
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK no problem. :)
    You are most welcome. :)
     
  35. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Here is the output zip of MGtool

    I also re-ran Rogue (since when I ran it yesterday it was before I removed Firefox and Chrome)
     

    Attached Files:

  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning :)

    Those logs look great. How're things running? Ready for final steps?
     
  37. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Overall better. But there are still some aspects that are slow.

    Many times IE will be slow and a message at the bottom saying the page isn't responding click to recover page.

    I have cleared out temp files etc.

    I guess the real test is to give back to my friend and let him use it. He is an hour away. So I want to make sure everything is best I can do to avoid a trip to take it back and work on it again. This is a VERY good friend so I don't mind helping, plus don't think he would have the patience for this :)

    Again thanks.

    Btw anything I can do to test more.. Bootups and shutdowns I would think should be quicker. On bootup after the main screen is presented I notice the disk still stays on for a bit. Not sure if there is any post-startup stuff it's doing. I looked in the msconfig file and didn't see a whole lot that was loading at startup.

    One other thing, safe mode was taking forever to come up (but I haven't tested that recently, which I will when home).

    Also I will check again for windows updates make sure that is working.
     
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can post about any remaining issues in the software forum if need be. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  39. DeputyDawgAtl

    DeputyDawgAtl Private E-2

    Thanks,

    So from your vantage point would you say all malware is gone
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Indeed. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds