Some malware remaining after standard procedure

Discussion in 'Malware Help (A Specialist Will Reply)' started by Anabaena, Sep 21, 2013.

  1. Anabaena

    Anabaena Private E-2

    I'm trying to clean up my mother's computer because it had a whole mess of malware on it. I don't know how long it has been infected for because I haven't lived with her recently. She suspects it got on there this spring/summer when my cousin downloaded a game he plays.

    Before I did the standard procedure, I looked at the add-ons/extensions in Firefox, Chrome and IE and the unfamiliar programs in control panel. I found the following things that googling suggested to be malware:

    Hotbar
    Browse to Save
    Blinkx beat
    White Smoke
    Oberon game toolbar
    search.conduit
    Codec-V
    Conduit/mixiDJ
    Snap.do
    DomaIQ
    QuickShare
    QuickDrag
    Software Version Updater (apparently related to White Smoke)
    Search Protect by Conduit
    White Smoke New Toolbar

    I followed the standard procedure for malware removal (logs are attached) and it seemed to clear some things but the following remain:

    Blinkx beat
    Snap.do
    QuickShare

    Snap.do is not listed in control panel, but it keeps being reset as the default search engine/home page for Firefox and Chrome. My sister has told me that she's tried to get rid of Snap.do some other way before.


    The AV used on this computer is AVG 2013 Free, the OS is Windows 7.

    Thanks for your help! :)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it delete everything it found.

    Reboot and rescan with Hitman and attach the new log.

    Tell me how things are running.
     
  3. Anabaena

    Anabaena Private E-2

    Everything seems to be the same as it was before I did hitman the second time.

    I deleted everything except for MGtools (it thought it was a trojan). Of course, when I scanned after deleting and rebooting I forgot to uncheck MGtools and it deleted it. XD

    Also, if hitman is just a 30 day free trial, then will I be able to use it again in the future? (After the 30 days are up)
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, when we are finished, you can delete Hitman. Tell me what issues remain, if any. I was not seeing any additional malware in your logs.
     
  5. Anabaena

    Anabaena Private E-2

    Three of the things I suspect are malware are still on the computer.

    Blinkx beat and Quick Share might not be malware, when I search on google I get mixed results on whether or not they are. I don't think they were installed intentionally but it's possible they were accidentally installed with another program. They're both listed under Programs and Features in Control Panel so I could try uninstalling them through there.

    Snap.do is the big problem though. It doesn't seem to be affecting Chrome anymore and it was never on Internet Explorer, but it's still on Firefox. It sets http://search.snapdo.com/?st=nt&q= as the homepage and default search engine, and even if I reset to google.ca next time I restart the computer Snap.do is back. It isn't listed as an add-on in firefox.
     
  6. Anabaena

    Anabaena Private E-2

    Sorry about the reply - I was too late to edit my last one.

    I tried resetting the firefox homepage to google again and it hasn't reverted to snap.do yet so I think Hitman did work. :D Looks like snap.do is gone!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just to be sure:

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  8. Anabaena

    Anabaena Private E-2

    A couple hours after my last message snap.do was back on firefox. I reinstalled firefox and haven't seen snap.do since but I ran the Junkware Removal tool to be sure as you said.

    Thanks again!
     

    Attached Files:

    • JRT.txt
      File size:
      14.6 KB
      Views:
      1
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds