Something Wicked This Way Came...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Mimsy, Aug 29, 2016.

  1. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    One afternoon a little over a week ago (right before we left on vacation), while my dear better half wasn't doing anything he doesn't do on the computer on a daily basis, Microsoft Security Essentials suddenly displayed a warning message that said the computer was at risk, and to call a provided phone number for help. The person that answered the call immediately stated they needed to run a scan on the computer, and proceeded to do so. The name of the scanning program is unknown (translation: he has forgotten the name). The person on the phone commented on the presence of Iobit Anti-Malware, and then went on to say that the computer needed a more thorough scan, that could be had for a one time fee, that would be applied to a credit card right there on the call. Just provide the full card info, please. At this point, my better half decided this was some kind of scam, and ended the phone call.

    Concerned about what might have been done computer, he then went on to install and run multiple anti-malware apps, hoping they would remove any malicious files installed by the (alleged?) scammer.

    MalwareBytes found something that it promptly cleaned out, but no log was collected at the time, so I can't confirm exactly what it found or what was done with it.

    Ever since this incident, Chrome starts on one of its own folders on c:\, instead of the home page it's told to start at. There is no noticeable hijacking or redirection, or any other unusual browser behavior, once you start to use Chrome to browse the web. Firefox and IE are unaffected. No other unusual computer behavior has been noticed, but since my husband is concerned that there might be malicious things left installed somewhere on his computer, he asked me to take a look. Since malware removal isn't my exactly specialty I decided to make full use of the outstanding guides available here, rather than try to figure things out on my own.

    I read through the guide for fixing browser hijack/redirection, and opted not to follow it. The thought of doing a factory reset on my router, and being forced to re-enter every single custom setting makes me cringe and whimper. I have two wireless networks, with nearly 20 devices between the two, and custom settings on everything. I would really prefer not to have to spend the rest of the day re-configuring all of that, over an issue that only affects one of the three installed browsers, on this one computer. All other wireless devices are connecting without issue or unusual behavior.

    Just to clarify: I will go back and follow the entire browser hijack fixing guide if it is necessary. I would just really prefer not to have to do so until I know for sure that it is. All the cache flushing described in that guide, including DNS cache, I had already done on my own while trying to figure out why Chrome was being so ornery.

    And yes, I'm having mental images of being yelled at for skipping steps now. :(

    I went through the entire guide for Windows 10 (64-bit), without any problems. A few notes I took along the way:

    1. When downloading all the tools and saving them to the specified locations, a very terse message popped up and told me that I did not have permission to save files to the root of C:\. I turned off all protection apps, but this made no difference. So I saved the MGTools file to Desktop and then manually moved it to the root of C:\ instead. The protection apps remained turned off for the remainder of the process.

    2. MalwareBytes didn't automatically launch after it was installed. I manually launched it by right-clicking the desktop shortcut and running it As Administrator. It claimed it didn't find anything, but I saved the log anyway. After scanning, MBAM parked itself in the system tray and kept running there throughout the rest of the process. Since it didn't interfere with any of the other tools, that I could tell, I left it running.

    3. While RougeKiller was running, Chrome suddenly opened a window to www.adlice.com/remove-pum/. Since I didn't recognize the site at all, and since RK found a few items that all were named PUM-something, I closed that browser window as soon as I could, and made sure not to accidentally click on anything in it.

    4. When I installed Hitman Pro, a message in the main program window said "Trial license expired. Removal of viruses and other malicious software is disabled." There was a link to buying the full version. Since the R&R guide said that I should not, under pain of severe pain, actually remove anything that HMP found, I ignored the message, but decided to mention it here just in case it matters.

    I think the R&R process took care of everything, but since I am not an expert, I decided to post my logs here just in case I'm wrong.

    Thank you in advance for your time, and for helping me check and verify things. :)
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, Mimsy

    I won't yell.. will go through your logs and post back.
    1) Tell your husband that MS doesn't contact users like that.
    2) MGTools needing to be run from desktop happens often.
    3) Alicedotcom is RogueKiller's developer site.
    4) Hitman Pro's expired license - no problem... the log helps me out.

    dr.m
     
    Mimsy likes this.
  3. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    1. We have had that conversation already. Let's just say I was not happy having to spend my last vacation day on computer clean-up duty... ;)
    2-4. Thanks for clearing that up! I was able to run MGTools from C:\, and have kept the file there in case I need to rerun it.

    I will now stop posting here and wait for you to post back about the logs. :)
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Nothing serious found.

    Re-run RogueKiller.exe. (Vista/Windows7/8/10 users should right-click and select "Run as Administrator")
    After it finishes the scan, under these tabs select and then click the Delete button.
    Registry
    Web browsers

    Then immediately reboot your PC.

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Upload RKreport[2].txt to your next message.
    After uploading RKreport[2].txt, now run a new scan with RogueKiller and save a log as in the original instructions and upload that new log also.

    *Update your version of Adwcleaner and do a "Scan" only > click on the Report button and upload that log, please.

    Please download ZHPcleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
      • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
      • Then press the ''Repair'' button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
    Delete this with Windows Explorer -
    C:\Users\Jim\AppData\Local???????????????????

    Please upload the requested logs and tell me how the pc is running.
     
  5. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    I re-ran the RougeKiller exe file. At the end it didn't have tabs and a delete button, but it labelled each type of threat clearly and had a very obvious "remove selected" button, so I just used that one instead. Rebooted, but I don't have an RKreport[2].txt file on my desktop. I opened a File Explorer window and ran a search for that file name, but nothing came up.

    What is the best way to get you the log you wanted? I'm holding off on following the rest of the instructions until this step has been resolved.
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) Just re-run RK and I'll compare the logs.
     
  7. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Done. Here is the log.

    The item RK found looks exactly like one of the ones I removed earlier. I didn't remove it this time, since I wasn't told to. :) Working on ZHPcleaner now, and will return with that log when I have it.
     

    Attached Files:

  8. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Almost forgot to turn off the resident anti-malware app, but thankfully ZHPcleaner reminded me. It ran for a very long time, and found a number of things. I repaired everything it found, and then I rebooted because ZHPcleaner said I needed to. The log is attached to this post.

    After reboot I also deleted that folder. I've been wanting to test Iobit's file shredder one something. :)
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) ZHPcleaner does a good job on browsers.
    If you didn't set that FF homepage, use RogueKiller again.
    Then tell me how the pc is running.
    *EDIT: How's the Chrome browser behaving also?
     
    Last edited: Aug 29, 2016
  10. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Ran RK again, and removed the Firefox item it found. That browser and IE are both behaving the same as before, that is, they are acting perfectly normal. Chrome is still opening to file:///C:/PROGRA~2/Google/Chrome/Application/, as before. Aside from that one thing, everything is back to normal.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Okay, let's reset Chrome to default settings..

    Reset Chrome to Defaults

    Then delete that Chrome shortcut, re-boot, then go to it's program folder, <edit to insert:right-click the Chrome.exe application> and create a new shortcut, send it to your desktop. Run a test or two....
     
    Last edited: Aug 29, 2016
    Mimsy likes this.
  12. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    That fixed it! Thank you very much! :)

    So am I correct in assuming the reason that didn't work yesterday was because of all the things that ZPHclener and RougeKiller removed for us?
     
    dr.moriarty likes this.
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :D Yes! (and you're very welcome!) Did you ever run Adwcleaner to see if it found anything?

    Ready for the final cleanup steps?
     
  14. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    I never did run Adwcleaner, no. My bad. It's not currently installed on that particular PC, but I can install it and run it if you want to see what it can find?

    Aside from that, yes, all set for the final steps. :)
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    To be thorough -

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.
    Please also download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
     
  16. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    I've always been a fan of being thorough. JRT log and AdwCleaner log, as requested.
     

    Attached Files:

    dr.moriarty likes this.
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Chrome is a pain, isn't it? We're almost there..being thorough pays off.

    Using AdwCleaner.exe previously downloaded:
    • Double click on AdwCleaner.exe to run the tool. (Vista, Win7/8/10 users should right-click and "Run As Administrator")
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
     
  18. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Yes,it can be. Good thing we like it so much, or we'd be tempted to get rid of it... ;)

    AdwCleaner log attached.
     

    Attached Files:

  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool:

    All Done! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    Mimsy likes this.
  20. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    ...and that should do it then. System Restore is back on, MalwareBytes and CCleaner get to stay installed, and all is well with the computer again.

    Thank you again, for helping. Believe me, it's very much appreciated. :)
     
    Kestrel13! and dr.moriarty like this.
  21. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) I appreciate that... and you're very welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds