Something Wicked This Way Comes

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Carl Lacy, Nov 13, 2017.

  1. Carl Lacy

    Carl Lacy Private E-2

    Something untoward is on my system. Could not get into forum for over a week. History here

    10/20 - Clean install of Windows 10 (not because of virus, just because of new PC)
    11/2 - Most recent programs installed (DoPDF 9.0, Itunes, Foxit, Dropbox, One Drive)
    11/4 Malwarebytes blocks 4 suspicious outgoing messages to "discountedshoes.review" 216.12.173.98
    11/6 Attempt to run both TDSS killer and avast aswMBR results in BSOD before program initialize
    (Tried later booting system into safe mode and same result)
    11/6 HitmanPro detects suspicious file c:\..drivers\76102391.sys and 91616367.sys dated 11/6/16
    (could not get registered into forum so I manually deleted these files)
    Malwarebytes detects PUP.Optional.Ilivid, in C:\..\APPLECOMPUTER\MOBILESYNC\BACKUP,
    Quarantined,
    MalwareHunter (Glary) says c:\..SysWow64\GameBarPresenceWriter.exe and isoburn.exe infected
    with TR/Crypt.XPAC.Gen3. However, these files show same modification date of system install
    9/29/17
    11/12 HitmanPro detects 4 new suspicious files in c\..system32\drivers. Similar pattern. (manual delete)
    11/13 Able to run Malwarebytes Mbar rooktit Beta and Bitdefender bookit - no suspicious files
    GMER detects hidden file C:\..drivers\TrueSight.sys GMER says it has found system modification
    Now I am in the forum, so I have attached logs from GMER, HitmanPro and MGtools
    Nothing else has found much -only GMER

    I did follow your ReadMeFirst guide back on 11/6 but I could not get into the forum and I had to improvise. It seems that GMER is onto something - but what to do about it.

    Thanks!!!!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have Hitman remove what it found (TrueSight). Then right click start/run/ and type in %temp% and clean out all it finds.

    I am not seeing any other malware. What are your main issues?
     
  3. Carl Lacy

    Carl Lacy Private E-2

    No symptoms yet, Master. However, 1) system tried to making outgoing calls to some unknown site (although that has stopped), and 2) every few days since then a new suspicious file starts showing up in my c:\..\drivers file. Didn't want to wait for trouble.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will leave this thread open in case you encounter another suspicious file. Just let me know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds