Trojan Infection + Browser Highjacking

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bryanousa, Jun 25, 2016.

  1. bryanousa

    bryanousa Private E-2

    I am cleaning up an HP Stream 11 with Windows 8.1 with Bing for a friend.
    I first ran CCleaner , then AdwCleaner got hung up and wouldn't reinstall without uninstalling but Revo uninstaller doesn't find it.
    I can see botsford, caster, hamster, speedchecker, etc. programs installed that don't look legit.
    I uninstalled Chrome completely since it was unusable.
    And, McAfee reports a Trojan named Artemis!AA24EC62A81B that was quarantined.
    I ran all the normal scans and attached them.
    Now Malwarebytes pops up with 'malicious website blocked' at IP 82.163.143.171 about every ten seconds.
    Please take a look at my logs and see if we can clean up this mess.

    thanks
    Bryan
     

    Attached Files:

  2. bryanousa

    bryanousa Private E-2

    I also ran MBR checker and JRT; scans attached.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    It's a portable tool that doesn't not require installation

    While I look over your logs, go back and fix what Threats Hitman Pro. detected and then rerun it, posting a new log, please.

    And please wait and do things in the order that I will give you.
    PS: It's also time for my dinner. I'll post back afterwards tonight.
     
  4. bryanousa

    bryanousa Private E-2

    Thanks Dr M,
    I removed ~30 threats with Hitman; new log attached.
    Also realized I didn't have normal startup on so re-ran MGtools; new zip file attached.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool: Thanks! Don't forget to now re-run Hitman Pro for an updated log.

    I'll eat now.
    dr.m
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Per chaslang: "MBRcheck just is not real reliable anymore at detecting all the various types of MBRs that exist."

    NOTE: You have MGlog.zip downloaded and running from the wrong directory. There it will not be removed when we do our final cleanup steps... Please place it where the instructions call for.

    Did you have Malwarebytes fix what it is detecting? Always do.

    Problem:



    Do the same with RKill's Registry Items:

    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Speedchecker Limited -> Found
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\{61FFE1F9-137D-4c31-A181-3415FCAA5946} -> Found
    [VT.Unknown] (X64) HKEY_USERS\S-1-5-21-2984772500-1399138-2121128338-1001\Software\Microsoft\Windows\CurrentVersion\Run | botsford : "C:\Program Files (x86)\evolve\botsford.exe" [-] -> Found
    [VT.Unknown] (X64) HKEY_USERS\S-1-5-21-2984772500-1399138-2121128338-1001\Software\Microsoft\Windows\CurrentVersion\Run | hamster : "C:\Program Files (x86)\revolutionizes\stockade.exe" [-] -> Found
    [PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-2984772500-1399138-2121128338-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings | AutoConfigUrl : http://unstops.info/wpad.dat?f79de0eaf50cc46df919d072b29ae82c12147380 -> Found
    [PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-2984772500-1399138-2121128338-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings | AutoConfigUrl : http://unstops.info/wpad.dat?f79de0eaf50cc46df919d072b29ae82c12147380 -> Found
    [PUM.Proxy] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NlaSvc\Parameters\Internet\ManualProxies | (default) : 0http://unstops.info/wpad.dat?f79de0eaf50cc46df919d072b29ae82c12147380 -> Found
    [PUM.Proxy] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NlaSvc\Parameters\Internet\ManualProxies | (default) : 0http://unstops.info/wpad.dat?f79de0eaf50cc46df919d072b29ae82c12147380 -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.1.1 ([]) -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.1.1 ([]) -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{05B357C7-9320-4640-9472-5F008A6630E3} | DhcpNameServer : 10.0.1.1 ([]) -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{05B357C7-9320-4640-9472-5F008A6630E3} | DhcpNameServer : 10.0.1.1 ([]) -> Found

    *Reboot and re-run it. Upload that log, too.

    Delete files:
    C:\Users\jackieardoin\AppData\Local\38059195.exe
    Please perform my instructions and upload requested log
    *Tell me how the pc is running afterwards!
     
  7. bryanousa

    bryanousa Private E-2

    MGlogs.zip has been moved to the root directory.
    Reran malwarebytes; deleted all and ran log.
    Reran RKiller; deleted the registry list provided;
    reran RKiller, found the last four items still listed; deleted again and reran the report.
    Deleted the app data file listed.
    Windows is running much better.
    Internet explorer still changing the default start page and wouldn;t load your site page at first. I was able to get there through the search bar.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Okay , now run , wait 1...

    Please download ZHPcleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
      • First press the "Scanner" button. Be patient, the scan takes longer than 5 mins.
      • Then press the ''Repair'' button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
     
  9. bryanousa

    bryanousa Private E-2

    :)
    Merci, Dr.M.
    I ran ZHPCleaner and have attached the log.
    Everything seems to be running smoothly so far with no redirects in Explorer.
    Boot time is fast and no warnings from Malwarebytes.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Satisfied and ready for final cleanup steps? :cool:
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  12. bryanousa

    bryanousa Private E-2

    All running fine and ready to do the cleaning process.

    thanks again Dr,M!:D
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds