Windows 7.0 infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by DelanoJoe, Jul 31, 2013.

  1. DelanoJoe

    DelanoJoe Private E-2

    My father in-laws computer was running Norton Internet Security and the subscription ran out on Friday - that same day he was infected. I attached the log files and quite a few programs were installed on that day but I was only able to remove a couple from control panel - the rest kept popping up to wait until the other program is finished uninstalling.

    Thanks for the help
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there and welcome. Please re run Hitman and have it delete Malware and Potentially Unwanted Programs.

    Uninstall the below:

    • 24x7 Help
      [*]Iminent
      [*]MixiDJ
      [*]LessTabs
      [*]Wajam
      [*]WhiteSmoke New Toolbar
      [*]Solid Savings
      [*]Qwiklinx
      [*]GetSavin




    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Users\Lehn Financial\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-413469749-1689335336-2738114167-1000\[...]\Run : SearchProtect (C:\Users\Lehn Financial\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [V2][SUSP PATH] Updater26278.exe : C:\Users\Lehn - Financial\AppData\Local\Updater26278\Updater26278.exe /extensionid=26278 /extensionname="Solid Savings" /chromeid=cijeeimilokkhlfjombmalgpabbonmah [x][x][x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. DelanoJoe

    DelanoJoe Private E-2

    Things didn't go as expected. I ran hitman and had it delete any infected files. I tried uninstalling the programs and was able to remove 24x7, Iminent, whitesmoke new toolbar, and getsavin. Lesstabs, Wajam, Solid Savings, and Qwiklinx all said I did not have permissions to remove them. I was logged in as adminstrator.

    I continued and ran roguekillerand removed the registry items you had mentioned.

    I then downloaded JRT and ran as adminstrator. Everything it tried to do (backup registry, check startup, gave access denied messages in the dos window. There was no log file produced.

    I then attempted to run mgtools but I got a message that mgtools was incompatible with 64 bit windows. The virus's are fighting back. I was able to run mgtools previously, so something has changed.

    I attached logs that were produced.

    Thanks,

    Joe
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then uninstall those programs using Revo Uninstaller, hopefully that will remove them.

    The Hitman log appears to still show alot that should be removed, when you rescan with it, does it find plenty? If so attach the FRESH log please.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. DelanoJoe

    DelanoJoe Private E-2

    Only 2 of the 4 programs were still there - hitmanpro must have removed them - the removal program removed the other 2 fine. There is nothing in either otl.txt or extras.txt so I didn't attach. I attached the hitmanpro file, but it didn't find any infections as well. I don't know why I wasn't able to run the junkware removal or mgtools, but I think it's back to normal. I installed an antivirus and firewall, so shouldn't happen again.

    I'll wait to hear if there is anything else I should do, but I think things are back to normal.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you still attach the log from OTL regardless? (I suffer with OCD and it would go against my grain not to look at it :-D)
     
  7. DelanoJoe

    DelanoJoe Private E-2

    Actually I tried to upload them but both failed. I checked them and they were both empty and 0 bytes. I then assumed the forum would not upload empty files and thought nothing of it. I suppose I should have reran OTL because I would have expected something in the log file even if the machine was clean.

    Do you want me to retry that one more time?

    Joe
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please. Rerun again and attach the log. :)
     
  9. DelanoJoe

    DelanoJoe Private E-2

    OK - I went back to my father in-laws and was able to re-run the junkware removal program, the OTL did save an OTL.txt file and mgtools. I've got Commodo firewall setup on his computer and I have to disable it to get internet explorer to run. Not sure if he permantly blocked something he wasn't supposed to or if something else is going on. There were things found and removed by the junkware program. I guess this wasn't done yet :-o

    Joe
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Comodo can be extremely aggressive depending upon how it is set up to run. You might want to think about switching your Father to something else otherwise he ma be calling you up frequently with questions and troubles.

    What issues remain on this machine please?
     
  11. DelanoJoe

    DelanoJoe Private E-2

    He was having problems getting out to the internet which look to be related to Commodo. What firewall program do you recommend? I do believe there is still a program called reimage in the windows programs but when I run revo uninstaller, it doesn't show up. When I went to uninstall in windows, Commodo threw up a bunch of warnings and I decided I better wait. I know this program is either malware or junkware as it was loaded on the same day as the rest of them. Other than that, I don't think there is anything else that is a problem.

    Joe
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall Reimage Repair with Revo Uninstaller.

    I recommend using the windows own firewall. :) I stick with that and don't bother with third party now that I am not on XP any more. Let me know how you get on with Revo.
     
  13. DelanoJoe

    DelanoJoe Private E-2

    In my previous post I told you I couldn't uninstall with Revo Uninstaller because it doesn't show up in Revo. It shows up in the program section of windows control panel. When I went to uninstall it, Commodo complained about programs - I thought I would hold off - if you think I can just uninstall in programs section of control panel, I'll do that.

    Joe
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry about the confusion and Yes, get rid if it! Let me know if it uninstalls ok.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds