Author Topic: Help with Malware!  (Read 11624 times)

0 Members and 1 Guest are viewing this topic.

aMat

  • Guest
Help with Malware!
« on: March 11, 2014, 09:49:35 PM »
Hi,

I recently "cleaned" (or so I thought) my computer from malware software that installed itself as an enterprise extension on Chrome (YTBloccKErAAPp) . I thought I had dealt with it my own way, and from what I know, there are no unknown programs or extensions currently installed (via Chrome>Extensions or Control Panel>Add/Remove Programs).

However after a couple weeks since then I keep receiving this notification from the webshield:
http://i.imgur.com/QFh9u4g.jpg?1

The link that it's trying to redirect me to is mypageresults.com/blahblah, which from the research I've done is a commonly known browser hijacking virus.

This virus has been persistently getting more intensive, and the processes are not just chrome, but pretty much anything. I'm not sure how to deal with it. I've run an antivirus scan and a malware scan, both of which came up with nothing.  Is there a reason why this isn't popping up in any of my virus scans? And how should I go about fixing it?

I have attached various logs that I think are required for these inquiries
« Last Edit: March 11, 2014, 09:53:22 PM by aMat »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Help with Malware!
« Reply #1 on: March 11, 2014, 10:00:08 PM »
Remover Notified. Sit tight.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help with Malware!
« Reply #2 on: March 11, 2014, 11:14:04 PM »
Could you let me know if this cures it

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
O2:64bit: - BHO: (IIsaver) - {20ACB41D-AF69-DCEF-707A-780369370679} - C:\ProgramData\IIsaver\qKbqV.x64.dll File not found
O2:64bit: - BHO: (YTBloccKErAAPp) - {F3161909-8CC0-5771-E327-9A8E69C4B9C5} - C:\ProgramData\YTBloccKErAAPp\LeD9.x64.dll File not found
O2 - BHO: (YTBloccKErAAPp) - {F3161909-8CC0-5771-E327-9A8E69C4B9C5} - C:\ProgramData\YTBloccKErAAPp\LeD9.dll File not found

:Files
C:\ProgramData\IIsaver
C:\ProgramData\YTBloccKErAAPp

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

aMat

  • Guest
Re: Help with Malware!
« Reply #3 on: March 11, 2014, 11:41:22 PM »
Hey essex, thanks for the reply ! :)

I'm not too sure yet if this fixes the problem, because its more of a "wait until it pops up" kind of way of verifying.

But here are the various attached logs (post-fix, scans and adw scans). One thing to note is that the log for the ADWCleaner was in its own subdirectory and indexed at "0" (not sure if that makes a difference but saying it anyways).

If its possible, is there anything I can take away from this? I'm assuming I had lingering files from when I tried to get rid of the virus before?

Thanks for the help :)

aMat

  • Guest
Re: Help with Malware!
« Reply #4 on: March 11, 2014, 11:44:15 PM »
Well haha I just got a pop up again, so I suppose this didn't fix the issue :(

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help with Malware!
« Reply #5 on: March 12, 2014, 03:26:04 PM »
Could you confirm it is only in chrome ..  If it is then as chrome has so many hiding places I would recommend resetting it.  Details here  https://support.google.com/chrome/answer/3296214?hl=en-GB

aMat

  • Guest
Re: Help with Malware!
« Reply #6 on: March 12, 2014, 05:06:39 PM »
Actually to be fair, the pop up no longer is regarding chrome, but pretty much every other process! This is (but probably not limited to) Steam, PMB (League of Legends patcher), HexChat, Explorer, etc.

Yea I think regarding chrome, it is fixed... (?)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help with Malware!
« Reply #7 on: March 12, 2014, 05:12:30 PM »
OK lets take a better look at the services and tasks

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

aMat

  • Guest
Re: Help with Malware!
« Reply #8 on: March 12, 2014, 06:02:13 PM »
Hmmm I don't know if I can run it. I'm using Windows 8.1 and keep getting a "Can't run Combofix in Compatibility mode" error, followed by force close.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help with Malware!
« Reply #9 on: March 12, 2014, 06:57:00 PM »
No it will not work on 8.1 Duh no problem I have another tool :)

Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from. 
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

aMat

  • Guest
Re: Help with Malware!
« Reply #10 on: March 12, 2014, 08:50:02 PM »
Alright here you go.

EDIT: Just an update, I've recieved a couple webshield popups regarding chrome as well. So my previous assumption that chrome was fixed was wrong I guess :S. One thing I am noticing though is that these pop ups are a lot less frequent than before!
« Last Edit: March 12, 2014, 09:16:37 PM by aMat »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help with Malware!
« Reply #11 on: March 12, 2014, 09:12:16 PM »
Could you attach a screenshot of the next popup please as I can see no running tasks or modules that appear to cause this

aMat

  • Guest
Re: Help with Malware!
« Reply #12 on: March 12, 2014, 09:56:58 PM »
Sure no problem :)

It's hard to say what exactly prompts the redirect. I can reproduce this every time I start the League launcher, but with Steam, Chrome, Hexchat etc. its very random.

The exact Process on the popup is "Program Files(x86)\Pando Networks\Media Booster\PMB.exe", which is used for making faster downloads on League patches. A lot of people find it sketchy software but I don't personally think it is the root of the problem (it might be though!).
« Last Edit: March 12, 2014, 10:03:21 PM by aMat »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help with Malware!
« Reply #13 on: March 12, 2014, 10:00:51 PM »
I see it is coming from Pando networks not a programme that I would recommend although I believe you do need to use it for some games