Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Audio Ads Playing in background


  • This topic is locked This topic is locked
19 replies to this topic

#1 DM2-Inc

DM2-Inc

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:39 AM

Posted 13 November 2015 - 12:33 AM

Hi folks...and hope you can help

 

I'm running Windows 7, 64 Bit

 

I've read a number of threads here on the subject, and tried a number of programs to clear this up, but no luck as of yet.  I also believe I have the "Proxy 127.0.0.1".  Using Admin rights I've tried to change the DWord for "ProxyEnable" to "0", and delete "ProxyServer", which was set to "http=127.0.0.1:8877;https=127.0.0.1:8877", but it keeps coming back.

 

I've downloaded the current versions, and virus databases of:

- Malwarebytes
- HitmanPro_x64

- SpyHunter

- tdsskiller

- ESET

- Adwcleaner 5.019

 

I've also downloaded the below files based on what i've read here, run them, and saved the text file:

- ESET

- Rkill

- Junkware Removal

- Adwcleaner

 

In may cases I have to run "RKill" again to launch the program.  Prior to realizing what RKill was, I was running in SAFE MODE.

 

Below are the FRST text files.  I sure hope someone can help

 

Attached Files



BC AdBot (Login to Remove)

 


#2 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:39 AM

Posted 13 November 2015 - 10:41 AM

Hi there, I will be helping you with your malware related problems.

 

Can you please upload the below files:

  • C:\Program Files (x86)\claim\remember.exe
  • C:\Program Files (x86)\repulsive\cars.exe

To this link for review?

 

Thank you



#3 DM2-Inc

DM2-Inc
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:39 AM

Posted 13 November 2015 - 10:58 AM

Files have been uploaded.

 

The Total Virus web site provided the following probability ratios for the two files (after reanalyzing):

Remember.exe = 0/54

Cars.exe = 0/53



#4 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:39 AM

Posted 13 November 2015 - 11:11 AM

Thank you for that. Please continue with the below steps.

 

 

 

frst.pngfrstfix.png

  • Please download the following Attached File  fixlist.txt   7.33KB   7 downloads
  • Place it in the same directory as FRST

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please post it to your reply.

 

__

 

 

Do you know if you installed "FastInternet" willingly? It should be visible from Control Panel -> Programs and Features

If are unsure what it is and are still experiencing issues, I would uninstall it if it allows you to. Let me know if you have problems with this step though.


Edited by thisisu, 13 November 2015 - 11:30 AM.


#5 DM2-Inc

DM2-Inc
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:39 AM

Posted 13 November 2015 - 11:30 AM

Farbar appears to have locked up.  Is it acceptable to use task manager to shut it down and restart?

 

With regard to "FastInternet", I have to say no.  I'm not usually willing to buy into such features.



#6 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:39 AM

Posted 13 November 2015 - 11:32 AM

Yes, but give me a second. I'm editing the previous script. I'll post the new one after this post.


Edited by thisisu, 13 November 2015 - 11:32 AM.


#7 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:39 AM

Posted 13 November 2015 - 11:34 AM

Ok, here is the newest script: Attached File  fixlist.txt   7.49KB   5 downloads

 

Also, it may be easier to attempt this from Safe Mode if you continue to have issues with FRST locking up.

 

 



#8 DM2-Inc

DM2-Inc
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:39 AM

Posted 13 November 2015 - 11:40 AM

Farbar locked up so I used Task Manager to shut it down and restart as Admin.

With respect to "FastInternet", I did not willingly install this

 

I've now discovered that using the advanced posting options I can simply "Attached" the files vs. placing them in between Code Tags.  Is there a preference?

 

FixLog.txt

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by dmarr (2015-11-13 10:32:38) Run:2
Running from D:\Utilities\Malware
Loaded Profiles: dmarr (Available Profiles: DMarr & dmarr)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
File: C:\Program Files (x86)\claim\remember.exe
File: C:\Program Files (x86)\repulsive\cars.exe
File: C:\Program Files (x86)\rude\winter.exe
File: C:\Program Files (x86)\repulsive\debonair.exe
Folder: C:\Program Files (x86)\repulsive
Folder: C:\Program Files (x86)\claim
GroupPolicyScripts: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 1 <======= ATTENTION (Restriction - ProxySettings)
ProxyEnable: [HKLM-x32] => Proxy is enabled.
ProxyServer: [HKLM-x32] => http=127.0.0.1:8877;https=127.0.0.1:8877
AutoConfigURL: [HKLM] => http=127.0.0.1:8877;https=127.0.0.1:8877
ProxyEnable: [S-1-5-21-4109533768-3781963708-1875491839-1132] => Proxy is enabled.
ProxyServer: [S-1-5-21-4109533768-3781963708-1875491839-1132] => http=127.0.0.1:8877;https=127.0.0.1:8877
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
FF user.js: detected! => D:\Internet\WaterFox\Profile\user.js [2014-08-09]
FF SearchPlugin: D:\Internet\WaterFox\Profile\searchplugins\Funmoods.xml [2013-01-27]
2015-11-10 13:38 - 2015-11-12 23:08 - 00003628 _____ C:\Windows\System32\Tasks\MySystemiTools
2015-11-10 13:38 - 2015-11-12 22:20 - 00003808 _____ C:\Windows\System32\Tasks\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048
2015-11-10 13:37 - 2015-11-12 23:07 - 00003808 _____ C:\Windows\System32\Tasks\Grapyy42631311Updates
2015-11-10 13:37 - 2015-11-12 23:07 - 00003638 _____ C:\Windows\System32\Tasks\MySyy42631311ytemy
2015-11-10 13:37 - 2015-11-12 22:40 - 00004346 _____ C:\Windows\System32\Tasks\72634775
2015-11-10 13:37 - 2015-11-12 22:20 - 00003810 _____ C:\Windows\System32\Tasks\4991101
2015-11-10 13:37 - 2015-11-10 13:38 - 00000000 ____D C:\Users\DMarr.AFP\AppData\Local\7165185
Folder: C:\Program Files (x86)\person
Folder: C:\Program Files (x86)\rude
C:\a
C:\Program Files (x86)\person
C:\Program Files (x86)\rude
C:\Program Files (x86)\claim
C:\Program Files (x86)\repulsive
2015-11-10 13:37 - 2015-11-10 13:37 - 00000000 ____D C:\Users\DMarr.AFP\AppData\Local\55088376
File: C:\Windows\pale.exe
C:\Windows\pale.exe
File: C:\Windows\overjoyed.exe
C:\Windows\overjoyed.exe
File: C:\Windows\reproduce.exe
C:\Windows\reproduce.exe
File: C:\Windows\instruct.exe
C:\Windows\instruct.exe
2015-11-10 12:01 - 2015-11-10 12:01 - 00000019 _____ C:\Windows\SysWOW64\77600582.bat
Folder: C:\Program Files (x86)\FreeSmartSoft
Task: {0058318A-B872-4D45-B961-9C781B4969BC} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
Task: {2B3E0AAD-CC58-4CD1-90BC-82994249DD02} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-5_user -> No File <==== ATTENTION
Task: {3936D2FC-B540-4C9C-8E2B-50C12DF674A8} - \globalUpdateUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {3E42CCD4-EAFA-44FD-958E-B9BB53E65B2D} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-1-6 -> No File <==== ATTENTION
Task: {76C64E5C-4850-493E-864A-A3997DBC8D8E} - System32\Tasks\Grapyy42631311Updates => C:\Program Files (x86)\rude\winter.exe [2015-11-10] (peck)
Task: {7A2FF997-78B8-4B9C-BA12-5C5B0F199714} - \globalUpdateUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {88665EBF-9E68-4483-8A30-7995C2F7FBA8} - \SPBIW_UpdateTask_Time_3338333337383532372d4a4a5b415a34782a456c375a -> No File <==== ATTENTION
Task: {94D8AEF0-EADE-4AB9-9C29-EE1DBB18B659} - System32\Tasks\4991101 => C:\Program Files (x86)\claim\remember.exe [2015-11-10] () <==== ATTENTION
Task: {9685B63F-A893-4859-A401-8356BA3BCDFF} - System32\Tasks\MySyy42631311ytemy => C:\Program Files (x86)\rude\winter.exe [2015-11-10] (peck)
Task: {996DD2A3-B967-46A6-9B7A-C729D6747863} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {9D0F7A5C-C707-47F6-B285-ED3222E65E01} - System32\Tasks\MySystemiTools => C:\Program Files (x86)\repulsive\cars.exe [2015-11-10] (windows 99)
Task: {9D872283-9FAD-4103-8749-6331A69C2CD2} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-5 -> No File <==== ATTENTION
Task: {B01F8BC6-05CA-479C-A1AC-FDE7DAF3ADFD} - System32\Tasks\72634775 => C:\Program Files (x86)\repulsive\cars.exe [2015-11-10] (windows 99) <==== ATTENTION
Task: {B7937BD6-7FAD-4410-90AD-8ADB12CDAC52} - \SPBIW_UpdateTask_Time_3338333337383532372d4a505b575a32786c452a3745 -> No File <==== ATTENTION
Task: {BC4D3106-8749-47FD-85F6-0298B2C16289} - \PC SpeedUp Service Deactivator -> No File <==== ATTENTION
Task: {BCAE12A6-630F-4199-845E-5E3F088F9EB4} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-1-7 -> No File <==== ATTENTION
Task: {CB77455F-179E-4E1A-BD80-9311C4C64698} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-10_user -> No File <==== ATTENTION
Task: {CF016AF0-679D-4740-A54D-BA7CAE161EC8} - \ShopperPro -> No File <==== ATTENTION
Task: {D4AC5518-3738-44EC-8892-83BABD7401AC} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
Task: {E5230EE8-1FD4-42D0-94CD-48CFF133A29E} - System32\Tasks\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048 => C:\Program Files (x86)\repulsive\cars.exe [2015-11-10] (windows 99)
Task: {F4161E9C-612E-45C5-AD8C-3603059BE102} - \SPDriver -> No File <==== ATTENTION
Task: {F9D7DE31-6A92-44B1-9EFD-ACE7A7A34809} - \Inst_Rep -> No File <==== ATTENTION
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3229
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3282
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3383
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\62015111.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\62015111.sys => ""="Driver"
FirewallRules: [{FB9E0FDC-5527-4A26-91E3-CF6FF6598961}] => (Allow) C:\Program Files (x86)\repulsive\cars.exe
FirewallRules: [{829492D7-7D9C-4891-906A-6DBB0B1A8D49}] => (Allow) C:\Program Files (x86)\repulsive\cars.exe
FirewallRules: [{36EDCAA4-DF76-4875-A55D-BC753DEE3936}] => (Allow) C:\Program Files (x86)\repulsive\getcap.exe
FirewallRules: [{CDC349F4-E9B9-4B26-A27D-5D5CF24C8546}] => (Allow) C:\Program Files (x86)\repulsive\getcap.exe
FirewallRules: [{F2C030BA-027F-4877-B329-3C0E0B5DED2C}] => (Allow) C:\a\winonit.exe
FirewallRules: [{C7DC01AE-E476-4F63-92CC-CDF71A6839E7}] => (Allow) C:\a\winonit.exe
FirewallRules: [{BE48D92F-4E68-490B-BD76-00B3AB60930F}] => (Allow) C:\Program Files (x86)\repulsive\debonair.exe
FirewallRules: [{381F47AA-A78B-4CAC-AACC-C0A20B071DB6}] => (Allow) C:\Program Files (x86)\repulsive\debonair.exe
FirewallRules: [{7AAF4DD7-561E-4C56-891F-61B3AB6181A5}] => (Allow) C:\a\vchk.exe
FirewallRules: [{320AD4F2-B684-4132-96E4-A77227A8EB0C}] => (Allow) C:\a\vchk.exe
FirewallRules: [{5A4B9AA0-6606-4F45-8F2A-E34FF6ADAEFD}] => (Allow) C:\a\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048.exe
FirewallRules: [{9F11AE87-85A2-4FB4-8D35-538C289DA366}] => (Allow) C:\a\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048.exe
FirewallRules: [{DB649646-CD99-4262-92EA-321661A72C3C}] => (Allow) C:\Program Files (x86)\rude\winter.exe
FirewallRules: [{AE3AC6DE-B6B1-4F0D-99D8-036C568AC8AE}] => (Allow) C:\Program Files (x86)\rude\winter.exe
FirewallRules: [{BB4FF719-DC18-44D6-95B9-BA5C69E78B6D}] => (Allow) C:\Program Files (x86)\claim\remember.exe
FirewallRules: [{C297EC50-BBFA-4069-A311-CE8A37140F86}] => (Allow) C:\Program Files (x86)\claim\remember.exe
cmd: bitsadmin /reset /allusers
cmd: netsh winsock reset catalog
cmd: ipconfig /flushdns
RemoveProxy:
Hosts:
EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.

========================= File: C:\Program Files (x86)\claim\remember.exe ========================

"C:\Program Files (x86)\claim\remember.exe" => not found.
====== End of File: ======


========================= File: C:\Program Files (x86)\repulsive\cars.exe ========================

"C:\Program Files (x86)\repulsive\cars.exe" => not found.
====== End of File: ======


========================= File: C:\Program Files (x86)\rude\winter.exe ========================

"C:\Program Files (x86)\rude\winter.exe" => not found.
====== End of File: ======


========================= File: C:\Program Files (x86)\repulsive\debonair.exe ========================

"C:\Program Files (x86)\repulsive\debonair.exe" => not found.
====== End of File: ======


========================= Folder: C:\Program Files (x86)\repulsive ========================

not found.

====== End of Folder: ======


========================= Folder: C:\Program Files (x86)\claim ========================

not found.

====== End of Folder: ======

"C:\Windows\system32\GroupPolicy\Machine" => not found.
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxySettingsPerUser => value not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value not found.
HKU\S-1-5-21-4109533768-3781963708-1875491839-1132\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\S-1-5-21-4109533768-3781963708-1875491839-1132\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found. 
HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found. 
D:\Internet\WaterFox\Profile\user.js => not found.
"D:\Internet\WaterFox\Profile\searchplugins\Funmoods.xml" => not found.
"C:\Windows\System32\Tasks\MySystemiTools" => not found.
"C:\Windows\System32\Tasks\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048" => not found.
"C:\Windows\System32\Tasks\Grapyy42631311Updates" => not found.
"C:\Windows\System32\Tasks\MySyy42631311ytemy" => not found.
"C:\Windows\System32\Tasks\72634775" => not found.
"C:\Windows\System32\Tasks\4991101" => not found.
"C:\Users\DMarr.AFP\AppData\Local\7165185" => not found.

========================= Folder: C:\Program Files (x86)\person ========================

not found.

====== End of Folder: ======


========================= Folder: C:\Program Files (x86)\rude ========================

not found.

====== End of Folder: ======

"C:\a" => not found.
"C:\Program Files (x86)\person" => not found.
"C:\Program Files (x86)\rude" => not found.
"C:\Program Files (x86)\claim" => not found.
"C:\Program Files (x86)\repulsive" => not found.
"C:\Users\DMarr.AFP\AppData\Local\55088376" => not found.

========================= File: C:\Windows\pale.exe ========================

"C:\Windows\pale.exe" => not found.
====== End of File: ======

"C:\Windows\pale.exe" => not found.

========================= File: C:\Windows\overjoyed.exe ========================

"C:\Windows\overjoyed.exe" => not found.
====== End of File: ======

"C:\Windows\overjoyed.exe" => not found.

========================= File: C:\Windows\reproduce.exe ========================

"C:\Windows\reproduce.exe" => not found.
====== End of File: ======

"C:\Windows\reproduce.exe" => not found.

========================= File: C:\Windows\instruct.exe ========================

"C:\Windows\instruct.exe" => not found.
====== End of File: ======

"C:\Windows\instruct.exe" => not found.
"C:\Windows\SysWOW64\77600582.bat" => not found.

========================= Folder: C:\Program Files (x86)\FreeSmartSoft ========================

2015-10-31 12:22 - 2015-10-31 12:30 - 0000000 ____D () C:\Program Files (x86)\FreeSmartSoft\FSSGoogleMapsDownloader
2015-10-31 12:22 - 2015-10-31 12:30 - 0000495 _____ () C:\Program Files (x86)\FreeSmartSoft\FSSGoogleMapsDownloader\debug.log

====== End of Folder: ======

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0058318A-B872-4D45-B961-9C781B4969BC} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SwiftSearch Auto Updater 1.10.0.25 Pending Update => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B3E0AAD-CC58-4CD1-90BC-82994249DD02} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-5_user => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3936D2FC-B540-4C9C-8E2B-50C12DF674A8} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E42CCD4-EAFA-44FD-958E-B9BB53E65B2D} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-1-6 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{76C64E5C-4850-493E-864A-A3997DBC8D8E} => key not found. 
C:\Windows\System32\Tasks\Grapyy42631311Updates => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Grapyy42631311Updates => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A2FF997-78B8-4B9C-BA12-5C5B0F199714} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88665EBF-9E68-4483-8A30-7995C2F7FBA8} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_3338333337383532372d4a4a5b415a34782a456c375a => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94D8AEF0-EADE-4AB9-9C29-EE1DBB18B659} => key not found. 
C:\Windows\System32\Tasks\4991101 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4991101 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9685B63F-A893-4859-A401-8356BA3BCDFF} => key not found. 
C:\Windows\System32\Tasks\MySyy42631311ytemy => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySyy42631311ytemy => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{996DD2A3-B967-46A6-9B7A-C729D6747863} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9D0F7A5C-C707-47F6-B285-ED3222E65E01} => key not found. 
C:\Windows\System32\Tasks\MySystemiTools => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySystemiTools => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9D872283-9FAD-4103-8749-6331A69C2CD2} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-5 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B01F8BC6-05CA-479C-A1AC-FDE7DAF3ADFD} => key not found. 
C:\Windows\System32\Tasks\72634775 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\72634775 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7937BD6-7FAD-4410-90AD-8ADB12CDAC52} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_3338333337383532372d4a505b575a32786c452a3745 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC4D3106-8749-47FD-85F6-0298B2C16289} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC SpeedUp Service Deactivator => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCAE12A6-630F-4199-845E-5E3F088F9EB4} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-1-7 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CB77455F-179E-4E1A-BD80-9311C4C64698} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-10_user => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF016AF0-679D-4740-A54D-BA7CAE161EC8} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4AC5518-3738-44EC-8892-83BABD7401AC} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SwiftSearch Auto Updater 1.10.0.25 Core => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5230EE8-1FD4-42D0-94CD-48CFF133A29E} => key not found. 
C:\Windows\System32\Tasks\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4161E9C-612E-45C5-AD8C-3603059BE102} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9D7DE31-6A92-44B1-9EFD-ACE7A7A34809} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Inst_Rep => key not found. 
"C:\Windows\SysWOW64\MSIHANDLE" => ":3229" ADS not found.
"C:\Windows\SysWOW64\MSIHANDLE" => ":3282" ADS not found.
"C:\Windows\SysWOW64\MSIHANDLE" => ":3383" ADS not found.
"C:\ProgramData\Reprise" => ":wupeogjxldtlfudivq`qsp`26hfm" ADS not found.
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\62015111.sys => key not found. 
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\62015111.sys => key not found. 
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FB9E0FDC-5527-4A26-91E3-CF6FF6598961} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{829492D7-7D9C-4891-906A-6DBB0B1A8D49} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{36EDCAA4-DF76-4875-A55D-BC753DEE3936} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CDC349F4-E9B9-4B26-A27D-5D5CF24C8546} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F2C030BA-027F-4877-B329-3C0E0B5DED2C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C7DC01AE-E476-4F63-92CC-CDF71A6839E7} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BE48D92F-4E68-490B-BD76-00B3AB60930F} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{381F47AA-A78B-4CAC-AACC-C0A20B071DB6} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7AAF4DD7-561E-4C56-891F-61B3AB6181A5} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{320AD4F2-B684-4132-96E4-A77227A8EB0C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5A4B9AA0-6606-4F45-8F2A-E34FF6ADAEFD} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9F11AE87-85A2-4FB4-8D35-538C289DA366} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DB649646-CD99-4262-92EA-321661A72C3C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AE3AC6DE-B6B1-4F0D-99D8-036C568AC8AE} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BB4FF719-DC18-44D6-95B9-BA5C69E78B6D} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C297EC50-BBFA-4069-A311-CE8A37140F86} => value not found.

=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {070BD699-35A4-4A70-9651-3C2AB934BA5F}.
Unable to cancel {94AC2EBB-DA96-4B16-B2C6-4E6BC4CC166C}.
Unable to cancel {C760C4C7-7F68-4F26-8402-4A08A43D4C4E}.
0 out of 3 jobs canceled.

========= End of CMD: =========


=========  netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-4109533768-3781963708-1875491839-1132\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-4109533768-3781963708-1875491839-1132\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 689.3 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 10:32:45 ====


#9 DM2-Inc

DM2-Inc
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:39 AM

Posted 13 November 2015 - 11:44 AM

My apologies but I loaded the first "Fix" file you posted.  After the lockup, Firefox shutdown.  I started firefox again and posted the original "...locked up..." message.  When I restarted the Farbar the 2nd time, all went well and it rebooted.  The post above is the "Fixlog.txt" file is not a result of your 2nd fix file.



#10 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:39 AM

Posted 13 November 2015 - 11:47 AM

It's ok.

 

First please upload the following files for review here again 

 

  • C:\Windows\reproduce.exe
  • C:\Windows\instruct.exe

If they aren't here, check in C:\FRST\Quarantine\C\WINDOWS

 

Once you've done that, then run the 2nd fixlist.txt provided in post #7.

 

Then uninstall "FastInternet"


Edited by thisisu, 13 November 2015 - 11:50 AM.


#11 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:39 AM

Posted 13 November 2015 - 11:48 AM

"Attached" the files vs. placing them in between Code Tags.  Is there a preference?

 

 

No preference from me.



#12 DM2-Inc

DM2-Inc
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:39 AM

Posted 13 November 2015 - 12:07 PM

The two files (reproduce.exe and instruct.exe) were not in the C:\Windows folder, but rather in the C:\FRST\Quarantine\C\Windows folder, and the file extensions for both were changed to "...exe.xBad".  Both file have been uploaded to the link you provided.

 

I uninstalled "Fastinternet" but received an error in the process stating that the file was already uninstalled and then asked if I wanted to remove it from the list, which I replied "YES" to.

 

Below is the new FixLog.txt file (which was performed before I attempted to uninstall "FastInternet"

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by dmarr (2015-11-13 11:00:15) Run:3
Running from D:\Utilities\Malware
Loaded Profiles: dmarr (Available Profiles: DMarr & dmarr)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
File: C:\Program Files (x86)\claim\remember.exe
File: C:\Program Files (x86)\repulsive\cars.exe
File: C:\Program Files (x86)\rude\winter.exe
File: C:\Program Files (x86)\repulsive\debonair.exe
Folder: C:\Program Files (x86)\repulsive
Folder: C:\Program Files (x86)\claim
GroupPolicyScripts: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 1 <======= ATTENTION (Restriction - ProxySettings)
ProxyEnable: [HKLM-x32] => Proxy is enabled.
ProxyServer: [HKLM-x32] => http=127.0.0.1:8877;https=127.0.0.1:8877
AutoConfigURL: [HKLM] => http=127.0.0.1:8877;https=127.0.0.1:8877
ProxyEnable: [S-1-5-21-4109533768-3781963708-1875491839-1132] => Proxy is enabled.
ProxyServer: [S-1-5-21-4109533768-3781963708-1875491839-1132] => http=127.0.0.1:8877;https=127.0.0.1:8877
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
FF user.js: detected! => D:\Internet\WaterFox\Profile\user.js [2014-08-09]
FF SearchPlugin: D:\Internet\WaterFox\Profile\searchplugins\Funmoods.xml [2013-01-27]
S2 prick; C:\Windows\reproduce.exe [19456 2015-11-10] (sleep) [File not signed]
S4 arrogant; C:\Windows\instruct.exe [8704 2015-11-10] (freezing) [File not signed]
2015-11-10 13:38 - 2015-11-12 23:08 - 00003628 _____ C:\Windows\System32\Tasks\MySystemiTools
2015-11-10 13:38 - 2015-11-12 22:20 - 00003808 _____ C:\Windows\System32\Tasks\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048
2015-11-10 13:37 - 2015-11-12 23:07 - 00003808 _____ C:\Windows\System32\Tasks\Grapyy42631311Updates
2015-11-10 13:37 - 2015-11-12 23:07 - 00003638 _____ C:\Windows\System32\Tasks\MySyy42631311ytemy
2015-11-10 13:37 - 2015-11-12 22:40 - 00004346 _____ C:\Windows\System32\Tasks\72634775
2015-11-10 13:37 - 2015-11-12 22:20 - 00003810 _____ C:\Windows\System32\Tasks\4991101
2015-11-10 13:37 - 2015-11-10 13:38 - 00000000 ____D C:\Users\DMarr.AFP\AppData\Local\7165185
Folder: C:\Program Files (x86)\person
Folder: C:\Program Files (x86)\rude
C:\a
C:\Program Files (x86)\person
C:\Program Files (x86)\rude
2015-11-10 13:37 - 2015-11-10 13:37 - 00000000 ____D C:\Users\DMarr.AFP\AppData\Local\55088376
File: C:\Windows\pale.exe
C:\Windows\pale.exe
File: C:\Windows\overjoyed.exe
C:\Windows\overjoyed.exe
File: C:\Windows\reproduce.exe
C:\Windows\reproduce.exe
File: C:\Windows\instruct.exe
C:\Windows\instruct.exe
2015-11-10 12:01 - 2015-11-10 12:01 - 00000019 _____ C:\Windows\SysWOW64\77600582.bat
Folder: C:\Program Files (x86)\FreeSmartSoft
Task: {0058318A-B872-4D45-B961-9C781B4969BC} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
Task: {2B3E0AAD-CC58-4CD1-90BC-82994249DD02} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-5_user -> No File <==== ATTENTION
Task: {3936D2FC-B540-4C9C-8E2B-50C12DF674A8} - \globalUpdateUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {3E42CCD4-EAFA-44FD-958E-B9BB53E65B2D} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-1-6 -> No File <==== ATTENTION
Task: {76C64E5C-4850-493E-864A-A3997DBC8D8E} - System32\Tasks\Grapyy42631311Updates => C:\Program Files (x86)\rude\winter.exe [2015-11-10] (peck)
Task: {7A2FF997-78B8-4B9C-BA12-5C5B0F199714} - \globalUpdateUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {88665EBF-9E68-4483-8A30-7995C2F7FBA8} - \SPBIW_UpdateTask_Time_3338333337383532372d4a4a5b415a34782a456c375a -> No File <==== ATTENTION
Task: {94D8AEF0-EADE-4AB9-9C29-EE1DBB18B659} - System32\Tasks\4991101 => C:\Program Files (x86)\claim\remember.exe [2015-11-10] () <==== ATTENTION
Task: {9685B63F-A893-4859-A401-8356BA3BCDFF} - System32\Tasks\MySyy42631311ytemy => C:\Program Files (x86)\rude\winter.exe [2015-11-10] (peck)
Task: {996DD2A3-B967-46A6-9B7A-C729D6747863} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {9D0F7A5C-C707-47F6-B285-ED3222E65E01} - System32\Tasks\MySystemiTools => C:\Program Files (x86)\repulsive\cars.exe [2015-11-10] (windows 99)
Task: {9D872283-9FAD-4103-8749-6331A69C2CD2} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-5 -> No File <==== ATTENTION
Task: {B01F8BC6-05CA-479C-A1AC-FDE7DAF3ADFD} - System32\Tasks\72634775 => C:\Program Files (x86)\repulsive\cars.exe [2015-11-10] (windows 99) <==== ATTENTION
Task: {B7937BD6-7FAD-4410-90AD-8ADB12CDAC52} - \SPBIW_UpdateTask_Time_3338333337383532372d4a505b575a32786c452a3745 -> No File <==== ATTENTION
Task: {BC4D3106-8749-47FD-85F6-0298B2C16289} - \PC SpeedUp Service Deactivator -> No File <==== ATTENTION
Task: {BCAE12A6-630F-4199-845E-5E3F088F9EB4} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-1-7 -> No File <==== ATTENTION
Task: {CB77455F-179E-4E1A-BD80-9311C4C64698} - \fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-10_user -> No File <==== ATTENTION
Task: {CF016AF0-679D-4740-A54D-BA7CAE161EC8} - \ShopperPro -> No File <==== ATTENTION
Task: {D4AC5518-3738-44EC-8892-83BABD7401AC} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
Task: {E5230EE8-1FD4-42D0-94CD-48CFF133A29E} - System32\Tasks\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048 => C:\Program Files (x86)\repulsive\cars.exe [2015-11-10] (windows 99)
Task: {F4161E9C-612E-45C5-AD8C-3603059BE102} - \SPDriver -> No File <==== ATTENTION
Task: {F9D7DE31-6A92-44B1-9EFD-ACE7A7A34809} - \Inst_Rep -> No File <==== ATTENTION
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3229
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3282
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3383
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\62015111.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\62015111.sys => ""="Driver"
FirewallRules: [{FB9E0FDC-5527-4A26-91E3-CF6FF6598961}] => (Allow) C:\Program Files (x86)\repulsive\cars.exe
FirewallRules: [{829492D7-7D9C-4891-906A-6DBB0B1A8D49}] => (Allow) C:\Program Files (x86)\repulsive\cars.exe
FirewallRules: [{36EDCAA4-DF76-4875-A55D-BC753DEE3936}] => (Allow) C:\Program Files (x86)\repulsive\getcap.exe
FirewallRules: [{CDC349F4-E9B9-4B26-A27D-5D5CF24C8546}] => (Allow) C:\Program Files (x86)\repulsive\getcap.exe
FirewallRules: [{F2C030BA-027F-4877-B329-3C0E0B5DED2C}] => (Allow) C:\a\winonit.exe
FirewallRules: [{C7DC01AE-E476-4F63-92CC-CDF71A6839E7}] => (Allow) C:\a\winonit.exe
FirewallRules: [{BE48D92F-4E68-490B-BD76-00B3AB60930F}] => (Allow) C:\Program Files (x86)\repulsive\debonair.exe
FirewallRules: [{381F47AA-A78B-4CAC-AACC-C0A20B071DB6}] => (Allow) C:\Program Files (x86)\repulsive\debonair.exe
FirewallRules: [{7AAF4DD7-561E-4C56-891F-61B3AB6181A5}] => (Allow) C:\a\vchk.exe
FirewallRules: [{320AD4F2-B684-4132-96E4-A77227A8EB0C}] => (Allow) C:\a\vchk.exe
FirewallRules: [{5A4B9AA0-6606-4F45-8F2A-E34FF6ADAEFD}] => (Allow) C:\a\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048.exe
FirewallRules: [{9F11AE87-85A2-4FB4-8D35-538C289DA366}] => (Allow) C:\a\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048.exe
FirewallRules: [{DB649646-CD99-4262-92EA-321661A72C3C}] => (Allow) C:\Program Files (x86)\rude\winter.exe
FirewallRules: [{AE3AC6DE-B6B1-4F0D-99D8-036C568AC8AE}] => (Allow) C:\Program Files (x86)\rude\winter.exe
FirewallRules: [{BB4FF719-DC18-44D6-95B9-BA5C69E78B6D}] => (Allow) C:\Program Files (x86)\claim\remember.exe
FirewallRules: [{C297EC50-BBFA-4069-A311-CE8A37140F86}] => (Allow) C:\Program Files (x86)\claim\remember.exe
cmd: bitsadmin /reset /allusers
cmd: netsh winsock reset catalog
cmd: ipconfig /flushdns
RemoveProxy:
Hosts:
EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.

========================= File: C:\Program Files (x86)\claim\remember.exe ========================

"C:\Program Files (x86)\claim\remember.exe" => not found.
====== End of File: ======


========================= File: C:\Program Files (x86)\repulsive\cars.exe ========================

"C:\Program Files (x86)\repulsive\cars.exe" => not found.
====== End of File: ======


========================= File: C:\Program Files (x86)\rude\winter.exe ========================

"C:\Program Files (x86)\rude\winter.exe" => not found.
====== End of File: ======


========================= File: C:\Program Files (x86)\repulsive\debonair.exe ========================

"C:\Program Files (x86)\repulsive\debonair.exe" => not found.
====== End of File: ======


========================= Folder: C:\Program Files (x86)\repulsive ========================

not found.

====== End of Folder: ======


========================= Folder: C:\Program Files (x86)\claim ========================

not found.

====== End of Folder: ======

"C:\Windows\system32\GroupPolicy\Machine" => not found.
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxySettingsPerUser => value not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value not found.
HKU\S-1-5-21-4109533768-3781963708-1875491839-1132\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\S-1-5-21-4109533768-3781963708-1875491839-1132\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found. 
HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found. 
D:\Internet\WaterFox\Profile\user.js => not found.
"D:\Internet\WaterFox\Profile\searchplugins\Funmoods.xml" => not found.
prick => service removed successfully
arrogant => service removed successfully
"C:\Windows\System32\Tasks\MySystemiTools" => not found.
"C:\Windows\System32\Tasks\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048" => not found.
"C:\Windows\System32\Tasks\Grapyy42631311Updates" => not found.
"C:\Windows\System32\Tasks\MySyy42631311ytemy" => not found.
"C:\Windows\System32\Tasks\72634775" => not found.
"C:\Windows\System32\Tasks\4991101" => not found.
"C:\Users\DMarr.AFP\AppData\Local\7165185" => not found.

========================= Folder: C:\Program Files (x86)\person ========================

not found.

====== End of Folder: ======


========================= Folder: C:\Program Files (x86)\rude ========================

not found.

====== End of Folder: ======

"C:\a" => not found.
"C:\Program Files (x86)\person" => not found.
"C:\Program Files (x86)\rude" => not found.
"C:\Users\DMarr.AFP\AppData\Local\55088376" => not found.

========================= File: C:\Windows\pale.exe ========================

"C:\Windows\pale.exe" => not found.
====== End of File: ======

"C:\Windows\pale.exe" => not found.

========================= File: C:\Windows\overjoyed.exe ========================

"C:\Windows\overjoyed.exe" => not found.
====== End of File: ======

"C:\Windows\overjoyed.exe" => not found.

========================= File: C:\Windows\reproduce.exe ========================

"C:\Windows\reproduce.exe" => not found.
====== End of File: ======

"C:\Windows\reproduce.exe" => not found.

========================= File: C:\Windows\instruct.exe ========================

"C:\Windows\instruct.exe" => not found.
====== End of File: ======

"C:\Windows\instruct.exe" => not found.
"C:\Windows\SysWOW64\77600582.bat" => not found.

========================= Folder: C:\Program Files (x86)\FreeSmartSoft ========================

2015-10-31 12:22 - 2015-10-31 12:30 - 0000000 ____D () C:\Program Files (x86)\FreeSmartSoft\FSSGoogleMapsDownloader
2015-10-31 12:22 - 2015-10-31 12:30 - 0000495 _____ () C:\Program Files (x86)\FreeSmartSoft\FSSGoogleMapsDownloader\debug.log

====== End of Folder: ======

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0058318A-B872-4D45-B961-9C781B4969BC} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SwiftSearch Auto Updater 1.10.0.25 Pending Update => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B3E0AAD-CC58-4CD1-90BC-82994249DD02} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-5_user => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3936D2FC-B540-4C9C-8E2B-50C12DF674A8} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E42CCD4-EAFA-44FD-958E-B9BB53E65B2D} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-1-6 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{76C64E5C-4850-493E-864A-A3997DBC8D8E} => key not found. 
C:\Windows\System32\Tasks\Grapyy42631311Updates => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Grapyy42631311Updates => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A2FF997-78B8-4B9C-BA12-5C5B0F199714} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88665EBF-9E68-4483-8A30-7995C2F7FBA8} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_3338333337383532372d4a4a5b415a34782a456c375a => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94D8AEF0-EADE-4AB9-9C29-EE1DBB18B659} => key not found. 
C:\Windows\System32\Tasks\4991101 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4991101 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9685B63F-A893-4859-A401-8356BA3BCDFF} => key not found. 
C:\Windows\System32\Tasks\MySyy42631311ytemy => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySyy42631311ytemy => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{996DD2A3-B967-46A6-9B7A-C729D6747863} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9D0F7A5C-C707-47F6-B285-ED3222E65E01} => key not found. 
C:\Windows\System32\Tasks\MySystemiTools => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySystemiTools => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9D872283-9FAD-4103-8749-6331A69C2CD2} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-5 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B01F8BC6-05CA-479C-A1AC-FDE7DAF3ADFD} => key not found. 
C:\Windows\System32\Tasks\72634775 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\72634775 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7937BD6-7FAD-4410-90AD-8ADB12CDAC52} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_3338333337383532372d4a505b575a32786c452a3745 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC4D3106-8749-47FD-85F6-0298B2C16289} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC SpeedUp Service Deactivator => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCAE12A6-630F-4199-845E-5E3F088F9EB4} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-1-7 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CB77455F-179E-4E1A-BD80-9311C4C64698} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fa1d5dd3-9a72-412f-b9b3-623c24b1e1a4-10_user => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF016AF0-679D-4740-A54D-BA7CAE161EC8} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4AC5518-3738-44EC-8892-83BABD7401AC} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SwiftSearch Auto Updater 1.10.0.25 Core => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5230EE8-1FD4-42D0-94CD-48CFF133A29E} => key not found. 
C:\Windows\System32\Tasks\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GslqV08FI9zx4FfWP071-ni-2015-11-10-ni-12048 => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4161E9C-612E-45C5-AD8C-3603059BE102} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9D7DE31-6A92-44B1-9EFD-ACE7A7A34809} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Inst_Rep => key not found. 
"C:\Windows\SysWOW64\MSIHANDLE" => ":3229" ADS not found.
"C:\Windows\SysWOW64\MSIHANDLE" => ":3282" ADS not found.
"C:\Windows\SysWOW64\MSIHANDLE" => ":3383" ADS not found.
"C:\ProgramData\Reprise" => ":wupeogjxldtlfudivq`qsp`26hfm" ADS not found.
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\62015111.sys => key not found. 
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\62015111.sys => key not found. 
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FB9E0FDC-5527-4A26-91E3-CF6FF6598961} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{829492D7-7D9C-4891-906A-6DBB0B1A8D49} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{36EDCAA4-DF76-4875-A55D-BC753DEE3936} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CDC349F4-E9B9-4B26-A27D-5D5CF24C8546} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F2C030BA-027F-4877-B329-3C0E0B5DED2C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C7DC01AE-E476-4F63-92CC-CDF71A6839E7} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BE48D92F-4E68-490B-BD76-00B3AB60930F} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{381F47AA-A78B-4CAC-AACC-C0A20B071DB6} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7AAF4DD7-561E-4C56-891F-61B3AB6181A5} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{320AD4F2-B684-4132-96E4-A77227A8EB0C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5A4B9AA0-6606-4F45-8F2A-E34FF6ADAEFD} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9F11AE87-85A2-4FB4-8D35-538C289DA366} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DB649646-CD99-4262-92EA-321661A72C3C} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AE3AC6DE-B6B1-4F0D-99D8-036C568AC8AE} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BB4FF719-DC18-44D6-95B9-BA5C69E78B6D} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C297EC50-BBFA-4069-A311-CE8A37140F86} => value not found.

=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


=========  netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-4109533768-3781963708-1875491839-1132\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-4109533768-3781963708-1875491839-1132\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => -4174720 byte temporary data Removed.


The system needed a reboot.

==== End of Fixlog 11:00:21 ====


#13 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:39 AM

Posted 13 November 2015 - 12:11 PM

Looks good. Thanks again for the files. Will give you some time to test out the computer and let me know its status.



#14 DM2-Inc

DM2-Inc
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:06:39 AM

Posted 13 November 2015 - 12:25 PM

Last night I reading a tutorial on Bleeping Computers about “How to determine what services are running under a SVCHOST.EXE process”

 

I started up Process Explorer and had a look at several of the “svchost.exe” file to see If I could figure something out on my own based on what the above tutorial.  While I'm not a whiz at this stuff the web site was real informative (...plus I stayed at a Holiday Inn last night :wink:).  I noted while this was happening, the computer kept providing feedback (Click's) as if I was using my mouse to click on something (but I wasn’t).

 

One of the svchost.exe’s was periodically starting up a process but it was moving too fast for me to see what it was.  I’ve got Process Explorer running now and it’s not doing the same thing as it did last night, but there are one or two svchost.exe’s firing off.

 

I’m assuming that this is normal, with the exception of the background audio, right???

 

I’ve had my speakers turned on now since my previous post and so far no audio and there's no more audio playing (should have activated by now if the malware was still there :thumbup2: ). 

 

Would you mind pointing me to what you think was the offending issue???



#15 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:06:39 AM

Posted 13 November 2015 - 09:11 PM

 

I’ve got Process Explorer running now and it’s not doing the same thing as it did last night, but there are one or two svchost.exe’s firing off.

 

I’m assuming that this is normal, with the exception of the background audio, right???

 

That sounds normal.

 

I’ve had my speakers turned on now since my previous post and so far no audio and there's no more audio playing (should have activated by now if the malware was still there  :thumbup2: ). 

 

 

Glad to hear that :)

 

 

 

Would you mind pointing me to what you think was the offending issue???

 

There was quite a bit out of the ordinary, but I think it mostly revolved around those 4 files (and the similar ones to it) that you uploaded which we removed using FRST. Some were responsible for setting the Proxy you mentioned, another for creating Services to run in the background, and others for creating Scheduled Tasks.

 

Are there any issues remaining or are you ready for the final cleanup steps?

 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users