Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Persistent Malware / Spyware (UAC Elevation, URL Redir, Hidden root/shadow vol)


  • This topic is locked This topic is locked
3 replies to this topic

#1 Dareyne

Dareyne

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:55 AM

Posted 21 March 2018 - 02:44 PM

Good Afternoon Folks.

 

I believe that my machines are infected with one or more persistent strains of malware. I am requesting assistance for primary machine, but posting from secondary. 

 

SIGNS OF INFECTION / PAYLOAD DELIVERY & PERSISTENCE:

 

The first sign that the latent (or new) payload executed was upon an unscheduled windows update which the system attempted but failed to apply, and then rolled back.

 

After the 'update' the Windows event log indicated that hundreds of URLs unsigned/recognized by Microsoft had been added to the list of places from which updates were sourced. So, it seems that Windows Update is one element of payload delivery / persistence. 

 

Further investigation indicated that WUSA.EXE had extracted one or more cab files, prompting the unauthorized updates. 

 

Event logs indicate that DLL injection is being used to override UAC controls, as evidenced by a hook whenever MCX2PROV.EXE is called.

 

Finally, unexplained URL redirects / abnormalities when using internet. For example,Google's Mail Login URL on a clean system:

 

https://accounts.google.com/signin/v2/sl/pwdhl=en&passive=true&continue=https%3A%2F%2Fwww.google.com%2F&FlowName=GlifWebSignIn&FlowEntry=ServiceLogin

 

Google's Mail Login URL on Infected System:

 

https://accounts.google.com/signin/v2/sl/pwdservice=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Ftab%3Dwm&scc=1&ltmpl=default&ltmplcache=2&emr=1&osid=1&flowName=GlifWebSignIn&flowEntry=ServiceLogin

 

HISTORY:

 

Issues first appeared on my secondary system around December. Chinese characters began mysteriously appearing in various event logs and registry keys, which I initially dismissed as file corruption; until I chanced upon the machine making mouse movements and running console commands on it's own. 

 

I rolled back my primary system using system restore out of an abundance of caution, and scrubbed the secondary system of the registry files, DLL hooks, pipes, SIDs, scheduled tasks, etc it needed to persist; or so I thought. 

 

Infection(s) are back on both systems, but it has less hold on this system, hence posting from here. 


Edited by hamluis, 21 March 2018 - 02:46 PM.


BC AdBot (Login to Remove)

 


#2 Dareyne

Dareyne
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:55 AM

Posted 21 March 2018 - 02:55 PM

See also, portion of Source Code from Google Mail Login on infected machine. 

 

own:UX7yZ(LgbsSe),npT2md(preventDefault=true); mouseup:lbsD7e(LgbsSe); mouseleave:JywGue; touchstart:p6p2H(LgbsSe); touchmove:FwuNnf; touchend:yfqBxc(LgbsSe|preventMouseEvents=true|preventDefault=true); touchcancel:JMtRjd(LgbsSe); focus:AHmuwe; blur:O22p3e;b5SvAb:TvD9Pc;" jsshadow jsname="rfCUpd" aria-label="Change language"><div jsname="LgbsSe" role="presentation"><div class="ry3kXd Ulgu9" jsname="d9BH4c" role="presentation"><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="af" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Afrikaans‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="az" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪azərbaycan‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ca" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪català‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="cs" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Čeština‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="da" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Dansk‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="de" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Deutsch‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="et" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪eesti‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="en-GB" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪English (United Kingdom)‬</content></div><div class="MocG8c B9IrJb LMgvRb KKjvXb" jsname="wQNmvb" jsaction="" data-value="en" aria-selected="true" role="option" tabindex="0"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪English (United States)‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="es" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Español (España)‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="es-419" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Español (Latinoamérica)‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="eu" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪euskara‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="fil" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Filipino‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="fr-CA" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Français (Canada)‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="fr" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Français (France)‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="gl" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪galego‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="hr" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Hrvatski‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="in" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Indonesia‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="zu" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪isiZulu‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="is" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪íslenska‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="it" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Italiano‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="sw" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Kiswahili‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="lv" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪latviešu‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="lt" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪lietuvių‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="hu" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪magyar‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ms" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Melayu‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="nl" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Nederlands‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="no" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪norsk‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="pl" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪polski‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="pt" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Português (Brasil)‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="pt-PT" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Português (Portugal)‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ro" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪română‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="sk" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Slovenčina‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="sl" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪slovenščina‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="fi" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Suomi‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="sv" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Svenska‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="vi" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Tiếng Việt‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="tr" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Türkçe‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="el" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Ελληνικά‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="bg" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪български‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="mn" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪монгол‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ru" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Русский‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="sr" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪српски‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="uk" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪Українська‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ka" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪ქართული‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="hy" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪հայերեն‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="iw" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‫עברית‬‎</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ur" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‫اردو‬‎</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ar" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‫العربية‬‎</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="fa" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‫فارسی‬‎</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="am" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪አማርኛ‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ne" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪नेपाली‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="mr" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪मराठी‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="hi" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪हिन्दी‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="bn" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪বাংলা‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="gu" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪ગુજરાતી‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ta" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪தமிழ்‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="te" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪తెలుగు‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="kn" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪ಕನ್ನಡ‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ml" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪മലയാളം‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="si" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪සිංහල‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="th" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪ไทย‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="lo" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪ລາວ‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="my" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪မြန်မာ‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="km" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪ខ្មែរ‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ko" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪한국어‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="zh-HK" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪中文(香港)‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="ja" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪日本語‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="zh-CN" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪简体中文‬</content></div><div class="MocG8c B9IrJb LMgvRb" jsname="wQNmvb" jsaction="" data-value="zh-TW" aria-selected="false" role="option" tabindex="-1"><div class="kRoyt MbhUzd" jsname="ksKsZd"></div><content class="vRMGwf oJeWuf">‪繁體中文‬</content></div></div><div class="CeEBt Ce1Y1c eU809d" role="presentation"><div class="TquXA"></div></div></div><div class="OA0qNb ncFHed" jsaction="click:dPTK6c(wQNmvb); mousedown:uYU8jb(wQNmvb); mouseup:LVEdXd(wQNmvb); mouseover:nfXz1e(wQNmvb); touchstart:Rh2fre(wQNmvb); touchmove:hvFWtf(wQNmvb); touchend:MkF9r(wQNmvb|preventMouseEvents=true)" role="presentation" jsname="V68bde" style="display:none;"></div></div></div><ul class="Bgzgmd"><li><a href="https://support.google.com/accounts?hl=en" target="_blank">Help</a><li><a href="https://accounts.google.com/TOS?loc=US&amp;hl=en&amp;privacy=true" target="_blank">Privacy</a><li><a href="https://accounts.google.com/TOS?loc=US&amp;hl=en" target="_blank">Terms</a></ul></footer></div><div class="VmOpGe" aria-hidden="true"><svg jsname="BUfzDd" xmlns="https://www.w3.org/2000/svg" viewBox="0 0 1440 810" preserveAspectRatio="xMinYMin slice" aria-hidden="true"><path fill="#efefee" d="M592.66 0c-15 64.092-30.7 125.285-46.598 183.777C634.056 325.56 748.348 550.932 819.642 809.5h419.672C1184.518 593.727 1083.124 290.064 902.637 0H592.66z"/><path fill="#f6f6f6" d="M545.962 183.777c-53.796 196.576-111.592 361.156-163.49 490.74 11.7 44.494 22.8 89.49 33.1 134.883h404.07c-71.294-258.468-185.586-483.84-273.68-625.623z"/><path fill="#f7f7f7" d="M153.89 0c74.094 180.678 161.088 417.448 228.483 674.517C449.67 506.337 527.063 279.465 592.56 0H153.89z"/><path fill="#fbfbfc" d="M153.89 0H0v809.5h415.57C345.477 500.938 240.884 211.874 153.89 0z"/><path fill="#ebebec" d="M1144.22 501.538c52.596-134.583 101.492-290.964 134.09-463.343 1.2-6.1 2.3-12.298 3.4-18.497 0-.2.1-.4.1-.6 1.1-6.3 2.3-12.7 3.4-19.098H902.536c105.293 169.28 183.688 343.158 241.684 501.638v-.1z"/><path fill="#e1e1e1" d="M1285.31 0c-2.2 12.798-4.5 25.597-6.9 38.195C1321.507 86.39 1379.603 158.98 1440 257.168V0h-154.69z"/><path fill="#e7e7e7" d="M1278.31,38.196C1245.81,209.874 1197.22,365.556 1144.82,499.838L1144.82,503.638C1185.82,615.924 1216.41,720.211 1239.11,809.6L1439.7,810L1439.7,256.768C1379.4,158.78 1321.41,86.288 1278.31,38.195L1278.31,38.196z"/></svg></div></div><div data-check-connection="%.@.null,null,&quot;youtube&quot;,[[&quot;https://accounts.youtube.com/accounts/CheckConnection?pmpo\u003dhttps%3A%2F%2Faccounts.google.com\u0026v\u003d569800954&quot;,&quot;youtube&quot;]   ]   ]   " jsaction="rcuQ6b:WYd" jscontroller="GfN5Qc"><input type="hidden" id="pstMsg" jsname="xa8ENe" name="pstMsg" value="0"><input type="hidden" id="checkConnection" jsname="ZVfTqd" name="checkConnection" value=""><input type="hidden" id="checkedDomains" jsname="pqkZjc" name="checkedDomains" value="youtube"></div><div class="lDwpOe"></div></body></html>

 



#3 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,740 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:55 AM

Posted 23 March 2018 - 12:24 PM

Hello, please repost with the FRST log from guide.

Do steps 6 & 7...

Please follow this Preparation Guide and post in a new topic.
Let me know if all went well..
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,740 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:55 AM

Posted 24 March 2018 - 09:03 AM

Now that your log is properly posted, you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a Malware Removal Team member, nor should you continue to ask for help elsewhere. Doing so can result in system changes which may not show it the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.
From this point on the Malware Removal Team should be the only members that you take advice from, until they have verified your log as clean.
Please be patient. It may take a while to get a response because the Malware Removal Team members are very busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the Malware Removal Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRL Team member is already assisting you and not open the thread to respond.
The current wait time is 1 - 3 days and ALL logs are answered.
If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.
To avoid confusion, I am closing this topic.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users