MormonYoYoMan
Honorary Members-
Posts
57 -
Joined
-
Last visited
Reputation
0 NeutralAbout MormonYoYoMan
- Birthday 11/05/1954
Profile Information
-
Location
Houston
-
It's almost 2020. Will Microsoft accept Malwarebytes for Edge? Must we return to Firefox or Chrome? It's almost 2020. Microsoft, may we please have Malarebytes' extension for Edge?
-
Whatever Happened to Chameleon?
MormonYoYoMan replied to MormonYoYoMan's topic in Malwarebytes for Windows Support Forum
Thank you for the explanation. I must have missed that notification in one of the updates. -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
Argh! That PCWorld page auto-ran so many videos, that it kept locking up my computer. Finally printed the page to PDF, closed Chrome, and was able to read the instructions thataway. To no avail. I turned off, as instructed, the option to send parts of Windows updates to any other computer, whether on my network or not. And when I rebooted... Nothing. Until I opened Malwarebytes. At that point, I got two MORE alerts on Shieldapps.mL. The reports are attached. Again. As they occurred at 5:15 pm, I've named them MByteReport(today's date) 1715a and b, respectively. Whoever wrote this malware - and I'm beginning to truly believe Equifax is less innocent than they claim - is diabolical and clever. MBytReport10-16-17 1715b.txt MBytReport10-16-17 1715a.txt -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
Turned off Sync Settings, rebooted, and -- got the same two blocks against shieldapps.mL. Double-checked the Sync Settings on Windows 10 -- and they are still off. Attached the two new reports. Each occurred at 1501 hours. MBytReport10-16-17 1501b.txt MBytReport10-16-17 1501a.txt -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
Since so many of the reports were at the same time and date (I don't know why MBy generated two or more reports for every alert) I've attached the last TEN reports. They cover only 2.5 days. If you need reports that go back further than the 14th, let me know. I can send them right away. Don't want to overwhelm you with Too Much Information. MBytReport10-14-17b.txt MBytReport10-14-17a.txt MBytReport10-15-17b.txt MBytReport10-15-17a.txt MBytReport10-16-17ab.txt MBytReport10-16-17aa.txt MBytReport10-16-17d.txt MBytReport10-16-17a.txt MBytReport10-16-17b.txt MBytReport10-16-17c.txt -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
And here they are! Addition.txt FRST.txt 2017.10.16-06.09.12-i0-t92-d1.txt -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
Upon booting, Malwarebytes still alerts "Blocking shieldapps.ml" -- ip 37.97.254.27 - Port 8 - If those are any help. I wonder what keeps trying to connect to Shieldapps.ML? -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
Here you go! Thank you, so far. I'm not giving up this until you tell me all is clear. "Bulldog tenacity" a colonel once complemented me. Addition.txt FRST.txt -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
Here you are. We ended up being "kidnapped" by our two youngest granddaughters and didn't get back from their home (our daughter and son-in-law live on the way from the grocery) until just an hour ago. Ran FRST, and looked for pevx.exe (Search03.txt) as well as pevz.exe (Searches 01 and 02.txt). They found nothing. Those logs (Searches 01, 02, and 03 in ASCII format) are attached. Where I found pevz.exe? -- That was in the Resource Monitor, where I saw pevz.exe taking up almost the entire CPU.. at least, I think it was the CPU that it hogged. When I googled the article aforementioned, http://greatis.com/blog/how-to-remove-malware/pevz-exe.htm , I quickly disabled pevz.exe. Almost immediately after I disabled it (That was the option I got when I right-clicked on it; to disable, not to terminate.) I forgot where in the Resource Monitor I'd seen it. But as soon as I disabled it, Zeok instantly came to life - and finished. There is still some minor, infrequent mouse pointer wandering (scrolling the screen completely down and to the right) but that's the only "badness" I've noticed. Shoul I run Zeok again, or the file you recommended 12+ hours ago? Search03.txt Search02.txt Search01.txt -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
I'll try when I get home. Right now am sitting in car waiting for my wife to come out of Wal-Mart. Zzzzz -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
Aha! Wait! Before we leave Zeok, I found something called PEVZ that looked and acted suspiciously. An article at http://greatis.com/blog/how-to-remove-malware/pevz-exe.htm indicated it is a trojan, and though I couldn't delete it manually, I did suspend it. At that point, Zeok began running again. It completed whatever was clogging it, demanded a reboot, then spit out its report. Here is that full Zeok report: Zoek.exe v5.0.0.1 Updated 27-09-2015 Tool run by Mormo_000 on Fri 10/13/2017 at 15:49:24.81. Microsoft Windows 10 Home 10.0.15063 x64 Running in: Normal Mode No Internet Access Detected Launched: C:\Users\Mormo_000\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2017-10-13-035927.log 12613 bytes C:\zoek-results2017-10-13-132921.log 1880 bytes ==== System Restore Info ====================== 10/13/2017 3:54:21 PM Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\Users\Mormo_000\AppData\Local\DBG deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\MORMO_~1\AppData\Roaming\Mozilla\Firefox\Profiles\lxuoyro5.default\prefs.js: user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); Added to C:\Users\MORMO_~1\AppData\Roaming\Mozilla\Firefox\Profiles\lxuoyro5.default\prefs.js: user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); ==== Batch Command(s) Run By Tool====================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\MORMO_~1\AppData\Roaming\Mozilla\Firefox\Profiles\lxuoyro5.default user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "AllMyTube@Wondershare.com"="C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com" [10/09/2017 07:48 AM] ==== Firefox Extensions ====================== ProfilePath: C:\Users\MORMO_~1\AppData\Roaming\Mozilla\Firefox\Profiles\lxuoyro5.default - Wondershare AllMyTube - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com AppDir: C:\Program Files (x86)\Mozilla Firefox - Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi ==== Firefox Plugins ====================== ==== Chromium Look ====================== HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions efaidnbmnnnibpcajpcglclefindmkaj - No path found[] Chrome Media Router - Mormo_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm 4.2.0 - Mormo_000\AppData\Local\Vivaldi\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd Chrome Media Router - Mormo_000\AppData\Local\Vivaldi\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm Chrome Media Router - C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Vivaldi\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.msn.com/?ocid=U220DHP&pc=U220" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.msn.com/?ocid=U220DHP&pc=U220" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Reset Google Chrome ====================== C:\Users\Mormo_000\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Mormo_000\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Preferences was reset successfully C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Secure Preferences was reset successfully C:\Users\Mormo_000\AppData\Local\Google\Chrome\User Data\Default\Web Data will be reset at reboot C:\Users\Mormo_000\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal will be reset at reboot C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Web Data was reset successfully C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Web Data-journal was reset successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Mormo_000\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Mormo_000\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Mormo_000\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Cache will be emptied at reboot C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Vivaldi\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=3537 folders=231 616577369 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\MORMO_~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Mormo_000\AppData\Local\Google\Chrome\User Data\Default\Web Data" not found "C:\Users\Mormo_000\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal" not found "C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Cache\data_0" deleted "C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Cache\data_1" deleted "C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Cache\data_2" deleted "C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Cache\data_3" deleted "C:\Users\Mormo_000\AppData\Local\Vivaldi\User Data\Default\Cache\index" deleted ==== EOF on Sat 10/14/2017 at 6:55:13.29 ====================== -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
In a valiant yet futile attempt to unclog this drainpipe, I uninstalled all Firefox Mozilla everything. It's still stuck. May I please turn Malwarebytes and Defender back on? The mouse cursor is wandering all over the place and clicking randomly, even when my hands are far from the desk. -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
It's been four hours since it stopped at Firefox extensions, and I have to use my laptop now. Last night/this morning, it got to the exact same spot: Firefox extensions - and that was after 13 hours. Zoek doesn't seem to work. Or it might be because the instructions to temporarily stop Windows Defender and Malwarebytes (from your links of "temporary disable your AntiVirus and AntiSpyware protection - instructions here or here ") -- the instructions at those links don't match up to the menus, commands, or directives within Defender or Malwarebytes. My wife is home now, and I sha'n't be able to do much more with the laptop tonight as she needs me to work. I shall try again Monday, to see if there is anything other than Zoek. And yep --- Malwarebytes still alerts (when booting) than shieldapps.ml is still around. Zoek.exe v5.0.0.1 Updated 27-09-2015 Tool run by Mormo_000 on Fri 10/13/2017 at 15:49:24.81. Microsoft Windows 10 Home 10.0.15063 x64 Running in: Normal Mode No Internet Access Detected Launched: C:\Users\Mormo_000\Desktop\zoek.exe [Scan all users] [Script inserted] ===== Runcheck 15:52:55.67 ===== --- Create Environment Variables 15:52:58.07 --- Create System Restore Point 15:53:18.45 --- Checking Input 15:54:25.98 --- AU AppData Check 15:54:46.37 --- Remove From Windows Installer 15:54:51.04 --- Empty Folders Check 15:56:18.75 --- Registry HKLM Software Check 15:56:18.82 --- Quick Launch Shortcut Check 15:56:49.92 --- IE Startpage Check 15:57:00.82 --- Program Files DB Check 15:57:36.40 --- C:\Users\Default\AppData DB Check 15:59:01.47 --- C:\Users\Mormo_000\AppData DB Check 15:59:01.47 --- C:\WINDOWS\SysNative\config\systemprofile\AppData DB Check 15:59:01.47 --- C:\WINDOWS\sysWoW64\config\systemprofile\AppData DB Check 15:59:01.47 --- C:\WINDOWS\serviceprofiles\networkservice\AppData DB Check 15:59:01.47 --- C:\WINDOWS\serviceprofiles\Localservice\AppData DB Check 15:59:01.47 --- C:\Users\Mormo_000 DB Check 16:02:30.45 --- C:\PROGRA~3 DB Check 16:03:28.04 --- C:\Users\Default\AppData\Local DB Check 16:03:38.70 --- C:\Users\Default User\AppData\Local DB Check 16:03:38.70 --- C:\Users\Mormo_000\AppData\Local DB Check 16:03:38.70 --- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local DB Check 16:03:38.70 --- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local DB Check 16:03:38.70 --- C:\WINDOWS\serviceprofiles\networkservice\AppData\Local DB Check 16:03:38.70 --- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local DB Check 16:03:38.70 --- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 16:06:27.09 --- C:\Users\Mormo_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 16:06:45.27 --- Tasks DB Check 16:06:57.04 --- C:\Users\Mormo_000\AppData\LocalLow DB Check 16:07:04.61 --- C:\WINDOWS\SysNative\config\systemprofile\AppData\LocalLow DB Check 16:07:04.61 --- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 16:07:04.61 --- C:\WINDOWS\serviceprofiles\networkservice\AppData\LocalLow DB Check 16:07:04.61 --- C:\WINDOWS\serviceprofiles\Localservice\AppData\LocalLow DB Check 16:07:04.61 --- Tasks2 DB Check 16:08:34.37 --- Documents DB Check 16:09:29.88 --- Documents2 DB Check 16:09:43.44 --- C:\Users\MORMO_~1\AppData\Roaming\Mozilla\Firefox\Profiles\lxuoyro5.default DB Check 16:09:46.19 --- C:\Users\Public\Desktop DB Check 16:09:50.44 --- C:\Users\Mormo_000\Desktop DB Check 16:09:59.28 --- Services DB Check 16:10:14.05 --- FF prefs.js DB Check 16:10:59.20 --- Emptyclsid 16:12:09.86 --- Del by CLSID 16:12:13.14 --- Delete Services 16:13:19.43 --- Firefox Fix 16:13:22.59 --- Batch Commands 16:13:24.88 --- Firefox Extensions 16:13:25.87 -
"shieldapps.ml" Is or Isn't?
MormonYoYoMan replied to MormonYoYoMan's topic in Resolved Malware Removal Logs
For some reason, Zoek stopped at 0829, which I didn't see until I came into the back room to check on it. I am going to run Zoek again in about an hour (about 1400 Central Time) to see if it does anything differently. Here is the screen output in the Zoek window: Zoek.exe v5.0.0.1 Updated 27-09-2015 Tool run by Mormo_000 on Fri 10/13/2017 at 7:30:17.84. Microsoft Windows 10 Home 10.0.15063 x64 Running in: Normal Mode No Internet Access Detected Launched: C:\Users\Mormo_000\Desktop\zoek.exe [Scan all users] [Script inserted] ===== Runcheck 7:35:11.46 ===== --- Create Environment Variables 7:35:19.48 --- Create System Restore Point 7:35:58.58 --- Checking Input 7:38:33.09 --- AU AppData Check 7:39:24.01 --- Remove From Windows Installer 7:39:37.71 --- Empty Folders Check 7:47:01.82 --- Registry HKLM Software Check 7:47:02.00 --- Quick Launch Shortcut Check 7:48:36.19 --- IE Startpage Check 7:49:24.25 --- Program Files DB Check 7:52:16.96 --- C:\Users\Default\AppData DB Check 7:55:45.09 --- C:\Users\Mormo_000\AppData DB Check 7:55:45.09 --- C:\WINDOWS\SysNative\config\systemprofile\AppData DB Check 7:55:45.09 --- C:\WINDOWS\sysWoW64\config\systemprofile\AppData DB Check 7:55:45.09 --- C:\WINDOWS\serviceprofiles\networkservice\AppData DB Check 7:55:45.09 --- C:\WINDOWS\serviceprofiles\Localservice\AppData DB Check 7:55:45.09 --- C:\Users\Mormo_000 DB Check 8:03:32.84 --- C:\PROGRA~3 DB Check 8:06:09.04 --- C:\Users\Default\AppData\Local DB Check 8:06:32.41 --- C:\Users\Default User\AppData\Local DB Check 8:06:32.41 --- C:\Users\Mormo_000\AppData\Local DB Check 8:06:32.41 --- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local DB Check 8:06:32.41 --- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local DB Check 8:06:32.41 --- C:\WINDOWS\serviceprofiles\networkservice\AppData\Local DB Check 8:06:32.41 --- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local DB Check 8:06:32.41 --- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 8:12:26.49 --- C:\Users\Mormo_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 8:13:04.69 --- Tasks DB Check 8:13:28.92 --- C:\Users\Mormo_000\AppData\LocalLow DB Check 8:13:52.03 --- C:\WINDOWS\SysNative\config\systemprofile\AppData\LocalLow DB Check 8:13:52.03 --- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 8:13:52.03 --- C:\WINDOWS\serviceprofiles\networkservice\AppData\LocalLow DB Check 8:13:52.03 --- C:\WINDOWS\serviceprofiles\Localservice\AppData\LocalLow DB Check 8:13:52.03 --- Tasks2 DB Check 8:17:01.95 --- Documents DB Check 8:18:53.55 --- Documents2 DB Check 8:19:22.66 --- C:\Users\MORMO_~1\AppData\Roaming\Mozilla\Firefox\Profiles\lxuoyro5.default DB Check 8:19:27.84 --- C:\Users\Public\Desktop DB Check 8:19:36.71 --- C:\Users\Mormo_000\Desktop DB Check 8:19:59.44 --- Services DB Check 8:20:36.55 --- FF prefs.js DB Check 8:23:09.78 --- Emptyclsid 8:26:15.32 --- Del by CLSID 8:26:27.41 --- Delete Services 8:28:59.69 --- Firefox Fix 8:29:07.12 --- Batch Commands 8:29:15.89 --- Firefox Extensions 8:29:19.82