Panicattack Posted January 30, 2021 ID:1435512 Share Posted January 30, 2021 I decided to go play around with things I knew were unsafe for people who don't really understand them and got a trojan, a pup and some annoying ass chrome extension for it. All I wanted to do is get gimp installed and as they had a torrenting possibility I was intriqued to find out why this would be a thing in the first place so I decided to look into what exactly torrenting is. Long story short I had the correct program and file, but clicked "yes" on some "dude you also want this installed" -thingie which apparently was a really bad idea. I didn't know anything was up until I got a pop-up saying that my browser was not secured. After a while of googling "what the ***** do I do" I found malwarebytes and ran a scan with it which to my relief actually found something, a trojan and a pup. Even after quarantining these 2 the original thing - the chrome extension - was still around and for a minute I thought it was gone but it still gets readded to chrome whenever I log in with another chrome account. My question is, how do I know that I'm safe and that the trojan didn't give me a keylogger or something within the 5-6 hours it might have sat there. The one thing giving me hope is that when I look at the detected trojan in malwarebytes, it says the directory for the file was (translated) "C:\USERS\myname\Downloads\Unconfirmed" after that it gives some seemingly random numbers and .crdownload at the end. I remember pausing some download that suddenly showed up while I was trying to figure out what I need to do to get rid of the pop-up prompting me to enable a browser (edge I think?) as my default one. Also I would like to get some help with the pesky chrome extension and sorry for the wall of text. Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435513 Share Posted January 30, 2021 Hello , Panicattack...and Please read the content of the topic I'm infected - What do I do now?, run the scans and attach the requested logs for my review. Then wait for further instructions. Thank you 🙂 Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435514 Share Posted January 30, 2021 scanlogs.txtFRST.txtAddition.txt Yeah was actually reading that topic right after making this one Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435517 Share Posted January 30, 2021 Hello , Panicattack...! I'm reviewing your logs and will get back to you soon...! :) Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435519 Share Posted January 30, 2021 I most definitely have some sort of adware Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435524 Share Posted January 30, 2021 (edited) Please download the attached fixlist.txt file and save it to the Desktop or location where you ran FRST from.NOTE. It's important that both files, FRST or FRST64, and fixlist.txt are in the same location or the fix will not work. Please make sure you disable any real time antivirus or security software before running this script. Once completed make sure you re-enable it. NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system that cannot be undone. Run FRST or FRST64 and press the Fix button just once and wait. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt) or wherever you ran FRST from. Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. NOTE-1: This fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will also run a disk check on the restart to ensure disk integrity. Depending on the speed of your computer this fix may take 30 minutes or more. NOTE-2: As part of this fix all temporary files will be removed. If you have any open web pages that have not been bookmarked please make sure you bookmark them now as all open applications will be automatically closed. Also, make sure you know the passwords for all websites as cookies will also be removed. The use of an external password manager is highly recommended instead of using your browser to store passwords. The following directories are emptied: Windows Temp Users Temp folders Edge, IE, FF, Chrome and Opera caches, HTML5 storages, Cookies and History Recently opened files cache Flash Player cache Java cache Steam HTML cache Explorer thumbnail and icon cache BITS transfer queue (qmgr*.dat files) Recycle Bin Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns please ask before running this fix. The system will be rebooted after the fix has run. ============================================================================================================== Next,Download AdwCleaner by Malwarebytes onto your Desktop. Right-click on AdwCleaner.exe and select Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users) Accept the EULA (I accept), then click on Scan Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Quarantine button. This will kill all the active processes Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply fixlist.txt Edited January 30, 2021 by icotonev Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435525 Share Posted January 30, 2021 Chrome flagged the txt file as dangerous so I can't download it Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435527 Share Posted January 30, 2021 changing browsers fixed it Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435528 Share Posted January 30, 2021 I hope I didn't just seriously ***** something up by forgetting to turn windows defender off Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435529 Share Posted January 30, 2021 9 minutes ago, Panicattack said: I hope I didn't just seriously ***** something up by forgetting to turn windows defender off No problem .. Please follow the fix..! Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435530 Share Posted January 30, 2021 follow the fix? Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435532 Share Posted January 30, 2021 I'm sorry for wanting overly clear instructions but I'm really stressed out for way too many reasons right now and don't want to do anything wrong anymore, I just need this out of my life asap so I can go back to fixing my other problems Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435533 Share Posted January 30, 2021 26 minutes ago, icotonev said: Please download the attached fixlist.txt file and save it to the Desktop or location where you ran FRST from.NOTE. It's important that both files, FRST or FRST64, and fixlist.txt are in the same location or the fix will not work. Please make sure you disable any real time antivirus or security software before running this script. Once completed make sure you re-enable it. NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system that cannot be undone. Run FRST or FRST64 and press the Fix button just once and wait. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt) or wherever you ran FRST from. Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. NOTE-1: This fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will also run a disk check on the restart to ensure disk integrity. Depending on the speed of your computer this fix may take 30 minutes or more. NOTE-2: As part of this fix all temporary files will be removed. If you have any open web pages that have not been bookmarked please make sure you bookmark them now as all open applications will be automatically closed. Also, make sure you know the passwords for all websites as cookies will also be removed. The use of an external password manager is highly recommended instead of using your browser to store passwords. The following directories are emptied: Windows Temp Users Temp folders Edge, IE, FF, Chrome and Opera caches, HTML5 storages, Cookies and History Recently opened files cache Flash Player cache Java cache Steam HTML cache Explorer thumbnail and icon cache BITS transfer queue (qmgr*.dat files) Recycle Bin Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns please ask before running this fix. The system will be rebooted after the fix has run. Is there anything unclear in my instruction...? Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435534 Share Posted January 30, 2021 do I just do the same thing again but this time with windows defender off? I already ran it once so idk if that changes something Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435535 Share Posted January 30, 2021 12 minutes ago, icotonev said: The tool will make a log on the Desktop (Fixlog.txt) or wherever you ran FRST from. Please attach or post it to your next reply. Don't forget to attach the result..! Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435536 Share Posted January 30, 2021 Fixlog.txt Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435537 Share Posted January 30, 2021 49 minutes ago, icotonev said: Next,Download AdwCleaner by Malwarebytes onto your Desktop. Right-click on AdwCleaner.exe and select Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users) Accept the EULA (I accept), then click on Scan Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Quarantine button. This will kill all the active processes Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply I expect a result from the scan with AdwCleaner ..! Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435541 Share Posted January 30, 2021 I wasn't asked to restart but did, now I have two logs "AdwCleaner[S00]" and AdwCleaner[C00]" I assume one of them is the one you are after # ------------------------------- # Malwarebytes AdwCleaner 8.0.9.1 # ------------------------------- # Build: 01-20-2021 # Database: 2021-01-26.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 01-30-2021 # Duration: 00:00:00 # OS: Windows 10 Home # Cleaned: 2 # Failed: 0 ***** [ Services ] ***** No malicious services cleaned. ***** [ Folders ] ***** No malicious folders cleaned. ***** [ Files ] ***** No malicious files cleaned. ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks cleaned. ***** [ Registry ] ***** Deleted HKCU\Software\Lavasoft\Web Companion Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries cleaned. ***** [ Firefox URLs ] ***** No malicious Firefox URLs cleaned. ***** [ Hosts File Entries ] ***** No malicious hosts file entries cleaned. ***** [ Preinstalled Software ] ***** No Preinstalled Software cleaned. ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* AdwCleaner[S00].txt - [1520 octets] - [30/01/2021 15:52:38] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ########## # ------------------------------- # Malwarebytes AdwCleaner 8.0.9.1 # ------------------------------- # Build: 01-20-2021 # Database: 2021-01-26.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Scan # ------------------------------- # Start: 01-30-2021 # Duration: 00:00:18 # OS: Windows 10 Home # Scanned: 31956 # Detected: 2 ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** PUP.Optional.WebCompanion HKCU\Software\Lavasoft\Web Companion PUP.Optional.WebCompanion HKLM\Software\Wow6432Node\Lavasoft\Web Companion ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries found. ***** [ Chromium URLs ] ***** No malicious Chromium URLs found. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries found. ***** [ Firefox URLs ] ***** No malicious Firefox URLs found. ***** [ Hosts File Entries ] ***** No malicious hosts file entries found. ***** [ Preinstalled Software ] ***** No Preinstalled Software found. ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ########## Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435542 Share Posted January 30, 2021 Excellent work..! :) How is the computer running? Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435543 Share Posted January 30, 2021 I still have the chrome extension, adware seems to be gone Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435544 Share Posted January 30, 2021 Whenever I log into Chrome it tells me that an extension called Web Safety was added which has been review bombed with 1 star ratings calling it a virus so I'd rather not have that around Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435553 Share Posted January 30, 2021 Uninstall an extension: On your computer, open Chrome. At the top right, click the three points - More tools - Extensions. On to the extension you want to remove, click Remove. Quote Web Safety Confirm by clicking Remove. Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435554 Share Posted January 30, 2021 I know how to remove the extension, I have done that 10 times already, but whenever I log in to chrome again it automatically adds itself back Link to post Share on other sites More sharing options...
icotonev Posted January 30, 2021 ID:1435555 Share Posted January 30, 2021 (edited) And with which profile ..? Quote CHR Extension: (Web Safety) - C:\Users\Jere\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp [2021-01-30] Edited January 30, 2021 by icotonev Link to post Share on other sites More sharing options...
Panicattack Posted January 30, 2021 Author ID:1435556 Share Posted January 30, 2021 if I create a new profile it adds it back automatically, that definitely shouldn't happen. Also I don't speak bulgarian or understand what that quote means Link to post Share on other sites More sharing options...
Recommended Posts