View Single Post
Old 06-24-2014, 11:09 AM   #401
The Franchise The Franchise is online now
Most Valuable Villain
 
The Franchise's Avatar
 

Join Date: Dec 2006
Casino cash: $3095047
Quote:
Originally Posted by Fish View Post
Dude, that system is a mess.

Looks like it's infected with Snap.Do, according to this line:

C:\Users\dcbrummer\AppData\Local\LPT\srptm.exe

That will take over your browser and change your browser settings/homepage/search/etc.
Manually remove Snap.Do: http://www.pcthreat.com/parasitebyid-24962en.html

Likely related, but your browser search is already hosed, according to this line:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?p=mKO_AwF...YQICtkYCoZLrIj PJfQr0xIk08q-vF_N19VuJ-xynJ4wg,,&q={searchTerms}

The following lines very likely could be a rootkit:

O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

Are you in a managed corporate environment or something? You've also got a program called DesktopAuthority running. It's a pretty powerful IT Admin app that can give the admin pretty much complete control of your computer. It can even monitor keystrokes and shit if the admin chose to use it that way. If you're in a corporate managed environment, it's probably OK. But if not, that could be serious trouble. I notice it's an Alienware with lots of normal consumer stuff, but also some admin stuff and Papercut client.

Regardless, your system need to be cleaned ASAP. I'd recommend a complete reimage or reinstall if possible. It might already be too far gone. But you might be able to resuscitate it. I'd run the malware cleaners listed in the OP. I'd also include Malwarebytes Anti-malware.

Considering all the unnecessary stuff running in the background, your system would feel like a new machine if you would format and reinstall. If you're in a corp environment, tell your IT to backup and reimage that mofo.
Yeah....work environment. I ran Malwarebytes and removed around 20 different ****ing things. I've now run it two more times just to make sure it didn't miss anything. Desktop Authority and Papercut are mandated by my work....so they aren't going anywhere.
Posts: 92,180
The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.The Franchise is obviously part of the inner Circle.
    Reply With Quote