Solved

removing keybar malware?

Posted on 2013-06-02
9
695 Views
Last Modified: 2013-06-03
i went to the wrong site to download gimp (gimpsoft.com, i think).. it put some junk (PC Speed Fix/24x7 Help malware) in the system which was trying to overtake. (in the name of gimp, they gave a malware file, basically, which i was fooled into).

so i went in safe mode and restored it to a point before i went to the above site.

when i booted the computer, i dont see the 24x7 windows popping up anymore.. but i in FF, i see the page for keybar  

so i ran malware bytes, but it did not find anything.. so i ran combofix and also adwcleaner  .. do you see any reference to any malware removed or concerns? do you think the system is OK and past the concern of whatever 24x7 might have put in?
0
Comment
Question by:25112
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 5

Author Comment

by:25112
ID: 39215107
attached is the keybar screen and also the log from comboxfix and adwcleaner..

should i run the 'delete' on adwcleaner? or dont need to now? is there any downside to running the delete on adwcleaner, if i just want to be sure, it get anymalware if any left?
adwcleaner.png
keybar.png
AdwCleaner-R1-.txt
ComboFix.txt
0
 
LVL 24

Assisted Solution

by:aadih
aadih earned 300 total points
ID: 39215110
Can't see any attachments.
0
 
LVL 5

Author Comment

by:25112
ID: 39215112
i ran TDSS, too.. please see attached log for that, too, please.
TDSSKiller.2.8.16.0-02.06.2013-1.txt
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 
LVL 24

Assisted Solution

by:aadih
aadih earned 300 total points
ID: 39215119
Yes. Delete what adwcleaner asks to delete.

Also did you try system restore to an earlier date?  It's a good way to fix problems. After doing the restore, scan with MBAM and ad-cleaner, just to be sure.
0
 
LVL 5

Author Comment

by:25112
ID: 39215203
thank you- i ran DELETE on ADW, and attached is the log.. i see it removed some folders.. do you recommend anymore?
AdwCleaner-S1-.txt
0
 
LVL 24

Assisted Solution

by:aadih
aadih earned 300 total points
ID: 39215212
Your PC is clean of ad wares now.

Just to be sure do a quick scan with MBAM.  If it comes clean, no worries; enjoy using your PC.
0
 
LVL 1

Assisted Solution

by:mstickler1
mstickler1 earned 100 total points
ID: 39215254
You may want to check you homepage in each of your browsers that's probably what is coming up.

Also I like hitman pro as one last check.
0
 
LVL 27

Accepted Solution

by:
Thomas Zucker-Scharff earned 100 total points
ID: 39215259
try  running  spydllremover  and spy bhoremover.  these should make sure.
0
 
LVL 5

Author Comment

by:25112
ID: 39216037
yes- thanks a lot!
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the biggest threats facing all high-value targets are APT's.  These threats include sophisticated tactics that "often starts with mapping human organization and collecting intelligence on employees, who are nowadays a weaker link than network…
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…
This Micro Tutorial will teach you the basics of configuring your computer to improve its speed. It will also teach you how to disable programs that are running in the background simultaneously. This will be demonstrated using Windows 7 operating…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question