[SOLVED] Malware + CSI Payload corrupt

A bad news:

I have Discord installed in my laptop. It seems my account got hacked :(. My friend told me that some random messages had been sent to him and some more people. And when I tried logging in Discord using mobile, it says "Account disabled".

Can discord account be hacked easily?

What about my accounts in other websites/apps which require logging in? I don't have any saved passwords if I recall correctly.
 
Hi, Soor.

You have to change your passwords from a healthy computer and get ready to clean the infected one as soon as possible.
 
I have changed the passwords for some. Should the passwords for the websites that require OTP also be reset?

Currently, I'm backing data up from laptop. I'll be ready soon (If backing up is delayed, I'll carry out the processes, which you said before, tomorrow).
 
Backup has now been completed and I am ready to proceed further. I am going to start the process you had mentioned before.
 
Step 3 and 4 completed.

Attaching log:

By the way, on my attempt to start Preparing Automatic Repair, I failed twice. During the first time, it booted normally and it asked me to enter the sign in password. As I entered it and hit OK, it then did not show me the 'Start' menu. The screen was kind of blank.

I turned my PC off. Is that ok?
 

Attachments

Hi, Soor.

Good to see that you ran FRST in the Recovery Environment. (y)

Since I had a very busy day today, and since your computer's infection needs special treatment and a clean mind, I will review the log tomorrow.

Thank you for your patience.
 
Hi, Soor.

I see signs of Ransomware infection in your log. These files, for example, are encrypted:

C:\aow_drv.log.shgv
C:\510326261_21.pdf.shgv
C:\DBAR_Ver.txt.shgv
C:\IIBF_ADMIT_CARD_510279573.pdf.shgv

What about your other documents? Do they have this shgv Ransomware extension?

==============================

1. Prepare the fix

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system



Open a notepad window (Start > All Programs > Accessories > Notepad), copy and paste the following code in it, and name it as fixlist.txt. Change the Save as Type to All Files and save it in the USB drive where the FRST tool is.

Be careful to select the whole content of the code below.

Code:
Task: C:\Windows\Tasks\GdnhtbLklpMPYjM.job => C:\Program Files (x86)\bGfPtQlxU\KXlgZB.dll
Task: C:\Windows\Tasks\nhrdRfLcpSITSNSsC.job => C:\Windows\Temp\CTpLrEvlTmUdAMcR\AHMaIoKCfOiSopp\yXZPvKm.exe
Task: {93E5938A-5FAE-4DF7-AD96-714B40BDD49F} - System32\Tasks\{51E9B402-312D-4452-99DE-324BF8FE8A2E} => C:\Windows\system32\pcalua.exe -a D:\AutoRun\AutoRun.exe -d D:\AutoRun
Task: {1F5EC8A3-0E13-407B-A159-FEB8B802BBF7} - System32\Tasks\{609E01CF-29E8-404F-8B0C-08E780750A48} => C:\Windows\system32\pcalua.exe -a C:\Games\MCM\mcm.exe -d C:\Games\MCM
HKLM-x32\...\RunOnce: [InnoSetupRegFile.0000000001] => "C:\Windows\is-EVQ5S.exe" /REG /REGSVRMODE (No File)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\vandana\...\Policies\system: [DisableChangePassword] 0
HKU\vandana\...\Policies\Explorer: [] 
HKU\vandana\...\Policies\Explorer: [NoLogoff] 0
GroupPolicy: Restriction - Windows Defender <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
2021-12-17 01:05 - 2021-12-17 01:05 - 001183288 _____ C:\Windows\is-EVQ5S.exe
2021-12-17 01:05 - 2021-12-17 01:05 - 000022709 _____ C:\Windows\is-EVQ5S.msg
2021-12-17 01:05 - 2021-12-17 01:05 - 000000312 _____ C:\Windows\is-EVQ5S.lst
2021-12-16 22:25 - 2021-12-16 22:25 - 000000000 ____D C:\Windows\SysWOW64\xhldhgjs
2021-12-16 22:22 - 2021-12-16 22:22 - 000001117 _____ C:\Users\vandana\_readme.txt
2021-12-16 22:22 - 2021-12-16 22:22 - 000001117 _____ C:\Users\DefaultAppPool\_readme.txt
2021-12-16 22:22 - 2021-12-16 22:22 - 000001117 _____ C:\Users\Administrator\_readme.txt
2021-12-16 22:22 - 2021-12-16 22:22 - 000001117 _____ C:\Users\.NET v4.5\_readme.txt
2021-12-16 22:22 - 2021-12-16 22:22 - 000001117 _____ C:\Users\.NET v4.5 Classic\_readme.txt
2021-12-16 22:20 - 2021-12-16 22:20 - 000001117 _____ C:\_readme.txt
2021-12-16 22:16 - 2021-12-17 08:02 - 000000000 ____D C:\Program Files (x86)\bGfPtQlxU
2021-12-16 22:16 - 2021-12-17 07:28 - 000000312 _____ C:\Windows\Tasks\GdnhtbLklpMPYjM.job
2021-12-16 22:15 - 2021-12-16 22:52 - 000000420 _____ C:\Windows\Tasks\nhrdRfLcpSITSNSsC.job
2021-12-16 22:14 - 2021-12-17 06:25 - 000000000 ____D C:\Users\vandana\AppData\Local\672efbce-225f-4b4d-ab61-ed3327cf90c6
2021-12-16 22:14 - 2021-12-16 22:14 - 000000000 ____D C:\ProgramData\UAUE27TND1ZZKWCDCB8SKX1QP
2021-12-16 22:14 - 2021-12-16 22:14 - 000000000 ____D C:\ProgramData\U0GZ934RNA9TYFOCSUQQR6MHS
2021-12-16 22:11 - 2021-12-16 22:13 - 000000000 ____D C:\ProgramData\ZF8V8TEET554RC5S10QW8OVW0
2021-12-16 22:11 - 2021-12-16 22:12 - 000000000 ____D C:\ProgramData\B7HPMSBZT9SRFGWSY671A1DGM
2021-12-16 22:10 - 2021-12-16 22:10 - 000000000 ____D C:\Program Files (x86)\Company
2021-12-16 22:09 - 2021-12-16 22:11 - 000000000 ____D C:\ProgramData\N3FWE679090P7B0PMLY2BOVKJ
2021-12-16 22:09 - 2021-12-16 22:09 - 000000560 _____ C:\Users\vandana\AppData\Local\bowsakkdestx.txt
2021-12-16 22:09 - 2021-12-16 22:09 - 000000000 ____D C:\SystemID
2021-12-16 22:08 - 2021-12-20 08:57 - 000000000 ____D C:\Users\vandana\AppData\Local\d7c2e2ad-a80e-445b-8abf-c56c36d54e86
2021-12-16 22:04 - 2021-12-16 22:11 - 000000000 ____D C:\ProgramData\4C7ZE9Z2KBZ16F2HA0DQUGQA4
C:\Games\MCM
C:\Windows\Temp\CTpLrEvlTmUdAMcR


2. Enter Recovery Environment

Enter the Recovery Environment as you did before. Select Command Prompt again.

After that...

Run FRST from the Command Prompt
  1. In the black window that will open, called command prompt, type notepad and press on Enter.
  2. Notepad will open. Click on the File menu and select Open.
  3. Click on Computer, find the letter for your USB Flash Drive, then close the window and Notepad.
  4. In the command prompt, type e:\frst.exe (for the x64 version, type e:\frst64.exe) and press on Enter. IMPORTANT: Replace the letter e with the drive letter of your USB Flash Drive.
  5. FRST will open.
  6. Click on Yes to accept the disclaimer.
  7. Click on the FIX button and wait for the scan to complete.
  8. A log called fixlog.txt will be saved on your USB Flash Drive.

3. Provide the FRST.txt

Open the USB drive, find fixlog.txt, open it, copy its content and paste it here, in your next reply.
 
Hi, Soor.

I see signs of Ransomware infection in your log. These files, for example, are encrypted:

What about your other documents? Do they have this shgv Ransomware extension?
I am not sure about the other files :(. I had scanned my back up files twice, first using the AV of laptop before backing up and then using the AV of computer after backing up. I got "no threats was detected" both the times. I think I have to check the extension of the files I had backed up.
==============================

1. Prepare the fix

Open a notepad window (Start > All Programs > Accessories > Notepad), copy and paste the following code in it, and name it as fixlist.txt. Change the Save as Type to All Files and save it in the USB drive where the FRST tool is.

Be careful to select the whole content of the code below.
This has to be done using the healthy computer, right?

I'll do this process in the morning.
 
I had scanned my back up files twice, first using the AV of laptop before backing up and then using the AV of computer after backing up. I got "no threats was detected" both the times.

Actually, you have to check if these files open. If they have that extension, they got encrypted.

This has to be done using the healthy computer, right?

It would be better. Did you use a healthy computer before? If yes, use a healthy computer now too.
 
Actually, you have to check if these files open. If they have that extension, they got encrypted.
If the files are encrypted, it won't open, right?
It would be better. Did you use a healthy computer before? If yes, use a healthy computer now too.
Yes, I used a healthy computer before and I'll use it for the above process too.
 
If they are encrypted, we are going to send a sample to a site for this purpose, to check if they can get decrypted. But in most of the cases, unfortunately, this can't be done, at least at this moment.

OK, I will be waiting to see the result after the fix in Recovery Environment.
 
Another doubt. Should I keep the old FRST.txt as it is on the USB drive, or can I delete it from the USB drive?

I checked my backup files for the shgv extension using the search option, and it said no files.

C:\IIBF_ADMIT_CARD_510279573.pdf.shgv
I didn't back this file up, the file is also not necessary, but it has some info. Can the file be read by others?
 
Last edited:
Another doubt. Should I keep the old FRST.txt as it is on the USB drive, or can I delete it from the USB drive?

Yes. You can use that FRST (last update 11 Dec).

Can the file be read by others?

Since the bad guys have the key for the decryption, it's possible.
 
I was not quite specific/correct in my previous post. Since we are going to clean the computer, the bad guys won't be able to have access to the computer and your files. Theoretically, if they got into the computer and copied/stole information before they encrypted it, then yes. But let's think positively.

I would like you to run FRST in normal mode now.
  • Double-click on the FRST icon (it is on your Desktop) to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Make sure to check the 90 Days Files option, under the section of the Optional Scans.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.
 
Last edited:
Good! (y)

I will review your logs tonight, after work.
 
Hi, Soor.

There are many things to be done, before proceeding to a further cleaning. Let's start.

1. P2P program

You have μTorrent installed in your computer. This is a P2P program. P2P programs form a direct conduit on to a computer. They have always been a target of malware writers and are increasingly so of late. P2P security measures are easily circumvented and if your P2P program is not configured correctly, you may be sharing more files than you realize. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program. If you don't uninstall it, your computer will probably get infected again, as soon as you use it again. But it is your computer and of course your decision.
  • If you decide to keep it, DON'T use it during the cleaning procedure.
  • If you decide to uninstall it, uninstall it along with the unwanted programs in Step 3 below.

2. Security Protection

You have Kaspersky Total Security installed. Is this the trial version or did you pay for it? If you don't intend to buy it, please uninstall it:

• Visit this site and follow the steps to run the Kaspersky Antivirus Removal Tool
• If not done automatically reboot your computer

You have also McAfee® Central for Dell application, which is not shown as enabled in the Security Center. There are also some orphan McAfee files, probably from previous installations.

First, uninstall the app: Press Start button, find McAfee Central for Dell, right click and choose Uninstall.

Then, run the Removal Tool to check for/remove remnants (Method 2): McAfee KB - How to remove McAfee products from a PC that runs Windows (TS101331)


3. Uninstall programs

Microsoft Office Enterprise 2007

Enterprise edition is for big companies and not for individuals. Therefore, the license used here is not legal, unless the computer belongs to a company. If this is not the case, please uninstall it. Having not legally activated programs installed, is the best and easiest way to infect a computer.

Adobe Player and Java

Adobe Shockwave Player isn't supported anymore. Having it installed is a security risk.

There are very few reasons these days to continue having Java installed on your computer. However, if you do elect to keep Java, it needs to be updated to the latest version. If you need it, do that at the end of the cleaning procedure.

Other programs

There are other programs installed in the computer not legally activated. Please uninstall them.


To uninstall the programs:
  • Press the Windows Key + R.
  • Type appwiz.cpl in the Run box and click OK.
  • The Add/Remove Programs list will open. Locate the following programs on the list:
Code:
µTorrent *
Adobe Shockwave Player 12.3
Adobe Shockwave Player 12.3
Java 8 Update 241
Java SE Development Kit 8 Update 241
Java(TM) SE Development Kit 17.0.1
Microsoft Office Enterprise 2007
Other Programs not legally activated
  • Select the above programs, one by one, and click Uninstall.
  • Restart the computer.

4. Uninstall a Chrome extension
  • Open Chrome.
  • At the top right choose More (the three vertical dots) > More Tools > Extensions
  • Find MySearch, and remove it, clicking on Remove.
  • Confirm the action by clicking Remove once again.

5. Notifications

Did you intentionally enable notifications from the following sites?

hxxps://mysite.m4marry.com;
hxxps://www.sanfoundry.com


6. Fresh FRST logs

After doing the above, please attach fresh FRST logs, Addition and FRST.


In your next reply please post:
  1. Which programs you uninstalled (Steps 1, 2, 3)
  2. If the extension is successfully removed (Step 4)
  3. A reply about the Chrome notifications (Step 5)
  4. The fresh FRST logs, Addition and FRST.
 
Last edited:
The version of Kaspersky Antivirus I use is the paid version.


1. Uninstalled

µTorrent *

Adobe Shockwave Player 12.3

Adobe Shockwave Player 12.3

Java 8 Update 241

Java SE Development Kit 8 Update 241

Java(TM) SE Development Kit 17.0.1

Microsoft Office Enterprise 2007

Other Programs not legally activated (not sure about some of them though about the activation thing)

-7zip

-Adobe Photoshop 7.0

-Alpine Valley 3D Screensaver

-CCleaner

-Adobe Flash Player

-Fonedog Toolkit for Android

-Hotspot Shield

-Keepvid Pro (it said it had already been uninstalled)

-MKV to MP4 Converter (same as above)

-Morning Snowfall Screensaver 2.0

-Mount&Blade With Fire and Sword

-PhoneRescue for Android

-Pixillion Image Converter

-PowerISO (same as Keepvid Pro)

-Snow Village 3D Screensaver and Animated Wallpaper

-Spotify

Ran the MCPR removal tool. It said "Incomplete Uninstallation. Some or all files may not have been removed successfully. See logs for more details".


I don't know whether some other programs may have to be uninstalled or not. If anything else needs to be uninstalled, please let me know.


2. Removed the chrome extension. I noticed a thing in chrome settings. It said "Your browser is managed by your organization". It's them.


3. I guess those notifications were enabled by us. I have blocked them now. Also, there are some more new websites added to the "Not allowed to send notifications" list.


4. Logs:

(I did not check the 90 Days Files in the Optional Scan this time).
 

Attachments

It looks like you did a good job, Soor!

I'll review your logs tomorrow.

In the meantime, try this to uninstall McAfee remnants, and let me know about the result:
  • Download the Revo Uninstaller (Free Download) and save it on your Desktop.
  • Double click on the exe file created on your Desktop to run the installer, and follow the instructions to install the program.
  • Double click the program's icon to open it.
  • Write in the search area, on the top left, the following:
Code:
McAfee
  • Choose the Uninstall tab from the menu and let the program to create a Restore point.
  • Choose Scan, and then the Advanced mode scan.
  • Select all the McAfee items found, Delete and Next.
  • Let the procedure be completed and click on Finish.
  • Restart the computer.
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top