Solved CMD popup caused by Mail.ru malware?

Mana823K

New Member
Thread author
Feb 13, 2018
8
Hi.
I downloaded a file yesterday, and when I clicked it it installed random programs like Go and Mail.ru and alerted my browser, too. I deleted the file and everything that seemed to correspond with it. I also download and run Malwarebytes and HitmanPro, they solved most of the probems, but I still have CMD with outbound connection opening every hour or so. The Malwarebytes succesfully blocks it but I only have a trial licence that will run out. I also tried to reset my browser and even reinstall it, and installed Comodo Firewall and tried to block the IP address but it didn't work.
I upload the FRST and Addition file, and also Malwarebytes' report of the blocked website.
I would appreciate any help you can provide.
 

Attachments

  • FRST.txt
    33.4 KB · Views: 2
  • Addition.txt
    68.1 KB · Views: 3
  • BlockedDmc.txt
    698 bytes · Views: 4

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,

Do you remember where did you download this file yesterday?

Can you export MalwareBytes scan reports for my review? You can find it in reports section, remember I don't need website blocked reports, only the scan reports.
 

Mana823K

New Member
Thread author
Feb 13, 2018
8
Sorry, I restarted everything on my browser, so I don't know which website was it.
Yes, I can upload the scans.
Thank you for your help.
 

Attachments

  • MalwarebytesScan1.txt
    6.3 KB · Views: 5
  • MalwarebytesScan2.txt
    1.2 KB · Views: 1

Mana823K

New Member
Thread author
Feb 13, 2018
8
The program is still scanning, but it already detected 30 items. I'll tell you later, if it worked.
 

Mana823K

New Member
Thread author
Feb 13, 2018
8
Finished scanning and deleted every suspicious file, but I still have the same problem.
I attached the scan files. Every file has been deleted or replaced except C:\ProgramData\Mail.Ru, which says error. I checked the ProgramData folder but didn't find any Mail.Ru named file or folder (I set hidden files visible).
 

Attachments

  • RogueKillerScanReport.txt
    11.1 KB · Views: 4
  • RogueKillerDeleteReport.txt
    13.1 KB · Views: 3

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

Mana823K

New Member
Thread author
Feb 13, 2018
8
Done with scan, and attached the files.
 

Attachments

  • Addition.txt
    69.1 KB · Views: 1
  • FRST.txt
    89.5 KB · Views: 1

Mana823K

New Member
Thread author
Feb 13, 2018
8
Yesterday, it didn't find anything, but this time it detected 7 items and failed to remove 2 of them. I only run a system file check, to solve another issue, since my last scan (but it didn't find anything), I don't know if it has any affect.
 

Attachments

  • MalwarebytesScan.txt
    2.2 KB · Views: 3

Mana823K

New Member
Thread author
Feb 13, 2018
8
I made new FRST scans, too, if they're needed.
 

Attachments

  • Addition.txt
    64.7 KB · Views: 1
  • FRST.txt
    89.4 KB · Views: 1

Mana823K

New Member
Thread author
Feb 13, 2018
8
Well, I ran another scan and managed to remove the last items, too, and since then I don't have any CMD popups. Seems like the problem solved itself..
I'm really sorry for causing you trouble, and thank you for helping me.
 
  • Like
Reactions: darko999

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top