Popup When Logging Into Windows And Slower Computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cstrife32, Feb 12, 2016.

  1. cstrife32

    cstrife32 Private E-2

    Hello everyone,

    Thanks in advance for the help! So, a couple of months ago my friend messaged me on Steam and asked me to join his new teamspeak server and admin for it. Like a dufus, I didn't realize it was an automated message and joined. He later told me he didn't send the message, and that my computer might be infected with something. After a couple of weeks, I started to notice a consistent pop up that opens whenever I log into windows. There's never any content in the pop up, and it gives me an IE script error. Upon investigation, I found that the popup is linked to mshta.exe*32 in my processes, and when I end the process the pop up disappears, but I have a feeling that whatever it is is leeching resources from my computer because I've noticed that my performance in games (mainly lower FPS) has been unexplained as I have cleaned my computer and all my temps are fine. I've followed all the steps in the malware removal guide, and I'm still having the problem. I have attached the logs I could get. For some reason, whenever I try to click save logs in HitmanPro, it just doesn't work. I can attach screenshots of what my HitmanPro window shows right before I move to the results tab, and the results tab, if you guys like. Until then, I've attached the rest of the logs according to the malware removal procedure. Thanks again!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please, sorry for the inconveniance. ;)
     
  3. cstrife32

    cstrife32 Private E-2

    Attached. No inconvenience, you are doing me the favor after all!
     

    Attached Files:

    Kestrel13! likes this.
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One item that stands out to me from the logs is that drive C free space is too low .
     
    Kestrel13! likes this.
  5. cstrife32

    cstrife32 Private E-2

    Yeah, been working on that. Deleted a fair number of things yesterday. Currently at 33.3 GB free.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing much...


    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP][Folder] C:\ProgramData\{27440670-2ED6-4EFE-82F2-6A2927939B83} -> Found
    • [PUP][Folder] C:\ProgramData\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14} -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    What is this?
    C:\ProgramData\271368

    Let me know the exact word for word error you get.
     
  7. cstrife32

    cstrife32 Private E-2

    Hey,

    Deleted those 2 items as requested, but they were under the File/Folder tab and not the Registry tab. Roguekiller also told me nothing was actually deleted when I tried to close it. I've attached the log of Roguekiller.

    C:\ProgramData\271368 has an XML config file named sysmon.exe.config I opened the file in Visual Studio and have pasted the contents below.

    Code:
    <?xml version ="1.0"?>
    <configuration>
        <startup>
            <requiredRuntime safemode="true" imageVersion="v2.0.50727" version="v2.0.50727"/>
        </startup>
    </configuration>
    
    I have posted attached a screenshot of the exact word for word error from the pop up.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh I think you would be better off posting about that in the software forum.

    Just do this so I can have a final check before referring you on....

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  9. cstrife32

    cstrife32 Private E-2

    Ran Farbar as requested. I've attached the logs.

    Did I misunderstand the previous message when you were asking about the error? I assumed you were asking about the error I got from the popup when Windows started, which is what I attached to my previous post. If you were talking about a different error, let me know and I can try and get you that. Thanks again!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I see this in your logs:

    Can you do this...
    Could you please get this: system.hta into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    %systemdrive%\MGTools\zip "%systemdrive%\collect.zip" C:\Users\Maher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\system.hta

    log retrievable @ C:\collect.zip
     
  11. cstrife32

    cstrife32 Private E-2

    Tried that command, for whatever reason it didn't work. However, I went to the directory you requested and zipped the file myself and have it attached.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am private messaging you. ;) Look out for it.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I cannot start a conversation with you, your settings do not allow. You should try deleting that file and see what happens. It does NOT look like an important file at all. You can view the contents of the file by sending it to notepad to see for yourself if you like.
     
  14. cstrife32

    cstrife32 Private E-2

    Deleted the file, no more popup! Thanks again for all your assistance. :)

    Quick question, so do you have any idea where this application came from? It's certainly not anything I downloaded, so I'm kind of suspect there's still something on my computer, or is it possible that it was just some standalone junkware/malware?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. ;) I'm glad it's sorted. I have no idea how it could have gotten there but you have run a good deal of tools and I have reviewed all of the logs and am satisfied nothing malicious or junky remains. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds