A quick question about doing the Malware thread...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HisAngel, Aug 8, 2015.

  1. HisAngel

    HisAngel Private First Class

    I am trying to clean up my husbands Windows 8 PC for the installation of Windows 10. Only problem is he has so much crap on his PC I can not even open Major Geeks website to Download the tools to fix it. My question is....Can I download the tools to a zip from my PC and move them and run them on his pc to hopefully fix it that way? I have to do something cause I went to the MG's site and I had to repeatedly close ad after ad after ad and I have literally waited for 10 mins and the page still has not loaded. So the only thing I can think of is to download from here and move them to his.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can download to a flash drive and move the tools to the infected machine.
    You may have to run them in safe mode.
     
  3. HisAngel

    HisAngel Private First Class

    Thank you very much.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach logs when you are ready.
     
  5. HisAngel

    HisAngel Private First Class

    Does Windows 8 not hide any files or folders? I am gathering the info to clean hubby's pc but when I went to copy the info on how to show hidden files and folders I saw all but Windows 8. If they do hide them can you tell me how to un-hide them please?

    I will post the logs as soon as I gather them. Thank you. Should I post on this same thread or start a new one?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. HisAngel

    HisAngel Private First Class

    I did not see a Windows 8 set.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Follow the instructions for Win7.
     
  9. HisAngel

    HisAngel Private First Class

    Ok I am having 1 problem here....It will not allow me to download anything to the C drive and I am using the account with Administrative privileges. How do I run MGtools? Also Should I be putting the logs in a new thread or here?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can, download them to your desktop. And attach the logs to this thread.
     
  11. HisAngel

    HisAngel Private First Class

    I finally got the last one ran. I had to boot to safe mode (that was a big fiasco) to get it to C drive but I got it.

    Here are the logs.....
     

    Attached Files:

  12. HisAngel

    HisAngel Private First Class

    Here are the rest of the logs. I had to zip CCleaner cause it was .1kb over the limit lol.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it remove all it finds.

    Now rerun RogueKiller and have it fix these items:

    Code:
    ¤¤¤ Registry : 10 ¤¤¤
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jxyeJJR ("C:\ProgramData\RpZXHc\jxyeJJR.exe") -> Found
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\jxyeJJR ("C:\ProgramData\RpZXHc\jxyeJJR.exe") -> Found
    Now have it fix these items:
    Code:
    ¤¤¤ Tasks : 2 ¤¤¤
    [Suspicious.Path] \Ifalneho -- "C:\ProgramData\Ifalneho\1.0.4.1\tecinama.exe" ("/e=L3A9MTkwNjAxXi91PTgyMDAxYjAzYzMyMTQ2ZjQ4ZjkwMTM3MDMzZDNkN2UzXi9kPWNyaW1ldGhyZWF0YWxlcnQuY29tXi9uPUNSTUVeL2E9Q3JpbWVXYXRjaF4vdA==") -> Found
    [Suspicious.Path] \Mart Component -- C:\WINDOWS\system32\rundll32.exe ("C:\Users\danny\AppData\Local\Mart Component\Bin\MartComponent.dll",#3) -> Found

    Download OTM by Old Timer and save it to your Desktop.

    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\WINDOWS\TEMP\*.*
    C:\Users\danny\AppData\Local\Temp\*.*
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6167D44D-C80F-462A-8799-DF50D8B8BE70}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}]
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Now rescan in normal mode with both RogueKiller and Hitman and attach the logs along with the OTM log.
     
  14. HisAngel

    HisAngel Private First Class

    OK I ran Hitman and RK (logs attached).

    Hitman would not let me clean anything unless I bought it and I just don't have the money to buy it right now.

    I could not find the first 2 codes in RK but the 2nd ones are fixed.

    OTM did not give me a chance to copy the other side when it was done but the logs are attached.

    I attached the 2nd logs of Hitman and RK also.

    It is still hard to do anything online on his PC but I have managed to make this post from his PC.

    There is something new that has come up...Now anything I am working with, web page, file folder, or Icon etc., has a blue outlined box around it.
     

    Attached Files:

  15. HisAngel

    HisAngel Private First Class

    Pic of the blue box that goes around everything.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have a free trial on Hitman. Just activate it and remove what it found.
    I am not seeing any additional malware. You may have to post in the software forum for additional assistance.
     
  17. HisAngel

    HisAngel Private First Class

    Can I ask how to activate it? Would it be safe to update 10 now? Could it be a software that is causing all the ads?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It must be already active as it did remove a lot of the crap. As to updating, that may help. Let me know if it does. Are you talking about updating to Win 10? What ads are you talking about? And if which browser?

    You need to resolve your issues before you upgrade.
     
    Last edited: Aug 11, 2015
  19. HisAngel

    HisAngel Private First Class

    Yes I am talking about upgrading to Windows 10.

    I am having issues with popups, pop unders, redirection, and ads on the page that make it move as slow as a snail till I close them all then it auto refreshes the page and I have to start over closing them again and when I open either one it does not go to Google. Instead it says Google has claimed you as a lucky winner and redirects me to some page to claim my prize. No I do not click anything but a new tab and the X to close the page.

    He has IE and Chrome and it is happening on both browsers.
     
    Last edited: Aug 11, 2015
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  21. HisAngel

    HisAngel Private First Class

    Here are the logs you asked for. The one with the 2 is from the scanner it's self. I did not know if they were the same or not so I added both.

    There were a lot of Reg. files so I was afraid to delete till you looked at them. I still have the scanner open on his PC with all files waiting to be deleted.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Clean everything it finds. Then reboot and rescan and attach a new log. Be sure to tell me how things are running.
     
  23. HisAngel

    HisAngel Private First Class

    By George I think we got it LOL. Ads seem to be gone and when I open IE or Chrome either one, google opens. So I am posting logs and holding scanner open to see if you want me to remove anything but all looks great. Thank you so much TimW you are awesome.

    Please let me know if I need to delete anything else. Also Please let me know if it is safe to upgrade his PC to Windows 10.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Delete the last bit that ADW found. You should be fine to do an upgrade now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  25. HisAngel

    HisAngel Private First Class

    Thank you so much TimW. My hubby's PC is all set for Windows 10 now. You are awesome.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck with the upgrade. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds