i did the malware removal procedure need help, have logs and info

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dkk, Apr 23, 2015.

  1. dkk

    dkk Private E-2

    *i had some problems with my avira antivirus interfering with the first scans directed by the MG malware removal procedure. i had disabled all the avira measures including firewall, but the next time i checked they were all enabled again; i noticed it when doing the malwarebytes removal, and it wanted to remove registry things but avira stopped it. only after this did i uninstall avira, and then i ran malware bytes again (i only remembered after i reran it i did that the instructions say not to repeat steps), but this time no detections were found. so even though i thought i had disabled the antivirus, it may have been active up until after the malwarebytes scan step, ie during the roguekiller and malwarebytes scans
    **i am missing the txt logs of the mbytes scans and only have the xmls, could not upload them, i am not sure where they went but i did search for them

    So here are my logs, i followed all the instructions. The problems i am having are 1) very intrusive adware is in my chrome browser on search engine results pages (google/yahoo) and also on ebay. at one point my chrome browser was prevented from installing an adblock extension, and after speaking to some techs i believe it was the malware causing a problem, though i have been able to install it since.

    i also had trouble copying files to a usb flash drive. files copied to the drive from my computer were inaccessible, and the folder and file icons were replaced with blank ones, and all files and folders were the same 32kb size. afte that i had other problems with using the flash drive for file transfer and storage even after wiping it (a simple formatting).

    I am also having trouble with using an hp envy printer scanner (related or not i do not know), opening documents at one point was not possible, and printing from pdf's both in acrobat and from chrome (related or not i do not know). i am also seeing a notification popup in chrome whih is another form of adware malware, which tries to force open another tab which contains adware, happened even on majorgeeks, i think it got as far as opening a save dialog for a setup.exe, which i roundly closed.

    the chrome adware malware is still there after all the scans, i don't know about the files and flash drive problem.
     

    Attached Files:

    Last edited: Apr 23, 2015
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it remove all it finds.

    Now do this to reset Chrome:

    Reset Chrome to Defaults



    Reboot and rescan with Hitman and attach the new log. Tell me how things are running.
     
  3. dkk

    dkk Private E-2

    ok chrome malware/adware now gone after the hmp removal and chrome reset. 0 detections in hitmanpro scan after the restart, would that mean you don't need to see the log? i have attached it anyway.

    do you think it is safe to now save files to a flash drive from this computer? i don't want to test it and risk ruining a flash drive. is there a way to fix the flash drive which is now unable to open any files which are put on it from anywhere, even after formatting?

    i also still can't print from a pdf, it still asks to save the pdf instead, when the final print button is clicked. i have not ticked 'print to file' - the option is not available anywhere in the print dialog.

    i had to activate the free trial of HMP, but it used to be totally free; is there a free (older) version or alternative to hitman pro in the hitmanpro step in the malware removal procedure? (for if this should this happen again, which it might as this is for my grandfather who is totally unaware of what is legitimate and what is dangerous on the internet)

    can you tell me if there was something on my computer, from the logs, which would have caused the problem i had with transferring files to a flash drive? / which scans came up with malware
     

    Attached Files:

    Last edited: Apr 23, 2015
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those issues should be worked in the software forum.

    In the meantime, please do the following:

    Download OTM by Old Timer and save it to your Desktop.


    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.


    Code:
    :Processes
    explorer.exe
    
    :files
    C:\ProgramData\7552528567054537143
    C:\ProgramData\755c607c000072ef
    C:\ProgramData\cacb8cc1000073fd
    C:\ProgramData\couponcheapchea
    C:\ProgramData\{65AB91D4-DDD0-48D4-804D-C24E1FC90D44}
    C:\ProgramData\{884e698c-5385-dc90-884e-e698c538a631}
    C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.*
    C:\Users\z\AppData\Local\Temp\*.*
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  5. dkk

    dkk Private E-2

    I didn't get a chance to copy the results window before laptop reset. The log is attached. i hope this is not a problem
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At this point I will suggest you post in the software forum for additional assistance.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  7. dkk

    dkk Private E-2

    hi, after all this the adware has been coming back into chrome. i have reset chrome settings a few times since to clear it but it always comes back.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. dkk

    dkk Private E-2

    yes when i said reset chrome that is what i meant i did. i reset chrome settings to default, using 'reset chrome to (somethig or other)' . and i have had to do it several times as it comes back every time
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does it happen in other browsers?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds