infected with adware/malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jan Scrivens, Jan 23, 2014.

  1. Jan Scrivens

    Jan Scrivens Private First Class

    Hello, I am having a problem with Adware? Malware? On my Asus Netbook and would appreciate your help.
    I am running Comodo Internet security (full paid for version), but don’t find it very user friendly so am thinking of changing to Avast.
    I have recently returned it to factory settings but whilst re-installing basic programmes it has become flooded with toolbars and adverts. I try to be very careful when installing but have obviously missed one of the devious installation options.
    I have worked through your read and run me first information and have worked through the recommended scans.
    I have attached my system information and scan reports, and would really appreciate you looking at them for me.
    Thanks, Jan Scrivens
     

    Attached Files:

  2. Jan Scrivens

    Jan Scrivens Private First Class

    here are the other attachments.
    I am sorry but I cannot seem to attach my system info.
    Jan
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :)

    Let me ask firstly, are you deliberately set up to use a proxy?
     
  4. Jan Scrivens

    Jan Scrivens Private First Class

    Hi, thanks for responding. Yes I am travelling abroad and using a lot of wifi links so was using Hotspot shield for added protection and to be able to access UK only sites if I needed to. I am using the free one at the minute whilst deciding if I want the full package. The free one does have adverts but they have always been subtle in the past and not a problem. These new adverts are very different and have just appeared since the resetting of the computer. Jan
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [V1][ROGUE ST] The weDownload Manager-chromeinstaller.job :
    • [V1][ROGUE ST] The weDownload Manager-firefoxinstaller.job :
    • [V2][ROGUE ST] The weDownload Manager-chromeinstaller : C:\Program Files\The weDownload Manager\The weDownload Manager-
    • [V2][ROGUE ST] The weDownload Manager-firefoxinstaller : C:\Program Files\The weDownload Manager\The weDownload Manager-firefoxinstaller.exe

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  6. Jan Scrivens

    Jan Scrivens Private First Class

    Thanks very much.
    I am travelling just now and have limited battery power and charging facilities so will have to wait a couple of days to carry out your instructions. As soon as I can I will do them and send you the results.
    Jan
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, I'll be floating around here somewhere. :)
     
  8. Jan Scrivens

    Jan Scrivens Private First Class

    OK here goes, hope I did everything right.
    Error messages were
    'nwkst'nis not recognised as an internal or external command, operable program or batch file.
    GetRunKey-the system cannot find the file specified.

    I am having a problem attaching the logs, so will try again on another reply.

    Jan
     

    Attached Files:

  9. Jan Scrivens

    Jan Scrivens Private First Class

    MGlogs.zip
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 4 detections:

    • [V1][ROGUE ST] The weDownload Manager-chromeinstaller.job :
    • [V1][ROGUE ST] The weDownload Manager-firefoxinstaller.job :
    • [V2][ROGUE ST] The weDownload Manager-chromeinstaller : C:\Program Files\The weDownload Manager\The weDownload Manager-
    • [V2][ROGUE ST] The weDownload Manager-firefoxinstaller : C:\Program Files\The weDownload Manager\The weDownload Manager-firefoxinstaller.exe

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Windows\System32\b402~1
    C:\Program Files\The weDownload Manager
    C:\Windows\Tasks\The weDownload Manager-codedownloader.job
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  11. Jan Scrivens

    Jan Scrivens Private First Class

    Hi,

    msconfig done.

    When I ran Rogue Killer it did not come up with the 4 things mentioned. I had already deleted them last time I ran it I think. Report attached.

    OTM notepad report attached.

    MGTools.zip attached.

    The random adverts have stopped and the machine is running as normal I think. However, I do not have any added security whilst using open wifi links now. The Hotspot Shield gave me added security and allowed me to access UK sites whilst travelling abroad. Can I now reinstall it, or do you think that was part of the problem?

    Thanks, Jan
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go ahead and reinstall.

    360Amigo System Speedup Free <<< Uninstall this.

    Also I asked you to do this in post #10:

    You have two antivirus installed:

    • Trend Micro Titanium
    • COMODO Internet Security Complete

    You need to uninstall one immediately.


    This file still shows: C:\Windows\Tasks\The weDownload Manager-codedownloader.job <<< Please delete it.

    Next... Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. Jan Scrivens

    Jan Scrivens Private First Class

    Hi again,

    I have uninstalled 360 Amigo.


    I did use MSConfig to put this machine back into normal start up mode the first time you asked me to.

    I have uninstalled Trend Micro Titanium which has never been activated.

    I cannot find C:\Windows\Tasks\The weDownload Manager-codedownloader.job There are 4 files in 'tasks' but not that one.

    I have run MGTools and attached log.

    Thanks
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you are attaching a set of OLD logs (Mglogs.zip) from 25th January. It's 30th today. You need to do this:

    Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.

    Download it from fresh, and run it again. Attach the MGlogs.zip once done please.
     
  15. Jan Scrivens

    Jan Scrivens Private First Class

    Hi, I tried to run MGclean.bat but although the file logo showed up when I looked for it, the computer said it was not there.
    I have run a search for it and it is not anywhere.
    Jan
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then simply redownload and re run. Let the new MGTools.exe overwrite the old. :)
     
  17. Jan Scrivens

    Jan Scrivens Private First Class

    Sorry but struggling with this!

    I have redownloaded MGTools from your site and re-run it in C:\
    I got the command prompt for seconds then went to run clean.bat again command prompt for seconds and then zip file just disappeared!

    Jan
     
  18. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Jan

    You must produce a new MGLogs.zip for attachment by re-running the downloaded MGTools.exe. *WAiT until prompted that the new zip has been created and upload it. Running the clean.bat before instructed effectly erases everything, logs and all! ;)
     
  19. Jan Scrivens

    Jan Scrivens Private First Class

    Oh sorry! I must have misread it!

    I'll try again.

    Jan
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there Jan, are you still with me?
     
  21. Jan Scrivens

    Jan Scrivens Private First Class

    Sorry.

    Yes, still here, just rravelling and internet is a bit intermittent!

    I hope I've done it right this time.

    Jan
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running currently?
     
  23. Jan Scrivens

    Jan Scrivens Private First Class

    I think it's running mainly OK. Very slow but I guess that's because it's only 2GB RAM?
    Can I get rid of some of the start up programmes again? Is there any software you'd recommend to tell me what can go and what needs to stay?
    Thanks for your help.
    Jan
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's what you have available. So yes perhaps an upgrade in memory could boost the performance even more.

    You could, but this is best further discussed in the software forum, as it's non malware related.

    I'm not seeing anything that SHOULD be uninstalled.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  25. Jan Scrivens

    Jan Scrivens Private First Class

    I already put 2GB ram in instead of 1 but was told that was the maximum I could install. Is that correct do you think?
    Thanks very much for all your help.
    Jan
     
  26. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  28. Jan Scrivens

    Jan Scrivens Private First Class

    Thanks Dr Moriarty,
    I had a feeling it was. Just have to be patient I guess.


    Thanks TimW I'll have a look at that.

    :)
    Jan
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds