Is this machine clean (Computer run slow)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ONEEYEMAN, Jan 8, 2014.

  1. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    First of all Happy New Year to everybody who is helping people here with the cleaning process. You are all doing very important stuff for people.
    Now, to my problem. During the new year celebration I was invited to my wife's brother house and eventually was asked to look at his laptop as it become slow.
    I did uninstall couple of things manually and then run R&R process.
    MalwareBytes did find some stuff which was successfully cleaned. Ether Hitman Pro or TDSSKiller did find some more, but said that it is OK.

    So now I'm wondering if the system is really clean.
    Could someone please take a look?

    Thank you.

    [EDIT]
    P.S.: I just woke this machine up and there is a lot of HDD activity going on. So I presume something is still present...
    [/EDIT]
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode


    If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Re run Hitman and have it remove Potential Unwanted Programs.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this 1 detection:

    • [V1][SUSP PATH] TopArcadeHits.job : C:\Documents and Settings\boris spektor\Local Settings\Application Data\TopArcadeHits\updater.exe [x] -> FOUND
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Documents and Settings\boris spektor\Local Settings\Application Data\Conduit
    C:\Documents and Settings\boris spektor\Local Settings\Application Data\Strongvault
    C:\Documents and Settings\boris spektor\Local Settings\Application Data\Strongvault Online Backup
    C:\Documents and Settings\boris spektor\Local Settings\Application Data\SySaver
    C:\Documents and Settings\AI_RecycleBin
    C:\WINDOWS\Tasks\SpeedUpMyPC.job
    C:\Documents and Settings\boris spektor\Local Settings\Application Data\TopArcadeHits
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3CF0B4AF-55BA-44EA-A40A-07DE07B69F57}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13,
    Ups... Sorry about that. I should've checked.

    No we do not and this step is done.

    OK, here's the question. HitmanPro found a lot of stuff which says "Ignore". Should I change them or keep them "Ignore"'d?

    Thank you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want all the Rocketfuel, SpeedupmyPC, Conduit items gone, Hitman labels them as Potential Unwanted Programs.
     
  5. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13,
    Now this is done.

    Now here's my next problem. There is no such item on the "Registry" tab.
    What am I suppose to do?
    Thank you.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just continue on. :)
     
  7. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13,
    OK, continuing...

    Here's the problem.
    I copy pasted the text into the OTM, and hit the button. And then nothing happens. The button was still pressed and it looks like the computer is frozen somewhere.
    The mouse is alive and I can minimize the Windows to the task bar but I can't do anything else.
    What did we do wrong? What else?

    Thank you.
     
    Last edited by a moderator: Jan 11, 2014
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Replace the OTM step with the below and then continue on.

    OK, you can manually delete these:
    • C:\Documents and Settings\boris spektor\Local Settings\Application Data\Conduit
    • C:\Documents and Settings\boris spektor\Local Settings\Application Data\Strongvault
    • C:\Documents and Settings\boris spektor\Local Settings\Application Data\Strongvault Online Backup
    • C:\Documents and Settings\boris spektor\Local Settings\Application Data\SySaver
    • C:\Documents and Settings\AI_RecycleBin
    • C:\WINDOWS\Tasks\SpeedUpMyPC.job
    • C:\Documents and Settings\boris spektor\Local Settings\Application Data\TopArcadeHits


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  9. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    Since the laptop was unresponsive I cold-rebooted it (power off/on).
    Upon start-up it gave message that it can't load user profile.

    I hit OK and it did continue by recreating the user profile.
    Now, I have a booted-up machine where all my Desktop icons, but standard ones are gone.

    Does this mean that the profile had been re-created? What should I do?

    Thank you.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can ask about that in the software forum. Let's do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13!,
    Well the question is whether it is safe to run anything right now.
    Because if the profile of the user is saved somewhere, and it will be gone after that run it will be really unfortunate.

    Thank you.
    Do you have any idea what went wrong? Is the old profile there somewhere or its gone?

    Thank you.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You may have to copy your stuff from C:\Documents and Settings\boris spektor but this is topic for the software forum. You should post about it in the software forum and then return here to finish up.

    Or you could take a look at this: How do I... recover a damaged Windows XP user profile?
     
  13. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13!,
    Sorry for such a long delay.
    I am back with fully recovered user profile.
    I am also finished with the original instruction to the end.

    Attached please find the logs you were asking for.

    Thank you.
     

    Attached Files:

    Last edited: Jan 16, 2014
  14. ONEEYEMAN

    ONEEYEMAN Corporal

    One more thing: how to finish Roxio Media Manager installation?
    It is currently failing...

    Thank you.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKUS\S-1-5-18\..\RunOnce: [SpUninstallDeleteDir] rmdir /s /q "C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect" (User 'SYSTEM')
    • O4 - HKUS\.DEFAULT\..\RunOnce: [SpUninstallDeleteDir] rmdir /s /q "C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect" (User 'Default user')
    After clicking Fix exit HJT.




    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Documents and Settings\AI_RecycleBin
    C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect
    C:\Documents and Settings\LocalService\Local Settings\Application Data\SearchProtect
    
    :reg
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "SpUninstallDeleteDir"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  16. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13,
    Could you tell me how to do it manually (the OTM step)?
    This is not my machine and I don't want to risk it with the user profile again. ;-)

    Thank you.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these yourself, manually.

    • C:\Documents and Settings\AI_RecycleBin
    • C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect
    • C:\Documents and Settings\LocalService\Local Settings\Application Data\SearchProtect


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now continue on with whatever else came after the OTM step please.
     
  18. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13!
    Attached please find an updated MGTools log archive.
    The Roxio Media Manager installer is still present. Looking on the web people recommend Revo free version to remove that guy. Should I get that and remove it?

    Thank you.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you can download it here. Revo Uninstaller This is non malware related, but do let me know how you get on.
     
  20. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13!,
    I ended up installing the Pro trial version.
    I successfully removed the offending Roxio piece.

    So is this the end? Are we done?

    Thank you.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect
    C:\Documents and Settings\LocalService\Local Settings\Application Data\SearchProtect
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  22. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13!,
    MGLogs log attached.

    Now, any idea why minimizing the program, i.e. FireFox, takes a long time and its a visible process?

    Thank you.
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  24. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13!,
    Attached both logs.

    Thank you.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you see these folders?

    • C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect
    • C:\Documents and Settings\LocalService\Local Settings\Application Data\SearchProtect

    Are you able to rename them?
     
  26. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    No, I don't see them.
    Does this mean MGTools has a bug?

    Thank you.
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No idea. That's topic for the software forum.

    I'll ask Chaslang about those folders.

    In the mean time, is everything running ok?
     
  28. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi,
    Everything runs OK, just some operation is slow.
    As an example, minimizing the FF window is very visible. I can see how the screen gradually clears up to display a Desktop from FF.

    Any idea?

    Thank you.
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nope. As I said before, one for the software forum. ;) We'll see what Chas says about those folders, in the mean time, just carry on and surf around as usual.
     
  30. ONEEYEMAN

    ONEEYEMAN Corporal

    Hi, Kestrel13!,
    I live by Pacific Time and the laptop will be in my possession until Saturday afternoon.
    Any chance I will get some info before that?

    Thank you.
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well hopefully yes, if not you will have to relay the info back to the laptop owners. :)
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it means that you are not looking in the correct place one possibly due to what Kestrel13! posted. One folder is:

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\SearchProtect

    It was not the LocalService folder.

    I do not see the below in your MGlogs.zip file

    C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect

    It was probably already gone.
     
  33. ONEEYEMAN

    ONEEYEMAN Corporal

    Kestrel13!,
    Did you forget about me and this thread? ;-)

    Thank you.
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just final steps to do. :) (Sorry, I'm smack bang in the middle of moving house!)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  35. ONEEYEMAN

    ONEEYEMAN Corporal

    OK, I will pass this on.
    But what the big man said about those 2 files in question. Did you ask? Does this mean we hit the bug in MGTools?

    Thank you.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! It reported the correct information. At one point earlier in your logs, it showed the below existed:

    C:\Documents and Settings\LocalService\Local Settings\Application Data\SearchProtect

    But then after some other fixes had been run, it was now

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\SearchProtect

    And when you and Kestrel13! were looking the LocalService version, it was no longer there to remove. You needed to remove the one in the NetworkService location which is what MGtools showed.

    And for the other folder which was the below

    C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect

    It was not there at all for you to delete at all. It was only registry entry that mentioned this folder as seen in your early HijackThis log. The folder did not exist though.
     
  37. ONEEYEMAN

    ONEEYEMAN Corporal

    chaslang,
    Thank you for clarification. Good to know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds