malware removal *followed all steps (1-4)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hawley1109, May 23, 2013.

  1. hawley1109

    hawley1109 Private E-2

    hi, recently ive been noticing a lot of pop ups, usually with every new address i open, or i will have a really slow internet activation time (when i start google chrome it takes forevaaaaa). I have also noticed a program called strongvault, i immidiately googled it and came to this awsome forum site, when i was reading through a post, i realized i also had what i thought was another malware program: delta search bar. I left my room door open one day and my roommates friend went on a downloading spree and since ive been having these problems. I have also noticed toolbars in my mozilla and chrome popping up when i start them, i reinstalled mozilla and chrome and that fixed it. since i ran ccleaner (today), i havent really had many pop ups, but i did do all of the other steps and i have some logs for you awsome tech savy people to look thru =P. I noticed quite a few threats detected with all of the scans that i did, however tdsskiller did not show results for threats so i left that log out. I greatly appreciate the effort you all put forward to helping people like me(i feel so lost haha). i am a very patient person, so no bumping of this thread will happen i assure you. THANKS!
     

    Attached Files:

    Last edited: May 23, 2013
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun MBAM and have it fix everything it found.

    Now Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [TASK][ROGUE ST] 0 : c:\program files (x86)\internet explorer\iexplore.exe -> FOUND
      [TASK][ROGUE ST] 4808 : wscript.exe C:\Users\Jonathan Hawley\AppData\Local\Temp\launchie.vbs //B

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now rerun Hitman and have it fix everything it found.

    Reboot and rescan with both RogueKiller and Hitman and attach those new logs as well.

    Be sure to tell me how things are running.
     
  3. hawley1109

    hawley1109 Private E-2

    ok so far things are running alot smoother, i did notice delta search bar pop up once before the scan however after i deleted/removed files with the software i havent seen it. things seem to be running good at this time. i followed the steps you provided to the "T". I have said logs,after reboot, hitman did not find any malicious software. Im not sure if roguekiller found anything but i have the logs from the initial scan, the scan after i deleted said files, and the scan after using hitman. thanks for your help i sense we are close to resolving this one =)
     

    Attached Files:

    Last edited: May 24, 2013
  4. hawley1109

    hawley1109 Private E-2

    and hitman i forgot that one.
     

    Attached Files:

    Last edited: May 25, 2013
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it delete all of those PUP's. ( Potentially Unwanted Programs ).
     
  6. hawley1109

    hawley1109 Private E-2

    i deleted everything on hitman, still getting babylon.search as my initial webpage when i start up chrome.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    While you have Google Chrome open, type this into the address bar and press ENTER: chrome://chrome/settings/

    Now remove all Babylon items.

    Then:

    [​IMG] Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  8. hawley1109

    hawley1109 Private E-2

    did the steps, heres the log
     

    Attached Files:

    • JRT.txt
      File size:
      31.4 KB
      Views:
      2
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things running now?
     
  10. hawley1109

    hawley1109 Private E-2

    TimW, things are running superb! I greatly appreciate your help!!! I will monitor for a few days to see if there is still anything left.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds