Malware Removal logs here....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rrdjfan777, Nov 8, 2013.

  1. rrdjfan777

    rrdjfan777 Private E-2

    I am a Youtuber & heres a 42sec clip of me detailing my exact problem with my computer here:

    http://youtu.be/a850VGb1-98

    I believe it could be malware related because I did some full scans last night, and ALOT of infected stuff got removed. But I still have the distorted audio problem so I wanted to know if you could look at my attached logs, and let me know if my current audio problem is malware related somehow, or is my system clean?

    My system:
    Microsoft windows xp
    home edition
    version 2002
    service pack 3

    mobile AMD sempron(tm)
    processor 3600+
    1.99GHz, 896MB of RAM
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. rrdjfan777

    rrdjfan777 Private E-2

    I have now, yes. In my first message below, thats where the logs for malware bytes are. The rest of the logs are here in this message. Am I clean from infection or do I need fixs?
    Problem occured about a week ago, no idea how, problem being that my computer is running slower than usual and audio is distorted. You can hear what it sounds like if you see my youtube video below in first message.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good afternoon. Yes I checked out your YT vid, got a fresh coffee, and am about to review your logs. :)
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below using Revo Uninstaller.

    • Yontoo 1.10.02
      [*]BabylonObjectInstaller



    Re run Hitman and having it delete the "Malware" "Malware Remnants" and "Potential Unwanted Programs"




    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Documents and Settings\Owner\Local Settings\Application Data\MixiDJ_V37
    C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
    C:\Documents and Settings\Owner\Local Settings\Application Data\CRE
    C:\Documents and Settings\Owner\Local Settings\Application Data\Search_Spin
    C:\Documents and Settings\Owner\85ec~1        
    C:\Documents and Settings\Owner\3a20~1
    C:\Documents and Settings\Owner\3a20~2       
    C:\Documents and Settings\Owner\4530~1       
    C:\Documents and Settings\Owner\0081~1        
    C:\Documents and Settings\Owner\3a26~1        
    C:\Documents and Settings\Owner\618c~1        
    C:\Documents and Settings\Owner\382e~1        
    C:\Documents and Settings\Owner\0a2c~1        
    C:\Documents and Settings\Owner\af60~1        
    C:\Documents and Settings\Owner\2a28~1
    C:\Documents and Settings\Owner\Application Data\SearchProtect
    C:\Documents and Settings\All Users\Application Data\Conduit
    C:\Documents and Settings\All Users\Application Data\TorchCrashHandler
    C:\Documents and Settings\Owner\Local Settings\Application Data\store-pp.jbs
    C:\Documents and Settings\Owner\Local Settings\Application Data\{A1307266-A0BF-40A5-B134-02C252AE661B}
    C:\Documents and Settings\All Users\Application Data\Conduit
    C:\Documents and Settings\All Users\Application Data\TorchCrashHandler
    C:\Documents and Settings\Owner\Start Menu\Programs\Torch.lnk
    C:\Program Files\MixiDJ_V37
    C:\Program Files\MyPC Backup
    C:\Program Files\SearchProtect
    C:\Program Files\Search_Spin
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4EDEDE12-9310-4BCB-A357-D993D9BA385B}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AA71CE57-D357-44EB-B196-1F992E94069E}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R3 - URLSearchHook: Search Spin Toolbar - {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files\Search_Spin\prxtbSear.dll
    • R3 - URLSearchHook: MixiDJ V37 Toolbar - {eef3855c-fc2d-41e6-8d91-d368f51b3055} - C:\Program Files\MixiDJ_V37\prxtbMixi.dll
    • O2 - BHO: KMP Media Toolbar - {daf5b34c-1aa3-4c33-ae24-766a370635d2} - C:\Program Files\kmpmediatoolbar\searchresultsDx.dll
    • O2 - BHO: MixiDJ V37 - {eef3855c-fc2d-41e6-8d91-d368f51b3055} - C:\Program Files\MixiDJ_V37\prxtbMixi.dll
    • O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll
    • O2 - BHO: Search Spin - {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files\Search_Spin\prxtbSear.dll
    • O3 - Toolbar: KMP Media Toolbar - {daf5b34c-1aa3-4c33-ae24-766a370635d2} - C:\Program Files\kmpmediatoolbar\searchresultsDx.dll
    • O3 - Toolbar: Search Spin Toolbar - {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files\Search_Spin\prxtbSear.dll
    • O3 - Toolbar: MixiDJ V37 Toolbar - {eef3855c-fc2d-41e6-8d91-d368f51b3055} - C:\Program Files\MixiDJ_V37\prxtbMixi.dll
    • O4 - Startup: kill.bat
    • O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    After clicking Fix exit HJT.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Re run both RogueKiller and Hitman and attach the logs.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. rrdjfan777

    rrdjfan777 Private E-2

    Attached the new logs (let me know if any are missing, should be all you reuested). My sound issue is still present though as you can see here in this 20ish sec clip:

    http://youtu.be/kXu8wQhrTSs
     

    Attached Files:

    Last edited by a moderator: Nov 10, 2013
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    I'm sorry that your sound still isn't fixed. I may have to refer you onto the guys and gals in the software forum where they can further assist you.

    However, I would like to ask a couple things.
    • When did this (the sound issues) first start occurring?
    • Do you remember what you had been doing at the time?
    • Had a windows update taken place at all?

    Also, I would like for you to re run RogueKiller and have it fix the Host File entry. Then rescan with it again and attach the log.

    Also, these did NOT delete, and other stuff got missed too.
     
    Last edited: Nov 10, 2013
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue with the below after the RogueKiller step.

    Uninstall >>> KMP Media Toolbar


    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Any change with the sound?
     
  9. rrdjfan777

    rrdjfan777 Private E-2



    Okay, I already started a thread on the software forums about my audio problem:
    http://forums.majorgeeks.com/showthread.php?t=281293


    When did this (the sound issues) first start occurring? A few days ago, maybe like 4-5, hard to say exactly.

    Do you remember what you had been doing at the time? Definitely not, no.

    Had a windows update taken place at all? Nope. There hasn`t been a new windows update either.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK thanks for answering my questions.

    Please do continue with my instructions, just in case any of that garbage is causing it. :)
     
  11. rrdjfan777

    rrdjfan777 Private E-2

    Thank you for your help, your instructions were very clear. However my audio is still not fixed. Here is the rest of the logs though.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. I'm ever so sorry what we did here did not help your sound, but indeed, you can now continue to post in software about it, rest assured that malware is not the cause. :)

    Just delete these:

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\MixiDJ_V37
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Search_Spin
     
  13. rrdjfan777

    rrdjfan777 Private E-2

    Okay I did but could you message someone to take a look at my thread over there? I can`t private message, heres the thread
    http://forums.majorgeeks.com/showthread.php?t=281293


    Its been a couple days and noone has responded to my thread.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I posted something. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds