Old Man Slow Computer Full Of Junk - Malware. Logs Attached.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Labtec600, Nov 27, 2015.

  1. Labtec600

    Labtec600 Private E-2

    Hello,

    My grandfather has a new computer that he has managed to fill with crap by keeping "yes" checked for every download. The start up is terribly slow, programs run slow or dont run at all. I have went through the read and try me first and this has made the computer a little faster, but some of the programs pulled threats that I left on per instructions so would like to see if anything else can be removed. Computer is still a little slow.

    Also, Norton Security Scan is loaded on and it will not come off. I have tried to uninstall through control panel and it just gets hung up on "preparing to uninstall please wait" and have tried the Norton Removal tool but it too does not work. Was planning on loading AVG.

    Thanks,
     

    Attached Files:

  2. Labtec600

    Labtec600 Private E-2

    MG log attached - couldnt add to first post.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there Labtec600,

    I am reviewing your logs and will get back to you with a response shortly.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please try using Revo Uninstaller (which is already installed) to remove Norton. Let me know how you get on.

    Re run Hitman Pro, enable/activate the free trial, and let it remove all that it finds.

    Give Malware Bytes a re run and let it remove anything else it may find.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a235e1e3-6296-4710-af39-104a7faa6c7c} -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f236ca79-3123-4afb-9f74-e98117ad5625} -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these items on the Files tab...

    • [PUP][Folder] C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} -> Found
    • [PUP][Folder] C:\Program Files (x86)\Driver Detective -> Found
    • [PUP][Folder] C:\Program Files (x86)\DriverUpdate -> Found


    ...and the same for this item on Web Browsers tab...


    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Delete this:
    • C:\Windows\system32\tasks\0615pizUpdateInfo


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now re run Hitman Pro again and attach the new log, we will see if anything remains.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  5. Labtec600

    Labtec600 Private E-2

    Hello,

    Thanks for the reply. Sorry for the delay, family stuff going on.

    Revouninstaller would not remove norton still. It brings up the Norton uninstaller which just gets stuck at the same "preparing to uninstall please wait". Left it for about an hour, so assume it's not working? Went through the other steps and got to the rogue killer - couple things:

    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a235e1e3-6296-4710-af39-104a7faa6c7c} -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f236ca79-3123-4afb-9f74-e98117ad5625} -> Found
    These no longer came up.

    • [PUP][Folder] C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} -> Found
    • [PUP][Folder] C:\Program Files (x86)\Driver Detective -> Found
    • [PUP][Folder] C:\Program Files (x86)\DriverUpdate -> Found
    Deleted.

    [PUM.HomePage][FIREFX:Config] seuwu8ak.default-1440687892402 : user_pref("browser.startup.homepage", "http://home.tb.ask.com/index.jhtml

    No longer shows. There is a similar one which I deleted by mistake as it was the same number, but it's not it. I do not see anything different now. No log saved to the desk top so I saved manually and attached. I have not gone through the rest of the steps yet. Wanted to see first as a few files are not showing now so not sure if something different is to be done.

    Thanks again for the reply, big help.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning!

    Continue on with other instructions : - )

    Also do this to try and remove Norton:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  7. Labtec600

    Labtec600 Private E-2

    Hello, how goes it?

    Norton is gone.

    Ran hitman - just found cookies. Logs attached.

    Start up is much nicer. Thank you so much for the help on this.
     

    Attached Files:

    Kestrel13! likes this.
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look good to me. Are you ready for final steps as I'm seeing nothing else to do? ;)
     
  9. Labtec600

    Labtec600 Private E-2

    Sure, ready!
     
    Kestrel13! likes this.
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds