Ran Removal/Cleaning Process- Please Check logs and Help??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pandaace, Jul 2, 2013.

  1. pandaace

    pandaace Private E-2

    I've been having issues for quite some time now. Probably over 3/4 mnths. I have had malware bytes downloaded for years and use it frequently. It does find things and I remove them but it hasn't totally fixed the issues. (For the purposes of this scan I did remove my version and used the guide to install the way it directed)

    Recently my computer has been randomly shutting down in the middle of me working. Sometimes it'll freeze and I have to hard shut it down. Sometimes it's blue screen. Sometimes it will take multiple times to turn on. Ocassionally it's just go black and go away and i'll hard shut down and start over.

    After going thru the full Malware Removal/Cleaning Procedure I still have no items at all in my start menu (an issue i've had for well over a year, maybe longer). I haven't at this point had a shut down or freeze.

    All my scans are attached. Please review and let me know how to proceed.
    Thank you for you time.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this that was just recently installed:
    C:\Windows\System32\drivers\tgbgkr.sys

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?

    [​IMG] Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. pandaace

    pandaace Private E-2

    I have not gotten a chance to take any of these measures/steps yet. Just wanted to give a quick update first.

    This is a work computer when I got in this morning I tried to start it twice (in normal mode) it complete started loaded all programs desktop perfectly than as soon as I went to move my mouse it froze (an issue that has happened before). So I hard shut down. This happened twice.

    I then opened in safe mode w. networking and it opened just fine and loaded just fine went to run an MBAM scan (I know I wasn't told you, I apologize, but i've been using this program for years and it's one of the only ways I know to get my computer to actually start running and I have to work) However it blue screened on me, and I again had to hard shut down.

    I then open in safe mode w/o network was able to run a mbam quick scan and got no results (which is odd).

    To answer your question, I have no idea what that installation could be, the only thing i've let run are ms updates. I didn't purposely install anything.

    My question is should I still continue with your suggested clean up given what happened this morning?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That driver was downloaded/installed on the 2nd. Did you install something that day? If you don't know what it is, delete it.

    Yes, you should follow my instructions.
     
  5. pandaace

    pandaace Private E-2

    I believe MS routine updates ran on the 1st or the 2nd. I have not manually installed anything!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then, as I said, delete it.
     
  7. pandaace

    pandaace Private E-2

    Thank you so very much for your replies. I am sorry for the long delay the holiday set me back I did everything you instructed with the exception of deleting the driver. This may sound dumb, but i'm not sure how to do that, I went into control panel but I don't see it listed there. How do I do that?

    Attached are the scans run from unhide, jrt, and mgtools, I also included the log they gave me from when I first ran hijack this before I deleted just in case you wanted to see that.

    At this time my start menu still hasn't restored to "normal" looking.
    In addition now my email server is running weird (we use go daddy) when I called them to tell them issue (when hitting reply it no longer auto-populates who to send to, won't let me attach any files, etc.) They stated it's an IE issue and that they do not trouble shoot that. Don't know what to do? Any solutions?

    My IE is set to auto update and it tells me often it can't install updates bc I have a different "flavor". Don't know what that means.

    Can you please review new scans and see if my computer is clean and if there is anything that I can do to fix these on going issues.

    I thank you so very much for all your help. It's very greatly appreciated.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. pandaace

    pandaace Private E-2

    OK, Thank you. So per my scans is my computer virus free, should i re-enable all the stuff I had to disable?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds