RK shows threats in standard account

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CynBagley, Jun 5, 2014.

  1. CynBagley

    CynBagley Private E-2

    Since I had a ransomeware scare, I run RogueKiller every so often as admin on my standard account. After the upgrade to 9.2.2--- I have been getting either ZeroAccess threat killed on mcshield.exe (yep McAfee). But when I went through the run and read me on my admin account, the computer looks clean. It also changed the RK threat on the standard account.

    I have attached the four scans run on the admin account and the one RK scan (RKstandard) on the standard account.

    Thank you.
     

    Attached Files:

  2. CynBagley

    CynBagley Private E-2

    This is the RK attachment for the Standard account.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you please elaborate on this comment?
     
  4. CynBagley

    CynBagley Private E-2

    The Roguekiller I ran as admin on my standard account showed two hidden processes that it killed, but after running the programs in my admin account the killed processes changed names in the standard account. (used to say zeroaccess and now it says killed two hidden processes). Also immediately after I run RK in my standard account I get an warning from McAffee.

    To be clear-- 1- my admin account always shows clean. 2=when I run in my standard account (the one I use to connect to the internet) I get a red warning in processes in RK.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm not seeing any issues with any of those logs at all. Perhaps you should run scans on the other account and attach all of the requested logs.
     
  6. CynBagley

    CynBagley Private E-2

    I reran all the tests in the standard account except MGtools. The only one that wouldn't run properly this time was TDSS Killer. It gave me these warnings-- can't initialize log, reboot is required, and can't load driver and then didn't leave a report. (Also it shows 0 objects scanned and no threat found). This is really confusing me because TDSS scanned on that account before. Here are the other logs--

    BTW Thank you for the time you've spent looking at these logs- Cyn
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why wouldn't MGTools run? What exactly happened?

    Try this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • SN64 <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Attach the MGlogs.zip
     
  8. CynBagley

    CynBagley Private E-2

    Kestrel -

    Sorry it took so long to get you the information. Our internet provider has been working on the cards and lines around our area and it was down most of the weekend.-- After the internet finally started working properly again, I had some problems with my McAfee-- it cleared up after I did a ccleaner and rebooted. I am thinking I may get rid of this particular program and go to Avast or AVG--

    Anyway--
    After wrestling with McAfee I finally was able to run MGtools. I also ran the three other tests (I assume they were a part of MG tools). There were no unusual error messages. I have attached the zip file and the other files below.

    Once again I apologize for not getting these to you earlier.

    Thanks-- Cyn
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. Things have been super hectic. I'm reviewing those logs right now. :major
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware in those logs either. What do you want to do from here?
     
  11. CynBagley

    CynBagley Private E-2

    Kestrel--
    I think maybe I was seeing a false positive, but to be safe, I will change my anti-virus. I decided at the beginning of the year to change McAfee for another anti-virus and firewall because it takes resources and scans while I am trying to use my computer. I publish ebooks and make covers, which makes the way the bloatware grabs resources very annoying and resource intensive.

    So I guess it is time to put this computer back to normal and l'll look into changing the software. It's just several months earlier than I wanted to do it.

    Thank you very much for looking at the files-- and thank you for the help and extra eyes on my second-guessing.

    Cyn
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. If after changing anti virus you ever think something's up, don't hesitate to come back and attach logs. better to be safe than sorry.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds