Simple question...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jmacintosh, Aug 29, 2014.

  1. jmacintosh

    jmacintosh Private E-2

    I am reading the cleanup procedures for Win 7 64 bit.

    Am I reading this correctly that I am to do a ONLY a scan using Roguekiller, then actually run the other programs?

    Am I ever to go back and actually run Roguekiller and have it clean anything? Or is this taken care of by the other programs?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We just want you to run the programs and then Attach the requested logs.
     
  3. jmacintosh

    jmacintosh Private E-2

    so I am running just scans and not cleans then...ok.

    Malwarebytes quarantines whatever it finds, but the other programs can just be used to scan and leave logs...ok

    Just trying to make sure I understand what you want
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is right. Plus, you should tell me what issues you are having.
     
  5. jmacintosh

    jmacintosh Private E-2

    Got digital herpes

    Dell Win 7 64 bit

    having issues with registry entries that reinstall themselves in the startup menu viewable in MSconfig. After running scans and MGtools I now get dialogue box that pop up saying Host processes for Windows Services has stopped working. It reappears every few minutes
    logs attached

    thank you in advance for your help
     

    Attached Files:

    Last edited by a moderator: Aug 29, 2014
  6. jmacintosh

    jmacintosh Private E-2

    I also should add that I attempted to do a windows update before scans and got two errors...

    Code 9c47 and 643

    enclosed a screenie of my startup
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it fix everything it found.

    Then rescan with RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry Entries : 36 ¤¤¤
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | ?tluafed?  : C:\Users\AppleAuto-01\Application Data\{0000517C-2232-5526-B7A9-0CA83A46097C}.exe  -> FOUND
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Arfuryalbyofil : "C:\Users\AppleAuto-01\AppData\Roaming\Eskizouk\xuoruky.exe"  -> FOUND
    [Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Arfuryalbyofil : C:\Users\AppleAuto-01\AppData\Roaming\Eskizouk\xuoruky.exe  -> FOUND
    [Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | {57726a88-08a8-18bf-4819-8ea682fb8f1e} : "C:\Users\AppleAuto-01\AppData\Local\Microsoft\{57726a88-08a8-18bf-4819-8ea682fb8f1e}\{57726a88-08a8-18bf-4819-8ea682fb8f1e}.exe"  -> FOUND
    [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-907975548-1222146210-4142812038-1000\Software\Microsoft\Windows\CurrentVersion\Run | Arfuryalbyofil : C:\Users\AppleAuto-01\AppData\Roaming\Eskizouk\xuoruky.exe  -> FOUND
    [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-907975548-1222146210-4142812038-1000\Software\Microsoft\Windows\CurrentVersion\Run | Arfuryalbyofil : C:\Users\AppleAuto-01\AppData\Roaming\Eskizouk\xuoruky.exe  -> FOUND
    Reboot and rescan with both Hitman and RogueKiller and attach the new logs.
     
  8. jmacintosh

    jmacintosh Private E-2

    I think I may have got it...pain in the *** it is...
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things running now?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Has it yet been established whether or not this user is intentionally set up to use a PROXY? :confused
     
  11. jmacintosh

    jmacintosh Private E-2

    I do have Zenmate running under Chrome, but not under any other browser.

    It is running much better, and those strange file names that kept reinstalling themselves seem to be gone.

    Is there anything questionable in the logs I sent after the scan? I won't be back in front of that computer until Tuesday.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for letting us know. When we see a proxy running it's always important for us to at least ask about it. :)
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds