Suspected malware...attached logs. Please help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Chrissyade, Apr 23, 2013.

  1. Chrissyade

    Chrissyade Private E-2

    I have been having some issues with my desktop for a while now. It has been running super slow, especially the past couple of weeks. It takes forever to open up anything at all, whether it is a browser or just windows explorer.

    Also, I have been hearing random static in my speakers for the past couple of years. I've checked everything to do with my speakers and I cannot find a reason for it. I didn't think it had anything to do with a virus until I happened upon another person's thread in another forum stating they had found a severe Rootkit virus, or whatever, that they thought caused the crackling sound. Figured it couldn't hurt to mention it.

    I just want to clean out my computer and make it run faster. I tend to have multiple things open at once, so barely being able to open a browser is frustrating. I know a little bit about computers but not a whole lot. Any help is appreciated. Oh, also, the first time I ran RogueKiller I got a blue screen of death. It completed without any issues the second time. Here are my computer specs:

    Dell XPS ONE
    Processor: Intel Core Duo CPU E4500 @ 2.20GHz
    Memory: 2 GB
    Windows Vista 34-bit
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hi Chrissyade,

    You are indeed infected with malware.

    First, can you please zip this file and attach it to your next post for analysis?

    • C:\Users\Cat\AppData\Local\rwm.exe

    __

    [​IMG] Next, reopen RogueKiller and run another Scan.
    When the scan is finished, press the Delete button.
    Attach the latest RogueKiller (delete) log for review.

    __

    [​IMG] From Programs and Features (via Control Panel), please uninstall the below:

    • AVG PC Tuneup 2011
    • Driver Detective
    • Java(TM) 6 Update 37
    • Java(TM) SE Runtime Environment 6
    • Search Protect by conduit

    __


    [​IMG] Please download and run AVG Remover

    __

    Now, download and run AdwCleaner.
    When the program opens, press the Delete button and reboot when requested.
    Attach the log from AdwCleaner that appears after the reboot.
    The log can be found in the root of your C:\ drive (C:\AdwCleaner[S?].txt )

    __

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • Press any to key to begin scanning.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (How to attach)
     
  3. Chrissyade

    Chrissyade Private E-2

    I could not find the rwm.exe file under where it is supposed to be or anywhere else on the computer.

    When attempting to uninstall Search Protect by conduit, the program force closed and disappeared from the program list. If I search for it in the computer, I come up with a registry file called Run_SearchProt0.reg.

    When I ran AVG Remover, it asked me if I wanted to continue with the removal, and when I clicked yes, nothing at all happened. Not sure if this was supposed to happen or not, but I assumed it would at least ask me to restart, lol.

    Another issue I had while completing these steps, is I incurred another blue screen of death when Deleting from AdwCleaner. Upon reboot however, I was able to run AdwCleaner and Delete without any interference, same as what happened with my original RogueKiller scan.

    Other than that, I did everything you asked.

    I very much appreciate you helping me out. I've been neglecting my poor PC for a while now.
     
  4. thisisu

    thisisu Malware Consultant

    Please attach the logs :)
     
  5. Chrissyade

    Chrissyade Private E-2

    Whoops. Sorry! :-o
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    No problem.
    Just need the log from AdwCleaner ;)

    Once you attach that, experiment a bit and let me know if the performance of the PC has improved at all.
     
  7. Chrissyade

    Chrissyade Private E-2

    Oh yeah, it didn't automatically open a report the first time I restarted after deleting. I searched and deleted again. I don't know if that will matter but it was the only way to get a log.

    Yes, my computer is running MUCH better now. Thank you so much for your help clearing it out. It's nice to be able to have 4 different programs/windows open at the same time without a problem.
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
    This updates your logs in C:\MGlogs.zip
    Attach the latest C:\MGlogs.zip for review once you have completed the scan.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds