Trying To Clean Family Laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by THE_CANADIAN, Apr 19, 2016.

  1. THE_CANADIAN

    THE_CANADIAN Specialist

    hey guys,

    Im on a family laptop and it seems my mom fell for some spyware fake virus infection , long story short the laptop was pretty infected. The computer recommended a refresh so it did that and i ran the programs from the read and run , everything seemed fine so i left it at that. Well someone was on the computer checking emails and all the fake virus messages came back so i ran the read and run again and have the logs.

    see if you can help me out getting it cleaned for good! thanks in advance anyone really appreciate the help always.

    logs attached if anything is wrong or any step needs to be re-done just post up! :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not seeing any issues in the logs but let's run the below just to be safe.


    Now please run the below anti-rootkit tool from Malwarebytes.
    • Download Malwarebytes Anti-Rootkit
    • If you happened to get a ZIP file version instead of an EXE file then unzip the contents to a folder in a convenient location.
    • Open the folder where you saved Malwarebytes Anti-Rootkit to. Now run mbar-1.07.0.1009.exe ( If running Vista, Win7 or Win 8, use right click and Select Run As Administrator )
      • Note: This filename will change as new versions are released, so this is just an example ).
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
      • Internet access
      • Windows Update
      • Windows Firewall
    • If there are additional problems with your system, such as any of those listed above or other system issues, then run the 'fixdamage' tool included with Malwarebytes Anti-Rootkit and reboot.
    • Verify that your system is now functioning normally.

    There will now be two log files created in the mbar folder called system-log.txt and one that starts with mbar-log. The mbar-log file will always start with mbar-log, but the rest will be named using a timestamp indicating the time it was run. For example, mbar-log-2012-11-12 (19-13-32).txt corresponds to mbar-log-year-month-day (hour-minute-second).txt. The system-log.txt contains information about each time you have run MBAR and contains diagnostic information from the program. A new mbar-log is created every time you run MBAR and will contain information about what was detected and removed. Please attach these logs.
     
    THE_CANADIAN likes this.
  3. THE_CANADIAN

    THE_CANADIAN Specialist

    hi chaslang,

    thanks for the help, i ran MBAR and it didnt seem to find anything. i haven't run into the pop up with fake malware detected again but no one has been using the laptop so im not sure how it keeps coming up. i ran all those previous scans right after it happened.

    logs attached :) thank you
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still all clean! So nothing for us to do right now except final instructions.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
    THE_CANADIAN likes this.
  5. THE_CANADIAN

    THE_CANADIAN Specialist

    Will do! if the problem returns just so i know what to do next time, should i re-run the read & run me or MBAR ? just want to keep myself ahead of this unless if i am 100% clean hopefully it doesn't come back and wont have to worry ahah :)

    Thanks for your help i always appreciate it ! much love!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you run into a problem again, I suggest that you run the regular Malwarebytes Antimalware scan and fix what it finds ( save a log just in case we need it later ). If this does not help then run the full READ & RUN ME FIRST and attach all the logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds