Unsure If Malware Or Not

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by l.i.s, Sep 2, 2016.

  1. l.i.s

    l.i.s Private E-2

    I have run all the cleaning procedures and they showed a couple of things, The only thing I can see happening on my laptop is that when I use Chrome, IE, or Firefox and try and go to ThePirateBay (hope this is legal in this thread, if not please delete), each browser give website cant be reached or take me to a 404 page.
    I can open TPB on ipad and iphone why not on this laptop or my desktop?

    Thanks for any help
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Just maybe your protection software is saving your.... systems.:D

    http://www.majorgeeks.com/news/story/pirate_bay_serving_up_malware.html

    I'll look over your logs for malware and post back later tonight.
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your MGlogs.zip is very incomplete. Did you wait for the prompt to "Hit any key to close"?

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select "Run As Administrator").
    Upload the new zip file in your next reply.
     
  4. l.i.s

    l.i.s Private E-2

    Thanks for the info and help.I have uploaded the files as requested.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The file should be atleast 200kb in size. and contain 22 log files. Try again please.
     
  6. l.i.s

    l.i.s Private E-2

    It says its 222kb in windows explorer when I attach
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please use MSconfig to reset your machine for Normal Startup Mode. Any other mode is primarily used for temporary troubleshooting and diagnostic purposes. View the following link for some proper tools to use:
    Dealing With Startup Processes

    *Navigate to this file > right-click Properties > Details tab ... what info is listed there?
    C:\Users\Mick\AppData\Local\Temp\{7404E6AB-A57F-476D-AE19-01FC9B3104BA}\{0C4BFE89-347D-4752-A8FF-34AE468044E8}.exe

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.
    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
     
  8. l.i.s

    l.i.s Private E-2

    HI, Normal Startup Mode was already setup in MSConfig, hit OK anyway to close. JRT found nothing, attached file. AdwCleaner did not find anything (attach file), I am sorry but I had run it last night before posting thread, I have also attached that file as Adwold. Sorry about running them last night.

    Also C:\Users\Mick\AppData\Local\Temp\{7404E6AB-A57F-476D-AE19-01FC9B3104BA}\{0C4BFE89-347D-4752-A8FF-34AE468044E8}.exe

    does not exist
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    This is an example of scans/logs being generated and then changes are made by the user.
    Here's the listing showing that MSconfig was being used to control startups when MGTools.exe was ran.
    It no longer exists... :)


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
  10. l.i.s

    l.i.s Private E-2

    I swear I did not change ONE thing, and did all that you asked. I still can not open <Moderator EDIT to break link> xxx.thepiratebay.org or .se in any browser.
     
    Last edited by a moderator: Sep 3, 2016
  11. l.i.s

    l.i.s Private E-2

    Thinking out loud..... Could this be a Router problem somehow?
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    This indicates why I don't think it's the router, if that is the only site that you are prevented from visiting... with any browser you use on your pc. How are you accessing that site with your Ipad? Through the router - wifi? If so, that tells you it's not the router.
     
  13. l.i.s

    l.i.s Private E-2

    it is def the only website i can not get to. Now i think about it I can get to it on ipad and iphone through router network so its not the router. Corrupt host file or something on both laptop and desktop maybe?
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Possibly... also perhaps your security software is preventing access.
     
  15. l.i.s

    l.i.s Private E-2

    it now opens on this laptop sometimes but only sort of half loads (load1.jpg), when i refresh i get load2.jpeg2
     

    Attached Files:

  16. l.i.s

    l.i.s Private E-2

    I have avast disabled ATM as per request at top of post
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Well, we have eliminated malware as the cause of your problem and further troubleshooting is needed in another forum on this board. Perhaps you can find a solution with the help from other specialists in our Software Forum.

    Best of luck,
    dr.m
     
  18. l.i.s

    l.i.s Private E-2

    thanks for everything
     
  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds