help fixing a potentially infected pc

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mapmd1234, Jul 15, 2014.

  1. mapmd1234

    mapmd1234 Private E-2

    ok, so I have cleaned my pc with two bootable virus scanners, and I went to install a skyrim related program to help manage mods, and for some reason the installer cannot and will not export a single file to /program files(x86), so my question for you all, is am I apparently still infected?

    any and all help to get this system fixed will be greatly appreciated due to the fact that my windows installation is currently over 400Gb of files.
     
  2. mapmd1234

    mapmd1234 Private E-2

    upon reading more of the removal guide, and trying to run rougekillerx64, THREE TIMES it has caused my computer to blue screen upon initializing. so this is rather alarming because it leads me to believe that something is detecting its running and preventing it from finding said program that is detecting it.
     
  3. mapmd1234

    mapmd1234 Private E-2

    mbam log
    tdsskiller log
     

    Attached Files:

  4. mapmd1234

    mapmd1234 Private E-2

    hitman pro log
     

    Attached Files:

  5. mapmd1234

    mapmd1234 Private E-2

    nevermind, just saw the zipped logs for mgtools.

    mgtools logs respectively
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove the below:

    MGTools did not run correctly. Run it again this ime ensuring that you indeed ran it as admin, that antivirus/antispyware is temporarily disabled and that UAC is disabled.
    Then attach the new log.
     
  7. mapmd1234

    mapmd1234 Private E-2

    as I said before about mgtools, it closes prematurely, it throws an "access is denied" error even when right clicking it and running as admin. why it is doing this I do not know because I both dissabled each security option of comodo and then exited comodo with everything dissabled and UAC turned off.

    anyways, here is the current log none the less although I do not believe that it is what you are wanting given that it exits prematurely.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You did not explain about this before. You mentioned RogueKiller. ;)

    You need to either temporarily uninstall Comodo antivirus in order to get MGTools ran, or run it in safe mode please.
     
  9. mapmd1234

    mapmd1234 Private E-2

    mgtools log after uninstalling comodo internet security free.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs look good. What is Hitman saying when you rescan with it? Does it pick up on anything?
     
  11. mapmd1234

    mapmd1234 Private E-2

    I dont know about hitman, I am running it again now, but when scanning with kaspersky livecd it detects 16 trojans, and I keep getting more and more trojans no mater how many times I get rid of them, they just keep coming back which leads me to believe that there is something that nothing is detecting, that is downloading said trojans...likely a polymorphic of some sort........thinking I might be better off just reinstalling windows from the ground up, because I have rid my pc of these trojans going on 3 times now as of the next time I get them.

    I'll post back once hitman is done scanning

    currently, after having ran the bootable kaspersky scanner, I still cannot connect to any server run by kaspersky...I can download updates from them, but I cannot visit their website which leads me to believe I'm still infected with something that cannot be detected. because call me crazy, but I KNOW their website is online and not down. same thing for comodo.com.
     
  12. mapmd1234

    mapmd1234 Private E-2

    woa...what the hell?!

    when rerunning hitman pro, it got to the "scanning for malware remnants" and then just crashed...it found the askbar again after I removed it the first time, and then like I said, it got to the point of scanning for remnants and just...stopped, crashing and exiting from the system tray.
     
  13. mapmd1234

    mapmd1234 Private E-2

    I scanned with hitman a second time, this time it did not crash, and the only thing it found was the ask.com data like it did the first time. nothing else.
     
  14. mapmd1234

    mapmd1234 Private E-2

    latest hitmanpro log
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I need to start seeing some logs showing what infections have been found then please.
     
  16. mapmd1234

    mapmd1234 Private E-2

    I'll post the log from my current kaspersky scan once it has finished running then. currently it has run from 11pm last night till 6:36am currently, and it is only 53% done, and has found 10 items. but I will post the log when it is done.

    thanks for all your help so far, it is much appreciated.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK that's good. It might help us alot, because the other logs are not showing anything.
     
  18. mapmd1234

    mapmd1234 Private E-2

    I just noticed something new, every site I visit, except for this one apparently, now will not let me visit it, and says that the issuer certificate is untrusted, so now I cannot visit inkbunny.net, furaffinity.net, soundcloud.com, or any of the websites that I usually visit...and it was not doing this to me last night...but now all of a sudden it is doing this to me, and those are fairly big websites so I highly doubt that they are actually having issues like this, whats more, palemoon will NOT let me make an exception like it usually does...

    also, the scan is still not finished, so I'll have to post the log tonight after work, asuming it is even done by then/my pc does not get turned off.
     
  19. mapmd1234

    mapmd1234 Private E-2

    the progress of the scan from kaspersky pure 3.0...as well as the quarantine progress/status
     

    Attached Files:

  20. mapmd1234

    mapmd1234 Private E-2

    jesus criminy... the results of my 2 day nonstop scan from kaspersky pure 3.0...

    OK, after something like that long of a scan, I think my pc is clean...sheesh...the fact that there were 35 FLIPPING trojans, that might explain why I kept getting more of them given that my bootable scanners were only detecting 16...so yea, that explains why they kept coming back. sheesh...

    then again, that did scan both of my external backup drives as well as windows itself, so i might have had a few to a lot on my external drives...don't know for sure...
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Think your problems may be more suited to the software forum. There were a few false positives in that Kasperky log. Thins like Ultimate Boot CD etc..

    Run this please:

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  22. mapmd1234

    mapmd1234 Private E-2

    jrt log
     

    Attached Files:

    • JRT.txt
      File size:
      1.2 KB
      Views:
      1
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Explain which problems remain and I'll decide whether they are more suited to the software forum.
     
  24. mapmd1234

    mapmd1234 Private E-2

    with the exception of getting continuous spam connections from various companies, I think I might actually be clean from viruses now...at least as far as I can tell...everything seems to be operating as normal now.

    the spam connections are a nuisance, but I have an application that is blocking them. so its not a huge problem.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds