Malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by arthurfp, Oct 21, 2014.

  1. arthurfp

    arthurfp Private E-2

    Several days ago my computer started to have strange delays.

    At first I thought it may have been a problem with my mouse because it was seemingly not consistently responding when I would click on either the left or right button. I use a wireless Logitech laser mouse and have replaced the batteries (having battery tested them first) and I have reset the Logitech connections and mouse multiple times, but I continue to have frustration with non-responsiveness and inconsistencies.

    Furthermore, I have found that it is not just that the mouse won't press stationary items, like buttons, but it will also not work when in motion such as trying press and drag the mouse to select sentences in a Word document. I am unable to get all the words to highlight no matter how many times I try, nor can I increase the success by changing the direction from which I begin the selection. Aside from Word documents, I have also found that the unresponsiveness is evident on my desktop, in games, and on my internet browser.

    I have one other strange occurrence to report. Yesterday, as I was dealing with the worst delays yet, having to click upwards of 7, 8, 9 or 10 times and still not getting the mouse/system to respond, I began to worry that my computer was going to stop working so used the CCleaner and started to prepare to back everything up. After cleaning my history, I was surprised to see that there was an item remaining in my internet history list...but it was not from the internet, at all. When I clicked on the entry, it opened the most recent Word file that I had saved. This is unnerving because this file has no connection to the internet whatsoever; it is saved in My Documents and nowhere else.

    I am really concerned that I may have something serious to address, even though the scans that I have run have not identified anything for me to address on my own. My hope is that I have followed the instructions provided in this forum by producing and uploading logs which might be useful for someone to offer additional help!

    Thank you very much!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's. Plenty available here for free at our website. :)


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Tr.Karagany][Folder] plugs -- C:\Users\A&L\AppData\Roaming\Adobe\plugs -> Found
    • [Tr.Karagany][Folder] shed -- C:\Users\A&L\AppData\Roaming\Adobe\shed -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Now re run RogueKiller (just a scan) and attach that log too please.


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    I am most grateful for your response and will be happy to follow your instructions; however, I do not know what is meant by your first step "to use MSConfig to put this machine back into normal start up mode." Would you please provide more details about how I am to complete this process?

    I have read your entire message and have found that the remaining tasks already include more detail...for which I am very grateful. I am not very "tech-y" and apologize for my lack of knowledge. I am hoping that once I understand what is involved in the first step I will be able to successfully work through the rest of the list.

    Thank you very much!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Click start > type in msconfig
    msconfig.exe will pop up, right click it and choose to run as admin
    Be on the "general" tab, and choose NORMAL start up. :)
     
  5. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    I appreciate your additional instructions.

    I did what you requested but wanted to let you know that NORMAL was already selected when I reached the msconfig General tab. Does this mean that I failed to do something correctly when running the earlier scans? Should I re-do anything before I continue with your other instructions?

    I am sorry...I am willing to do whatever is best...I just don't know what that would be.

    Thanks, again!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, just continue on. You're right, you are indeed in normal start up. :)
     
  7. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    Thank you for the clarification; I will get started on your remaining instructions, right away.

    Thank you!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No worries. ;)
     
  9. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    I'm back with another question, already. Sorry!

    Your next instructions told me to perform a scan using RogueKiller and, when finished, to click the Registry tab and locate these detections:

    [Tr.Karagany][Folder] plugs -- C:\Users\A&L\AppData\Roaming\Adobe\plugs -> Found
    [Tr.Karagany][Folder] shed -- C:\Users\A&L\AppData\Roaming\Adobe\shed -> Found

    Unfortunately, I could not find anything that matched this information under the Registry tab. I did, however, find these same items under the Files/Folders tab. They are the only two things listed under Files/Folders and they are shaded red and have checked boxes with the word Found in the Status category. Would this be helpful?

    If not, I am afraid that I will need additional information about how to identify what you would like me to do with the other items listed under the Registry tab.

    Thank you!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, files/folder tab - select them and let RogueKiller remove them.
     
  11. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    I believe I have deleted the threats. Please see the attached log. I will next be rebooting my machine and will do the follow-up scan and log, momentarily.

    Thank you!
     

    Attached Files:

  12. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    Here is the log from the RogueKiller scan completed after the computer reboot.

    I will now move on and begin downloading the next Junkware Removal Tool you suggested.

    Thank you!
     

    Attached Files:

  13. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    I think that something has gone wrong because the Junkware Removal Tool is not acting in the way that you indicated it should. I have tried to follow your instructions, twice, but the black box that shows the scan just gets to a certain point and then disappears. There is no indication that it is complete, and there is no log left on my desktop.

    I made sure that my Microsoft Essentials program was disabled and, after the first attempt to use JRT.exe seemed to fail, I took extra steps to make certain to also disable the Malwarebytes program which was downloaded during the Major Geeks Malware removal process.

    I was hoping to insure that neither program could be the cause of the disappearance of the JRT screen...to no avail. The second running of the JRT disappeared just as it did in the first instance. I have searched my entire computer for a JRT.txt file and it is not only not on my desktop, it is not anywhere in my computer.

    Do you have any further suggestions to help me complete the JRT.exe log you require?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just skip the JRT step and continue on. ;)
     
  15. arthurfp

    arthurfp Private E-2

    Will do...thank you for your continued guidance!
     
  16. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    I have completed the final step that you had given me and have attached the file you requested. I look forward to additional suggestions because I am still having serious trouble with my mouse/computer.

    Thank you!
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If it isn't because of malware, I will have to refer you to another area of our help forums. ;) Checking the logs now... will post back shortly.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, the only bit of malware that was found, RogueKiller has dealt with. Your mouse issues should be further discussed in the software forum. :) Best of luck!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  19. arthurfp

    arthurfp Private E-2

    Dear Kestrel13!,

    It is comforting to know there is no malware. I will try to explore the remaining issues over in the Software Forum, as you suggested.

    Thank you very much!
     
  20. arthurfp

    arthurfp Private E-2

    Oops...

    Kestrel13!, it's me, again...sorry...

    I just wanted to double-check your final instructions. They begin with a suggestion to keep the Malwarebytes Anti-Malware for scanning/removal of malware, but I am not sure whether that will conflict with the Microsoft Security Essentials that is already on my computer. Would you kindly let me know if having these two programs will cause trouble? I currently have both of their Real-time components disabled.

    Thanks, again!
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The two should run together no problems. :)
     
  22. arthurfp

    arthurfp Private E-2

    Thank you very much!
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds