Malware? Appreciate Any Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by knowsilence, May 2, 2015.

  1. knowsilence

    knowsilence Private E-2

    Hi,
    My computer started slowing down both when booting, shutting down, and began making me disconnect then reconnect to the internet (wireless). I erred and downloaded reimage repair, quickly caught it and uninstalled. I've removed most (?) of those files but some remain. And, in the process, I continue to still find malware, have registry keys I can't identify. I'm trying very hard to not have to reinstall my OS b/c I'd have to reinstall several disability programs. I'm at a real loss and would appreciate any help. As well, I purchased a used text and couldn't get on a support site (the book offers). A medical prof'l sent a page with an unsuccessful link to use - I've since learned it may have been a keygen(?). If it's also on the system, i'd very much like that off also. Thank you for any help. Attached are logs one of the majorgeeks pages requested (and run w uac, mbam, and kaspersky turned off) - the tdskiller log is 411kb and was the 375kb allowed and though I've run MGtools, I can't find the MGlogs zip file anywhere (Is there a different name for the file?). Thank for your patience and for any help.
     

    Attached Files:

    Last edited: May 2, 2015
  2. knowsilence

    knowsilence Private E-2

    Malware (trojan?) - Appreciate Any Help

    Found the MGlogs.zip file. Thanks so much!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest you post in the software forum and answer these questions:

    Please explain what operations are slow! For example answer the below:

    * Is boot up slow?
    * Is shutdown slow?
    * Is browsing/surfing slow?
    * Is downloading slow?
    * Is running any application?
    * Is it also slow in safe boot mode?
    * Also are any process showing in Task Manager to be using a lot of CPU time?
    * Anything else slow?

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  4. knowsilence

    knowsilence Private E-2

    Thank you so much for the quick reply. All of you are amazing! Will Follow your initial instructions and post answers to questions you asked in the software forum. Thanks again TimW!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.....good luck. ;)
     
  6. knowsilence

    knowsilence Private E-2

    Thank you - your kindness means a lot. I'm following the procedure you suggested but have one ques/concern: My attempt to not trouble all of you may have been a mistake. Superantispyware was loaded when I last ran the antimalware scans I attached-malware (trojan, reimage repair) was initially found several days ago (but I hadn't realized the UAC and malwarebytes weren't disabled when the scans ran, so I attached the latest files from 1 May). Also, if I was on the internet this past few weeks, I would try to use CCleaner after. I also added NoScript as a partial blocker for Mozilla, Chrome. Oy. I've uninstalled Superantispyware and followed your list - Pls let me know if I need to rerun scans. Internet connection, Opening antimalware programs -and for some time, even Outlook- remain slow. Still head to the software forum? Thanks again TimW - I usually watch from afar but all of you are SO appreciated!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need'nt rerun scans. The only thing found was Ask.com in the Hitman list which you can remove.
     
    Last edited: May 2, 2015
  8. knowsilence

    knowsilence Private E-2

    Dear TimW,

    The irony: I ran Hitman again. It picked up doubleclick (so I deleted). I hadn't deleted Ask.com b/f, unclear if it was malware...maybe it was automatically deleted. Thank you again. Some days it's SO appreciated when people are kind - I really needed a kindness today. Thanks to all of you for being part of the solution to help the world be a better place. Best,
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. ;)
     
  10. knowsilence

    knowsilence Private E-2

    Revisit - Malware? Appreciate Any Help

    Hi,

    1. I ran scans again bc the Software forum suggested there may be a deeper malware problem. After running the attached scans in safe mode (w UAC and antivirus off), and a complete shutdown/reboot to normal mode at the end, the system is back to indicating "limited access" that required manual disconnection/reconnection, then troubleshoot. It eventually connects but keeps the wireless bars flagged as disconnected for some time. As well, Kaspersky antivirus is back to taking time to load. (Both the internet connection problem and program loading problems were resolved after running Tweaking.com All In One).

    2. While running MGtools (system was connected online), the window that repeated had to be closed stated this: CWindow\System32\cmd.exeSYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers. Virtual device drivers formatting the registry is invalid.

    The cmd window had this text when that happened: SteelWerx App has stopped working – “The process cannot access the file because it is being used by another process.” The same problem appeared during Checking.com files

    3. Again, the tdskiller log is 405kb and will not upload.

    4. Am I missing files or is there a deeper malware problem?

    5. Tweaking.com All In One became corrupted (from Kaspersky antivirus) and will now not open nor uninstall. Software support said I can reload the program over the initial one. I can try to do that in case you want me to run it again, or, so it can be uninstalled.

    6. Will await thoughts on any next steps.

    Thanks so much for any help-this problem is definitely turning my gut upside down. I'm so grateful for your efforts and patience. :confused
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not having malware problems. Your logs are clean. Go back to your software thread. :)
     
  12. knowsilence

    knowsilence Private E-2

    TimW, I know there wasn't much to laugh about but thanks for the giggle. My gut is twisted over this but I'm glad it's not malware. Heading back to Software forum. Appreciate your kindness! :wave
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds