malware on my pc

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tadhgb, Dec 5, 2014.

  1. tadhgb

    tadhgb Private E-2

    Hi
    I downloaded a pesky malware when converting a youtube video to an mp3 (it was a lecture and not music). Anyway I've had various pops and interference when browsing.
    I've run the programmes and have the logs below.

    Thanks in advance for any help.

    Update: I couldn't upload the Unkeytxt as it says it is over the file size limit.
     

    Attached Files:

    Last edited: Dec 5, 2014
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should not be trying to attach individul log files from within the zipped file. We need the complete MGlogs.zip please. It contains MANY text files... thanks. :)
     
  3. tadhgb

    tadhgb Private E-2

    This is the zip files

    More to follow

    Thanks
     

    Attached Files:

  4. tadhgb

    tadhgb Private E-2

    And more files
     

    Attached Files:

  5. tadhgb

    tadhgb Private E-2

    and again
     

    Attached Files:

  6. tadhgb

    tadhgb Private E-2

    ......

    There are two files that it says are too large to upload.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I repeat!!!!! You are making extra work for yourself. I want the WHOLE MGlogs.zip. That is ONE zipped/compressed file please. I don't want ANY text files.
     
  8. tadhgb

    tadhgb Private E-2

    Apologies

    Here you go
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem...

    Re run Hitman Pro and have it remove all that it finds.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :files
    C:\ProgramData\10036731443646498920
    C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
    C:\ProgramData\nlmmondhgbcbhfbglonlgakibllmlpfj
    C:\ProgramData\Reimage Protector
    C:\ProgramData\SparkTrust
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
    C:\Program Files (x86)\DeltaFix
    C:\Windows\system32\tasks\Reimage Reminder
    C:\Windows\system32\tasks\ReimageUpdater
    C:\Windows\system32\tasks\{4774B93F-620C-450E-9AA2-DA441676A3E5}
    
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    • Re scan with Hitman again and attach new log too.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  10. tadhgb

    tadhgb Private E-2

    I haven't been able to have hitman pro delete anything as it asks for an activation code and money.
     
  11. tadhgb

    tadhgb Private E-2

    I ran all the tools (although I don't have an activation code for hitmanpro), Here are the logs.

    Thanks
     

    Attached Files:

  12. tadhgb

    tadhgb Private E-2

    NOt sure if one of these is the right OMT log
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\Users\Backup\bre\AppData\Local\Temp\2A04FCf9.exe
    C:\Users\Backup\bre\AppData\Local\Temp\4D8C64b7D7ca.exe
    C:\Users\Backup\bre\AppData\Local\Temp\7e23.exe
    C:\Users\Backup\bre\AppData\Local\Temp\A991E92b.exe
    C:\Users\Backup\bre\AppData\Local\Temp\dCea3f035a3B.exe
    C:\Program Files\Reimage
    C:\Windows\system32\Tasks\ReimageUpdater
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair\Reimage Repair.lnk
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair\Run in safe mode.lnk
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair\Change Reimage Repair Language.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\$Recycle.Bin\S-1-5-21-873813481-2511831922-1214619308-21063\$R2ZEGN1.lnk
    C:\Program Files\Reimage\Reimage Repair\Reimage Repair.url
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair\Website.lnk
    C:\Program Files\Reimage\Reimage Repair\uninst.exe
    C:\rei
    C:\rei\reimage.qsr 
    C:\rei\Results\EXE1.8.0.1
    C:\rei\SupportInfoTool.ini 
    C:\rei\Temp\20141205_2301
    C:\Windows\Reimage.ini 
    C:\Windows\System32\Tasks\Reimage Reminder (ReimageRepair)
    
    :reg
    [-HKLM\SYSTEM\CurrentControlSet\Services\ReimageRealTimeProtector]
    [-HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL]
    [-HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}]
    [-HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}]
    [-HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}]
    [-HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}]
    [-HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}]
    [-HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1]
    [-HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine]
    [-HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\AppID\REI_AxControl.DLL]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}]
    [-HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Reimage Reminder]
    [-HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ReimageUpdater]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Reimage.exe]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair]
    [-HKLM\SOFTWARE\Reimage]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Reimage.exe]
    [-HKLM\SOFTWARE\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}]
    [-HKLM\SYSTEM\ControlSet001\services\ReimageRealTimeProtector]
    [-HKLM\SYSTEM\ControlSet002\services\ReimageRealTimeProtector]
    [-HKLM\SYSTEM\CurrentControlSet\services\ReimageRealTimeProtector]
    [-HKU\S-1-5-21-873813481-2511831922-1214619308-21063\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}]
    [-HKU\S-1-5-21-873813481-2511831922-1214619308-21063\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.]
    [-HKU\S-1-5-21-873813481-2511831922-1214619308-21063\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}]
    [-HKU\S-1-5-21-873813481-2511831922-1214619308-21063\Software\Reimage]
    [-HKU\S-1-5-21-873813481-2511831922-1214619308-21063_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}]
    [-HKU\S-1-5-21-873813481-2511831922-1214619308-21063_Classes\Wow6432Node\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}]
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now ensure a reboot has been made, rerun Hitman Pro again and attach NEW log.
     
  14. tadhgb

    tadhgb Private E-2

    Here you go
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you confident in the Windows Registry? :confused Do you feel comfortable manually deleting some keys or not?
     
  16. tadhgb

    tadhgb Private E-2

    No problem
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nice.

    Delete these:

    • HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
    • HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
    • HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
    • HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
    • HKU\S-1-5-21-873813481-2511831922-1214619308-21063\Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
    • HKU\S-1-5-21-873813481-2511831922-1214619308-21063_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}


    Once done re run Hitman Pro again, let's see if anything remains. Attach log.
     
  18. tadhgb

    tadhgb Private E-2

    Ran the programme - it says no threats were found.

    Many thank:)
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. Are things running nicely? Ready for final steps? :)
     
  20. tadhgb

    tadhgb Private E-2

    Yes all good
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  22. tadhgb

    tadhgb Private E-2

    All done - thanks for your great help:)
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds