Strange happenings on my laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by armansrsa, Mar 15, 2014.

  1. armansrsa

    armansrsa Private E-2

    Hi!

    My laptop has been acting funny. My audio keeps cutting out and sometimes windows doesn-t start properly. I am not 100% sure it is malware related but I had to do the scans and post my logs here to be sure and eliminate the possibilites. I have done the preliminary cleaning process your website suggested so was wondering if anyone could help remove any malware I may have.

    NB Malwarebytes and TDSkiller never found anything so I have not attached a log for it

    thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Potential Unwanted Programs



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix exit HJT.


    Do you know what these are?
    • C:\Users\Ana\AppData\Roaming\.744FBAB82B7C2F13.sys
    • C:\Users\Ana\AppData\Roaming\.744FBAB85B92486B.sys



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Explain how things are running and don't forget to answer my question. :)
     
  3. armansrsa

    armansrsa Private E-2

    Thanks for the reply. I tried running hit man pro but I would need a license to remove the threats and I am not interested in purchasing any software at this stage. Can I go straight to the MGtools removal section of your post?

    Also, I have no idea what those two sys files. Do you have any idea? How can I found out about them?

    thanks again!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, you can replace the Hitman step with this:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Re scan with Hitman after following all of my instructions at the end, so we can see if my fix worked or not. Attach the log for me to see.
     
  5. armansrsa

    armansrsa Private E-2

    I followed instructions precisely and windows informed me that the .reg file was succesful.

    I then did a scan of Hitman pro but the two threats that were there previouly still came up

    see report please
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How comfortable are you going into the Windows Registry yourself and deleting those keys?
     
  7. armansrsa

    armansrsa Private E-2

    I deleted this one but I couldn't delete the other one

    [-HKU\S-1-5-21-2892177953-1229624924-2553007428-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
     
    Last edited: Mar 17, 2014
  8. armansrsa

    armansrsa Private E-2

    I deleted this one but I couldn't delete the other one as it wouldn't let me

    [-HKU\S-1-5-21-2892177953-1229624924-2553007428-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]


    How do I get rid of this one?


    [-HKU\S-1-5-21-2892177953-1229624924-2553007428-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download Combofix to your desktop. Please refer to these instructions prior to running. I do NOT want you to just double click it to run it, I have a script for you to run...



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Users\Ana\AppData\Roaming\.744FBAB82B7C2F13.sys
    C:\Users\Ana\AppData\Roaming\.744FBAB85B92486B.sys
    
    Registry::
    [-HKU\S-1-5-21-2892177953-1229624924-2553007428-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now re run Hitman once more and attach the log.
     
  10. armansrsa

    armansrsa Private E-2

    While running combo fix, I received the following error message. I did not click to close the window or anything as combofix was still running in the background.

    After combofix finished, I closed the error message and I ran Hitman Pro again. Still one threat is coming up.

    Both reports attached
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have a locked registry key that we need to deal with, and the utmost care and attention needs to be applied whilst we do this. You need to follow instructions exactly as they are written and make sure that you have completed each step precisely.

    Now download and install Registrar Lite


    Open up the program and navigate to the following key. (See key in bold further below) Actually click on they key so that it is highlighted in pale blue. Click on the "Edit" menu and from there choose "Properties" Click on "Take Ownership" and then click on "Permissions" and ensure that "Full control" is check marked if it is not already. Click Apply and click OK.

    So remember the two parts to complete for this key, the ownership and the permissions. Just take your time.

    Key we need to work on.

    • HKU\S-1-5-21-2892177953-1229624924-2553007428-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}

    Reboot the machine and navigate back to the key. On the permissions is full control still check-marked?
     
  12. armansrsa

    armansrsa Private E-2

    I navigated to "take ownership" - which is under security, not properties by the way - and I got a pop up saying:

    Ana has successfully taken ownership of the key

    Then I opened up "Permissions" and see 4 different users

    1) Restricted
    2) System
    3) Ana (Ana-PC\Ana)
    4) Administrators (Ana-PC\Administrators)

    Firstly, I don't understand why there are 4 users as my wife is the only user on the computer.

    If I click on the 3rd user and 4th user they both have "read" and "full control" checked as "allow". Neither of them however, have "special permissions" selected as "allow" and the boxes are greyed out so even if I wanted to grant those users "special permissions", I couldn't. I also notice that on the 3rd user the "special permissions" is selected as "deny" and I can't uncheck or change that. Could this be the problem?

    Furthermore, after taking ownership as you said, I tried to then delete the same registry key manually and windows gave me an error message saying "ACCESS DENIED"

    How do we proceed?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I will have to have a word with Chaslang. Hang in there. In the mean time, please try this:

    Please download AdwCleaner by Xplode http://www.bleepingcomputer.com/download/adwcleaner/ and save to your Desktop.

    Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator
    Click on the Scan button.
    AdwCleaner will begin...be patient as the scan may take some time to complete.
    After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    Attach the logfile to your next next reply.
    A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  14. armansrsa

    armansrsa Private E-2

    Who is chaslang?

    Log attached. It is in Spanish as I have a Spanish windows installed but I am sure you can make sense of what is what :)
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Chaslang is the head of the Malware Removal section here at Majorgeeks. He is the author of the Read and Run Me First Malware Removal procedures.

    Apart from this, describe how things are running for me. :)
     
  16. armansrsa

    armansrsa Private E-2

    I haven't really used that computer this week so can't say but I get the feeling that the item we cannot remove from the registry key is the one that is corrupting my sound device because now when I try delete it it says: ACCESS DENIED, your sound device is not working properly

    Any ideas on how we can remove it? What is the protocol regarding items that you cannot remove from the registry? What about trying in safe mode?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do not believe at all that the sound issue is related to the nuisance reg key that is being stubborn about being deleted.

    I am seeking Chaslang's advice, however, you can indeed try to delete the key in safe mode, but I have tried this in the past and it does not work.
     
  18. armansrsa

    armansrsa Private E-2

    I probably wasn't supposed to but it seemed like the folder with those files inside were not of any use to me so I deleted the whole folder with all those 5 registry keys and it let me, I then did a scan and the threat is gone. Did I break something in my computer by deleting those other reg keys in the same folder.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I asked you to run a tool called Junk Removal Tool a few posts back, did you manage to do so? If so attach the log please. There's a chance it could try and remove the key. (Edit, cross posted... user has deleted key)
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm... I do not know what other keys you deleted. Yes you should have backed up the registry first before doing this, but let's not panic. Reboot the machine, and then let me know if you have any issues starting back up or not. (You may have already rebooted since deleting the folder of keys)
     
  21. armansrsa

    armansrsa Private E-2

    I was able to reboot ok after deleting that folder. I had done a JRT scan, here is the log attached

    My computer seems ok for now but how can I check to be sure?
     

    Attached Files:

    • JRT.txt
      File size:
      623 bytes
      Views:
      2
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well we know Hitman no longer finds the rogue reg key....
    Does your sound issue still remain? (If so, this is not topic for this forum) and I already cleaned up any other junk I found.
    Also JRT found nothing. :)
     
  23. armansrsa

    armansrsa Private E-2

    let me use it for a couple days to be sure and if you don't hear back then all is good. thanks for all your help, I really appreciate it.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. I'll be here. ;)
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How is it going? :)

    Oh, by the way I wanted to point this out to you.

    You said:
    You did not follow my instructions. I said Edit, then Properties, then Take Ownership. You simply started looking for Take Ownership which is under the Security pull down. Had you followed my instructions properly, you also would have found it. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds