All because my Games vanished!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DaveRM, Mar 23, 2015.

  1. DaveRM

    DaveRM Private First Class

    I started a thread following some 'funnies' on my computer (This thread http://forums.majorgeeks.com/showthread.php?p=1908834#post1908834)

    My computer was running desperately slowly this morning. Truly, 5 minutes or more to open a page, or get en email. I timed it by the clock! Yet the 'disc activity' light wasn't flicking at all - I presume it was all within memory.

    I've followed the intructions to get started as best I can.

    I hope this makes sense! I've made brief notes, but had to be away ffrom the computer for half the day, in the middle.

    I started Rogue Killer. I thought it had hung, it was unmoving for what seemed a very long time, so I started Malwarebytes.

    Then RK kicked into life again, so for a while, both ran together. I hope this doesn't invalidate what I've done, but if necessary, I'll have to redo it all, I guess!

    Ran TDSKiller. Seems OK. No threats found.

    Ran Hitman Pro. No threats reported - I can't locate a log for it (there was no option to save one).

    Ran MGtools. It reported SteelWerx stopped. A message about Trend Micro HijackThis came up - so I accepted.

    Message re System Info refreshed.

    Logs attached.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I still need the log from Hitman and MGlogs.zip from you running MGTools.exe please.
     
  3. DaveRM

    DaveRM Private First Class

    Thanks, Kestrel. The logs are attached. (The problem with the Hitman log is that the 'button' to press to output a log is pretty inconspicuous. Maybe a note in the instructions, telling where to find it?)

    (I also had a comment from Eldon (Staff Sgt) 'Also check if the game files are still there. Got to C:\Program Files\Microsoft Games.'.

    I have checked hese - the files are there.I guess I might be able to activate the .exe from there, but I won't mess around trying, in case!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing anything to do hardly...



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:



    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Explain how things are running.
     
  5. DaveRM

    DaveRM Private First Class

    Thanks, Kestrel.

    RogueKiller started (seemed slow to start). Got on to 'Checking hidden processes...'), the progress bar under the Scan button on 60% - hung like that with no visible sign of movement for ages. Since I had a similar experience during the initial 'cleaning' run, when RK 'came back to life' after a long while, I waited. I assume I am suposed to wait until the checking of Processes, Registry, Tasks - etc has finished, before tackling the Registry?

    ..............

    Well, RK has been running well over half-hour, and almost all that time, stationary on 'Checking Processes ... 60%', so I'm going to kill it, and start again, assuming it's got stuck, somehow.

    Ironically, it says 'Closing, please wait'. As if I haven't done enough waiting already!!

    Beginning to look as though I won't be able to do this tonight - closing down is taking ages, too.

    (For something to do, I started Task Manager to see what was running. 'AcroRd32.exe *32' {Adobe Reader} is taking 48% or 49% of CPU time. I'm not aware of anything that should be running, using Abobe Reader, so I'm going to End Process it.)

    Rogue Killer is now fairly well up towards the top of the list - roughly varying between 2nd and about 10th place. RK itself still not closed, though.

    I shall have to leave the computer soon. Normally, I run a scheduled scan (AVG Anti-Virus) at night, after I've gone to bed, with an automatic shutdown when finished. I've just turned off the auto-shutdown, so it can take all night, if it needs - I'll resume trying in the morning. That's the entire evening spent on this. But I'll get to the bottom o it, (with much valued help!) if I can.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If RogueKiller wont run answer this: Can your home page in Internet Explorer be changed by you? It's set as Conduit at the moment, that's what I was trying to be rid of using RK...
     
  7. DaveRM

    DaveRM Private First Class

    Back at my computer after about 15 hours. I find that AVG did its usual scan, and found nothing amiss. RogueKiller has finished at some time overnight. I can't find any trace of any report from it.

    My home page on Internet Explorer (which I almost never use, BTW) was set to Google. I changed it to 'talktalk.co.uk' (my ISP's home page). It set itself back to Google.

    (I was dreading doing anything with the Registry - I've always steered well clear of touching it. When I first got a PC I was given dire warnings about the dangers of screwing up in this area.)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I wouldn't worry then. Ready for final steps? :)
     
  9. DaveRM

    DaveRM Private First Class

    Yes, sure. Need to mention a couple of things, first.

    I was looking at a folder with a number of scans (of 35mm transparencies) earlier today, when I got a sudden Blue Screen crash. It gave some details which I'll attach as an RTF file. It may be relevant.

    After the crash, I restarted in Safe Mode (It came up with the black-and-white screen) and ran a full AVG scan in SM. It said there was a report - AVGREP.TXT but I can't find it. (The 'Search Programs and Files' on the Start menu hardly ever finds anything for me - except occasionally a program.) So far as I know, SVG didn't find anything, but I can't be sure.

    With that, over to you, please. What now?
     

    Attached Files:

    • BSOD.txt
      File size:
      723 bytes
      Views:
      2
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not topic for the malware forum I'm afraid, you can ask about BSOD's in the software forum. :)
     
  11. DaveRM

    DaveRM Private First Class

    I'm sorry, I wasn't expecting you to branch off on another tack.

    Long ago (in the 60's!) I used to work on office computers (vastly simpler than todays machines) and latterly used to troubleshoot 'sick' installations. I know how significant, sometimes, apparently irrelevant observations can be. I mentioned the BSOD thing in case it threw any light on the main problem.

    So, I still have something - Conduit (? anything else) - on my computer that it would be good to deal with.

    If you're still happy to help me, I'd be grateful.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The BSOD is not to do with malware. I'm not seeing ANY malware on this machine.
    Not really malware, minor junk, but you did not answer my question: Can you change your home page in IE? :)
     
  13. DaveRM

    DaveRM Private First Class

    Sorry, I thought I had covered that, a couple of posts back :-

    I've tried IE again. No matter what I do, the Home Page always reverts to Google, as soon as I come back to it.

    So, I can change it, but the change won't stick. I hope that answers the question.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That would be best off asked about in the software forum too. I'm not seeing any malware at all. :)



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds