infected whilst setting up new laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jan Scrivens, Dec 28, 2014.

  1. Jan Scrivens

    Jan Scrivens Private First Class

    Hello, I am setting up a new laptop so am installing quite a few 'things'. I think despite my best efforts that the system has been infected. Can you help me please?
    Laptop is Lenovo Flex 2-14 running Windows 8.1 Intel Pentium 3558U @ 1.70GHz
    RAM 4.00GB 64-bit X 64 based processor.
    The problem started about a week ago (I think it was after installing Adobe reader) and I have run various scans, found some issues, but have been unable to clean it.
    I ran a SpyHunter scan but at the end it cleaned nothing unless I bought it. As I have already paid for other programmes, I'd prefer not to have to buy even more. I have attached photo's of the main items it found.
    I also ran MBAM and TDSKiller scans and have attached copies of them.
    The current situation is that it is essentially working OK but with Gremlins. Things need multiple clicks before responding etc.
    I am unable to do a system restore (tried a few different points)and last night it wouldn't turn off normally, so I had to do an 'power button' turn off.
    I am getting 'ad choices' pop-ups when I hover over links such as any of the green links on the majorgeeks pages.
    My Avast programme has identified and tried to remove potentially damaging browser addons, but 'an unknown error occurred', and it was unable to remove them.
    As I had already run some scans and done repairs I have attached them too so that you know what has happened.
    Thanks, Jan
     

    Attached Files:

  2. Jan Scrivens

    Jan Scrivens Private First Class

    here are more attchments
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :) I am reviewing those logs and will get back to you asap.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That attachment is upside down, I can't read that.
    Normal unless you use an adblocker and configure it to stop seeing them. ;)

    What is this?
    C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
     
  5. Jan Scrivens

    Jan Scrivens Private First Class

    Thanks, will look at pop up blocker.

    Which attachment was upside down please. I will try to re-attach.

    No idea how that programme data file got there.

    Jan
     
  6. Jan Scrivens

    Jan Scrivens Private First Class

    think this was the upside down one? hope it's OK this time
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is that a Spyhunter log? (Attachment)

    Delete this:
    C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}

    Let me know how things are going with that gone and a pop up blocker installed.
     
  8. Jan Scrivens

    Jan Scrivens Private First Class

    Yes, I had run spyhunter and it found lots, including these things. I then realised that it was not freeware so couldn't clear them with it and hoped to find a free alternative. I have tried to remove Vosteran but don't know if I've managed totally or not.
    I have removed that file.
    I have added a pop up blocker to chrome. I understand that your green links led to pop ups but the ones I WAS getting seemed inappropriate to the link. Seems better now.
    When I turned the machine on this morning, after logging in as usual, it didn't open but there was this message -
    "the group policy client failed the sign in"
    "the universal unique identifier type is not supported"
    I clicked OK and it seems to have opened correctly.
    Thanks, Jan
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for your update. :)

    That's topic for the malware forum. Are you satisfied we have cleaned all we can here in the malware forum, or is anything else occuring?
     
  10. Jan Scrivens

    Jan Scrivens Private First Class

    Thanks, sorry took so long to reply.
    I thought this WAS the Malware Forum? so a bit confused by your comment?
    Anyway, the laptop seems to be mainly running OK now. Thanks very much for your help.
    Are there any things I need to do to finalise things please?
    Thanks, Jan
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Kes meant it was a topic for the software forum. ;)
     
  12. Jan Scrivens

    Jan Scrivens Private First Class

    Ah I see. I'm easily confused !
    Just waiting to find out what I need to do to finalise things now.
    Thanks Tim
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes I meant the software forum. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  14. Jan Scrivens

    Jan Scrivens Private First Class

    Thanks,
    I could not find the Hijack this file.
    I also cannot find the MGclean.bat file. I've done a search for both and can't find them anywhere.
    What should I do please?
    Jan
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one. Now retry...
     
  16. Jan Scrivens

    Jan Scrivens Private First Class

    I'm sorry but I'm struggling here.
    I've downloaded the updated MGTools as you say. It would not save in C:/ as it said I didn't have enough permission, but saved in my Jan folder.
    When I click on it it opens up a black box and runs. It doesn't open for me to find MGclean.bat file.
    What am I doing wrong please?
    Jan
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then that is where the MGTools folder will be, and inside that is the MGclean.bat file. :)
     
  18. Jan Scrivens

    Jan Scrivens Private First Class

    Yes, I have the mgtools.exe file but it just opens up a cmd window. Where do i find the MGclean.bat file?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I said MGTools folder not file!! :)
     
  20. Jan Scrivens

    Jan Scrivens Private First Class

    Sorry for being so thick.

    All done now.

    Thanks very much.

    Jan
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Absolutely no worries at all! :) You're not thick, it's easily done!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds