Can you check logs please?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by eltpaqj, Dec 31, 2014.

  1. eltpaqj

    eltpaqj Private E-2

    Hi,
    I went through all the steps but stupidly, I find only these 3 files.
    Can you please check?

    I just found:
    1. the next day I followed all the steps in the malware guide, some vague icons appeared on my desktop screen (17 icons, today. I right clicked some of those and found that says: attributes - hidden)
    2. yesterday, my computer just stopped once, none of the keyboard buttons and mouse worked so I had to press the reset button physically. Then just got back to normal.

    One day before I followed the steps, I upgraded my antivirus: Avast free to Avast Premier trial. (And currently both of the Avast firewall and windows one are on. I read the note that I should not run more than 1 firewall but Avast support says both work different, that's OK. I'm confused... Do you think I should turn off one of them?)

    Your help will be very much appreciated. Thank you:)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need the logs from running RogueKiller and Hitman.
     
  3. eltpaqj

    eltpaqj Private E-2

    Hi,
    I've just found the rest files. I am really sorry for the late attachments!:cry

    I hope I did it correctly. Thank you very much in advance, and happy new year!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to uninstall one of these>
    Kaspersky Security Scan
    Avast Premier

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry : 22 ¤¤¤
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> Found
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> Found
    
    Now rerun Hitman and remove the items under:
    Potential Unwanted Programs
    
    Download [B][SIZE=3][URL="http://oldtimer.geekstogo.com/OTM.exe"][COLOR=blue]OTM [/COLOR][/URL][/SIZE][/B]by [B]Old Timer[/B] and save it to your Desktop.
     
    [LIST] 
    [*]Right-click OTM.exe And select " Run as administrator " to run it.
    [*]Paste the following code under the [IMG]http://farm3.static.flickr.com/2455/4173556815_a721a91733_o.png[/IMG] area. Do not include the word Code.
    [/LIST]
    
    [code]
    :Processes
    explorer.exe
      
    :files
    C:\Windows\SysWOW64\28caa510.0
    C:\Windows\SysWOW64\562174c6.0
    C:\Windows\SysWOW64\90307e75.0
    C:\Windows\TEMP\*.*
    C:\Users\RhRh\AppData\Local\Temp\*.*
     C:\Windows\system32\tasks\{1F6E3A22-210C-4D12-8DD0-3B9EA4013AC4}
    C:\Windows\system32\tasks\{45F1C1D7-7B61-4047-8A08-50347EA7273F}
    C:\Windows\system32\tasks\{5E65361D-04B4-47B9-B132-A956DF22CC18}
    C:\Windows\system32\tasks\{62CA01F7-E425-4F6A-A100-351F0DDBB2CA}
    C:\Windows\system32\tasks\{778BAA95-51D3-4037-9669-0EF5930E0787}
    C:\Windows\system32\tasks\{8FF09D08-53C9-4BF1-B49A-C1D5939ABE8D}
    C:\Windows\system32\tasks\{97FA0A83-D445-434A-9197-0D1C12248EC7}
    C:\Windows\system32\tasks\{C41E6BCB-F70D-4B4B-850F-955129DB52A1}
    C:\Windows\system32\tasks\{CFEE5AB3-D4CF-4995-9F0A-14A00E2D92C2}
    C:\Windows\system32\tasks\{ED577D3E-3448-472B-94A1-06FF2440F924}
    C:\Windows\system32\tasks\{F46C239F-FE09-4056-92A9-1ADFD166AA79}
      
     :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.



    Reboot and rescan with both RogueKiller and Hitman and attach the new logs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip

    Be sure to tell me how things are running.
     
    Last edited by a moderator: Dec 31, 2014
  5. eltpaqj

    eltpaqj Private E-2

    I've stopped here:

    Rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry : 22 ¤¤¤
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> Found
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> Found
    
    
    [B]I couldn't find: [code]¤¤¤ Registry : 22 ¤¤¤[/B]
    
    Please find attached the screenshot image file. 
    
    I'm just assuming the first and the second items under the Registry tab are the other 2 you meant.
    
    Kindly let me know so that I can go further. Thank you!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry, yes just the two items listed need to be fixed. If they no longer exist, just ignore the RogueKiller fix and continue
     
  7. eltpaqj

    eltpaqj Private E-2

    RogueKiller says my version is outdated, asks me to download the new version and when I click yes, the company website pops up and 4 versions of download are there (One was named Local and I don't remember the rest, I closed the window.rolleyes).

    Should I download one of them on the website (before clicking the scan button)? If so, which one?
    Or should I download from the READ & RUN ME FIRST Malware Removal Guide again? :cry

    Thank you!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. eltpaqj

    eltpaqj Private E-2

    If I can't find such terms like Potential Unwanted Programs on the HitmanPro scan results here:

    Now rerun Hitman and remove the items under:
    Potential Unwanted Programs

    then, is it that I don't have such items?

    Then can I just close the HitmanPro and continue? (Although I've already closed that...)
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, close the Hitman program and continue with the instructions. Be sure to rescan with Hitman after you are finished and attach the new log as instructed.
     
  11. eltpaqj

    eltpaqj Private E-2

    I'm a bit panicked as I got a blue screen(?)...

    In the OTM step, when I pushed the large Moveit! button, suddenly computer screen shut down and got to a blue screen, in which that says it's a stop error screen(?) and I can restart or go to a safe mode. So I pressed the start button (the power button) on my computer (as I don't know which one that meant by restart - start button or reset button). And pressed that once again to start computer, some comment was shown, and then windows started automatically after some seconds passed.

    I don't know what I have to do...

    Thank you!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and Hitman and attach the new logs.
     
  13. eltpaqj

    eltpaqj Private E-2

    Hi,
    Please find attached the logs.

    Thank you!
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and fix the items under> Potentially unwanted programs.

    Reboot and rescan with Hitman and attach the new log.

    Be sure to tell me how things are running.
     
  15. eltpaqj

    eltpaqj Private E-2

    1. So, I have to delete the items listed in the log (not in the program window), am I right?

    2. Before deleting the items there, can I delete/uninstall the entire Babylon program? Actually, I don't use the program...
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not sure if I understand your first question. As to the second, yes, you can uninstall it, but still do the fix.
     
  17. eltpaqj

    eltpaqj Private E-2

    Sorry, edited.

    1. So, I have to find the heading 'Potentially unwanted programs' in the log (not in the program window) so I have to look in the log, am I right?

    2. Before deleting the items there, can I delete/uninstall the entire Babylon program? Actually, I don't use the program...
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Program Files (x86)\Babylon
    C:\Program Files\Babylon
    
    :reg
    [-HKLM\SOFTWARE\Classes\Interface\{0BF91075-F457-4A8B-99EF-140B52D2F22A}]
    [-HKLM\SOFTWARE\Classes\Interface\{37425600-CB21-49A0-8659-476FBAB0F8E8}]
    [-HKLM\SOFTWARE\Classes\Interface\{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7}]
    [-HKLM\SOFTWARE\Classes\Interface\{5C9A230D-70A5-11D5-AFB0-0050DAC67890}]
    [-HKLM\SOFTWARE\Classes\Interface\{5F339F0B-716F-408F-A627-DEEB5DEB4020}]
    [-HKLM\SOFTWARE\Classes\Interface\{8911483C-C00A-4183-9FBC-6C9C00946C15}]
    [-HKLM\SOFTWARE\Classes\Interface\{95734BDE-B702-45B9-86E5-27676729F904}]
    [-HKLM\SOFTWARE\Classes\Interface\{B7EA2226-F876-4BE4-B478-76EBAE2A668A}]
    [-HKLM\SOFTWARE\Classes\Interface\{C3F058A9-407D-4CD1-8F66-B75605B54B69}]
    [-HKLM\SOFTWARE\Classes\Interface\{D0482C8E-BAEA-4943-911A-B661060F56A7}]
    [-HKLM\SOFTWARE\Classes\Interface\{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2}]
    [-HKLM\SOFTWARE\Classes\Prod.cap]
    [-HKLM\SOFTWARE\Classes\s]
    [-HKLM\SOFTWARE\Wow6432Node\Conduit]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASMANCS]
    [-HKU\S-1-5-21-641681502-1150777803-1933340716-1000\Software\Microsoft\Internet Explorer\LowRegistry\Extensions\CmdMapping\{F72841F0-4EF1-4df5-BCE5-BAC8ACF5478}]
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Reboot and rescan with Hitman. Attach that new log along with the OTM log.
     
  19. eltpaqj

    eltpaqj Private E-2

    -The logs are attached.

    - "OTM may ask to reboot the machine. Please do so if asked.
    Copy everything in the Results window (under the green bar), and paste it in your next reply." -- I failed to copy those. Just pressed the reboot button without doing that. Sorry!

    Thank you.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The items are gone from Hitman. What issues remain, if any?
     
  21. eltpaqj

    eltpaqj Private E-2

    I don't know but it looks good, and feels good :)

    But the vague 17 (hidden) icons are still shown there, which appeared the next day I followed the malware removal guide. Maybe those will be gone after the final step?

    Thank you!
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  23. eltpaqj

    eltpaqj Private E-2

    I'll do all those, thank you very much for your help!

    Have a very nice day and thank you again.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds