Problems with Windows 7 System 64 bit.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wjriv, Aug 29, 2014.

  1. wjriv

    wjriv Private E-2

    I started having issues with my computer and noticed that my Windows Update has stopped working and now gives me errors and fails to install correctly. Also I have noticed that the Windows Explorer keeps crashing and other services seem to not work.. So I expected that I had a virus of some sort. My computer is protected by Trend Micro Titanium Internet and I do run other scans at least once a month.. I use Malwarebytes Anti-Malware on a regular basis along with SUPERAntiSpyware Free Edition.. I also ran a few Trend Mirco Tools like Hijack This and RootkitBuster. All of my those scans came back clean.. I also tried to do a system restore back to an earlier date when I noticed this but it seems not to go back that far.. I am not sure if I have been hacked at all but things have not been running the way they should lately.
    I went ahead and followed all of the steps to get the logs for the procedure that you posted under Read & Run First.. I am enclosing the logs in this post.

    If I can not get this solved I will have to re-image my computer and start all over.. (I have been backing things up so I should be covered, but it is just a pain to re-install everything again..)

    Thanks

    John
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it fix all that it finds.

    MGTools did not run to completion. You need to run it again this time ensuring that you disable protection software, that UAC is disabled and that you did indeed run it as admin.

    Once done attach the fresh MGlogs.zip please.
     
  3. wjriv

    wjriv Private E-2

    I ran the 2 scans.. Here is the MG Tools Log again.. Thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\ProgramData\hsqvmxbo.uxh
    C:\Program Files (x86)\globalUpdate
    C:\Program Files (x86)\Common Files\Spigot
    
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. wjriv

    wjriv Private E-2

    Ok I ran the scans and have attached the logs..

    When I ran OTM. The program never restarted the computer and when I tried to Exit the program the button and the X in the corner would not close the program. I had to use Task Manager to exit it.. Before I quit the program I was able to copy the text into a notepad file.. I restarted the computer and followed your instructions again just to see if it would restart and close but still had to use Task Manager. After running all of the scans and I restarted the computer.. It seems to run much faster but I am still having Windows Explorer Crashes when I do certain things. For Example if I open Computer then click on the Security link.. It will crash..

    Let me know if you find anything in the logs..

    Thanks
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, not seeing anything else to remove. I suggest that you post in the software forum if necessary regarding any outstanding non malware issues. :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  7. wjriv

    wjriv Private E-2

    After I posted my last reply and attached the logs I decided to take a look at the Event Viewer to see if I could get any specific errors for why Windows Explorer would keep crashing and restarting.. I got this error: Unable to open eventvwr.exe-"MMC cannot open the file C:/windows/system32/eventvwr.msc

    So I ran a sfc scan and found that a bunch of things were missing or corrupt.
    Msxml.dll (Missing or Corrupt)
    Msxml2.dll (Missing or Corrupt)
    Msxml3.dll (I think this one was ok)

    I have attached the log for the full scan to this post

    So my question now is which forum should I present this problem to?

    I will run the final step for malware unless you instruct me to hold off for now.

    Thanks again..
     

    Attached Files:

    • CBS.zip
      File size:
      85.4 KB
      Views:
      3
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Software forum, yes. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds