Malware Issue on my PC

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kdog123, Dec 26, 2014.

  1. kdog123

    kdog123 Private E-2

    I have attached all logs from each program. Any help is greatly appreciated, thank you.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable your AV software while we do the following:

    Rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry : 11 ¤¤¤
    [PUP] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} -> Found
    [PUP] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1} -> Found
    [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | {b9193468-9006-c53d-ab98-eca49c41c1fc} : "C:\ProgramData\Microsoft\{b9193468-9006-c53d-ab98-eca49c41c1fc}\{b9193468-9006-c53d-ab98-eca49c41c1fc}.exe"  -> Found
    [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | {b9193468-9006-c53d-ab98-eca49c41c1fc} : "C:\ProgramData\Microsoft\{b9193468-9006-c53d-ab98-eca49c41c1fc}\{b9193468-9006-c53d-ab98-eca49c41c1fc}.exe"  -> Found
    [Tr.Poweliks] HKEY_USERS\S-1-5-21-2806417876-903906380-1203977365-1000\Software\classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LocalServer32 -> Found
    Now rerun Hitman and have it fix all the items in these categories:
    Malware
    Potentially unwanted programs.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Users\Keith\AppData\Local\Temp\*.*
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Re-enable your AV software.

    Rescan with both RogueKiller and Hitman and attach the new logs.'

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip

    Be sure to tell me how things are running.
     
  3. kdog123

    kdog123 Private E-2

    Thank you for your reply and help. Before I start my bitdefender AV is part of the problem or where I first noticed the problem. I worked with there tech support to try and delete and reinstall the software a number of times, but have been unsuccessful. Any attempt to delete the software currently installed on my computer (uninstall tool they have emailed me, or through the control panel, etc) fails. I am also unable to "disabled" it as well as far as I understand. It loads in my task bar but then greys out with an error and is unresponsive.

    Should I still attempt to follow through with the instructions from your last post or is there another way you may know of on how I may be able to disable my AV?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and follow the instructions. We will attempt to remove BitDefender in our next go around.
     
  5. kdog123

    kdog123 Private E-2

    Computer is running decently okay I would say. I have attached the new logs from the recent scans.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Users\Keith\AppData\Roaming\Bitdefender
    C:\Program Files\Common Files\Bitdefender
    C:\Users\Keith\AppData\Local\Temp\*.*
    C:\Program Files\Bitdefender
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Bitdefender Wallet Agent"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Bdagent"=-
    
    [HKEY_USERS\S-1-5-21-2806417876-903906380-1203977365-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "Bitdefender Wallet Agent"=-
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Tell me how things are running.
     
  7. kdog123

    kdog123 Private E-2

    Attached OTM log. Looks like that finally removed bitdefender from the computer. Should I try and do a fresh reinstall of bitdefender now? Also I have been noticing over the last few days my free space amount on my hard drive keeps going down pretty substaintally. I haven't downloaded, etc. anything in a couple of weeks and I had around 15 gigs of free space about a week ago and now I am down to less than 2 gigs of free space as of today.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post in the software forum for your issue with hard drive usage.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. kdog123

    kdog123 Private E-2

    I still might be having an issue possibly. I ran a CCleaner about 2 hours ago since it said around 12 gigs could be cleaned up and my hard drive space was so low. After it finished running it left me with 17.4 gigs of free space. But in an hour is has dropped back down to 13.4 gigs of free space and I haven't done anything on my computer. A huge amount of that space cleared out is showing as listed from from system-temporary files, (11,779,249 KB as 384,449 files) and I already ran CCleaner right before starting the malware removal process a few days ago. So that leads me to believe I still might be having a malware issue.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Again, an issue for the software forum. But, we can try this:

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  11. kdog123

    kdog123 Private E-2

    Okay sorry about that, I wasn't sure if it was specifically software related or still a malware issue. I have attached the log from the AdwCleaner scan, thank you.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let ADWCleaner clean up what it found.
    Omit these itesms:
    Folder Found : C:\Program Files\NCH Software
    Folder Found : C:\ProgramData\NCH Software
    Folder Found : C:\Users\Keith\AppData\Roaming\NCH Software
    Folder Found : C:\Program Files\advanced system optimizer 3
    Folder Found : C:\Program Files\IObit Apps Toolbar


    Are you still having issues?
     
    Last edited: Dec 31, 2014

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds