daughter's computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lorioelfke, Jul 20, 2015.

  1. lorioelfke

    lorioelfke Private E-2

    Daughter's laptop is likely infected by some adware/malware that I am working on fixing. I have completed all of the steps on "Fixing browser and search engine redirection/hijacking problems" without successfully eliminating the nuisance hijacking Google Chrome. I am now working on the Read & Run Me First: Malware Removal Guide and have run into an immediate problem. Step 3 asks me to open Control Panel and when I do, there is a problem. A screen shot is attached. I hope you'll be able to help me get past this stumbling block so I can move ahead with removing the malware.
     
  2. lorioelfke

    lorioelfke Private E-2

    I realized later that you would like to see logs from "Fixing browser and search engine redirection/hijacking problems." Those logs are attached. TDSSkiller did not find any issues. I am also including the report from backing up the computer, showing some files that could not be found.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you run into problems, let us know about it, but just keep going. We need the logs from RogueKiller, Hitman, and the MGTools.
     
  4. lorioelfke

    lorioelfke Private E-2

    After running CCcleaner, I was able to access Control Panel and was able to turn off User Control.

    Attached are requested logs.

    I subscribe to Malwarebytes Premium and have included the two scans that were generated this morning. One is a threat scan and the other is what they call a protection scan.

    Your file attacher would not allow me to upload the Rogue killer log that was created this morning, describing it as invalid. So I went into Rogue killer and created a text log, naming it Alternate Rogue killer log and attached it.

    The other logs will come in another message!

    Still Having issues with Google Chrome; a screenshot of what that issue looks like is attached as a jpeg.

    Thanks for your help!
     

    Attached Files:

  5. lorioelfke

    lorioelfke Private E-2

    MGTools log attached.
     

    Attached Files:

  6. lorioelfke

    lorioelfke Private E-2

    The screen shot is too big to upload so I guess you'll have to let me know if you want any additional information about the Google Chrome problem.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it remove all items under>> Potential Unwanted Programs.

    Now do this:
    Reset Chrome to Defaults

    Reboot and rescan with Hitman and attach a new log. Be sure to tell me how things are running now.
     
  8. lorioelfke

    lorioelfke Private E-2

    I have just finished running Hitman Pro again, the first step in your assignment to me. I do not know which items are Potentially Unwanted Programs. Everything in the scan results is listed as AskBar, CouponBar, Softonic, or Unideals. Do I delete all of these? Scan is attached.
     

    Attached Files:

  9. lorioelfke

    lorioelfke Private E-2

    I read the log and discovered that everything falls under the category of PUP so I'll proceed.
     
  10. lorioelfke

    lorioelfke Private E-2

    Here's the final Hitman Pro log. The log keeps showing ask.com even though its been deleted in Hitman Pro twice now. Also there was a coupon bar that showed up in the results but did not show up in the log.

    I opened 10 tabs in Google chrome and didn't have any hijacking trouble.

    I've turned the antivirus protection back on.

    Thanks for all of your help. Let me know if there's something else I should try.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    [​IMG] Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  12. lorioelfke

    lorioelfke Private E-2

    Here is the Junk Removal log.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't tell me how things are running now.
     
  14. lorioelfke

    lorioelfke Private E-2

    In response to your inquiry, I opened Google Chrome. Soundersfc.com worked fine in the first tab. I was in the midst of typing in youtube.com when the screen was taken over by a message that says "The page at https://solvemypc1.net says: 1) Windows Firewall Warning ***YOUR COMPUTER MAY HAVE ADWARE/SPYWARE VIRUS*** Call 1-866-377-1242 immediately for assistance on how to remove potential viruses. The call is toll free.

    The message goes on to describe risks and more about the virus, ending with another plea to call the phone number above.

    It was continually repeating messages such as these that prompted my visit to majorgeeks.com seeking assistance.

    When these messages pop up, they seem to affect typing and also cause random skipping from one tab to another in the midst of typing.

    I guess we are not out of the malware woods yet.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstalll Google Chrome. Completely.
    Uninstall Chrome but also delete these folders:
    C:\Users\User Name\AppData\Local\Google\Chrome
    C:\Program Files (x86)\Google\Chrome


    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    Reboot and reinstall Chrome. Now tell me how things are running.
     
  16. lorioelfke

    lorioelfke Private E-2

    Google Chrome is uninstalled.

    I cannot find either of the files that you requested to be deleted. When I type the second one into search, the MGlogs.zip file, and the JRT log pop up, but no individual file.

    I'll await further direction before running AdwCleaner.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and run ADW cleaner. Reboot and rescan with Hitman and attach the logs.

    Reinstall Chrome and tell me if the problems still exist.

    Are any other browsers affected?
     
  18. lorioelfke

    lorioelfke Private E-2

    Here's the AdwCleaner log. I didn't delete anything yet because I feel rather unsure. I see some AVG files in there and my daughter has AVG antivirus protection on her computer. So I am stalled until I get some advice as to whether or not I should leave all those things in the list of what AdwCleaner says should be deleted.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove everything except these items:
    Reboot and rescan with Hitman. Attach the log and tell me how things are running.
     
  20. lorioelfke

    lorioelfke Private E-2

    Okay to delete the following in AdwCleaner:

    HKLM\SOFTWARE\Mozilla\Firefox\Extensions
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All except the AVG secure search.
     
  22. lorioelfke

    lorioelfke Private E-2

    Attached is a post-cleaning AdwCleaner log. I rebooted and then ran HitmanPro; log is attached. Google Chrome has been reinstalled. I opened about 20 different tabs in Google Chrome with no problem.

    One thing that I noticed is that when Google Chrome opened after reinstallation, all of my daughters bookmarks were still there. Is that supposed to happen?

    Thanks for your help. Let me know what I should do next.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, they are still there because of the two files you could not find to delete.

    It looks good.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  24. lorioelfke

    lorioelfke Private E-2

    Running the MGclean.bat file left two copies of MGlogs.zip on the computer. Should I leave these?

    There is no uninstall available for TDSSKiller and AdwCleaner. I see those are both .exe files. Can I just delete them?
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can just delete those files. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds