Malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by michael.edwards00, Dec 9, 2014.

  1. michael.edwards00

    michael.edwards00 Private E-2

    It worked fine for a while then I did not use it for while. It is now acting funny again. One major issue is the Wifi will randomly turn off and it runs slow.

    I have attached newly ran scan reports. thanks in advance.

    ME
     

    Attached Files:

    Last edited by a moderator: Dec 16, 2014
  2. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Your original thread was from over a year ago and you didn't follow up on it after given the first set of instructions.

    I have moved your post to a new thread since you last thread was locked due to our new policy on locking old threads automatically once they are 6 months old.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put this computer in normal start up mode.

    You should not have BitTorrent running at start up.

    Use Add/Remove programs to uninstall:
    Ask Toolbar
    Babylon toolbar on IE
    BabylonObjectInstaller

    Rerun RogueKiller and have it fix these items:
    Code:
    [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 :  (C:\$Recycle.Bin\S-1-5-21-741989594-3182478639-2422309455-1000\$056fa88798dea7523c3a9b214aa0c1b6\n.) [x] -> FOUND
    Now rerun Hitman and have it fix everything it finds.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Users\Stephen\AppData\Roaming\Babylon
    C:\Users\Stephen\AppData\Roaming\BabylonToolbar

    Reboot and rescan with both RogueKiller and Hitman and attach the new logs.

    Then, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * RogueKiller log
    * Hitman log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. michael.edwards00

    michael.edwards00 Private E-2

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you are running AVG, please use add/remove programs to uninstall:
    McAfee Security Scan Plus

    Now rerun Hitman and remove these items:
    Code:
    Malware remnants ____________________________________________________________
    
       C:\$Recycle.Bin\S-1-5-21-741989594-3182478639-2422309455-1000\$056fa88798dea7523c3a9b214aa0c1b6\ (ZeroAccess)
    
    Potential Unwanted Programs _________________________________________________
    
       homepage
       C:\Users\Michael.Stephen-PC\AppData\Local\Google\Chrome\User Data\Default\Preferences
    
       ask.com
       C:\Users\Michael.Stephen-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data
    
       ask.com
       C:\Users\Stephen\AppData\Local\Google\Chrome\User Data\Default\Web Data
    Now use windows explorer to find and delete ( They may be gone after you uninstalled McAfee):
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

    Reboot and tell me what issues remain, if any.
     
  6. michael.edwards00

    michael.edwards00 Private E-2

    At first glance it is working well; definitely much better. I did have some issues getting Google Chrome to open. I uninstalled/re-installed it and seemed to work. I will post an update in a few weeks.

    thanks!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know.

    In the meantime:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  8. michael.edwards00

    michael.edwards00 Private E-2

    Thanks for all your assistance! I will post an update in the near future.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds