malware removal - have followed malware removal guide

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by marie95, Dec 17, 2014.

  1. marie95

    marie95 Private E-2

    Hi,

    I have a dell xps 8300. It started acting up about 1 week ago (freezing while working online, freezing while trying to boot). Today i got the Blue screen asking me to restart if this was the first time I had received a blue screen.
    I restarted it was fine for 30 minutes and everything froze.
    I restarted it and I received error beeps ( 4 beeps)
    I looked that up on dell support and they said it was RAM problems.
    I opened up the computer vacuumed a bit, took out ram cards and reinstalled them.
    It had been working o.k.for about 1 hour and only froze once more.
    I decided to try the malware removal guide and here are the logs
    Malware bytes did not find anything
    TDSSKiller did not find anything
    MGtools ran but as soon as it was done the window closed. i don't know how to find the log
    Your help will be greatly appreciated
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I still want to see the log from Malware Bytes please.

    Should be directly on C:\ if that's where you boot Windows from. If you really cannot find the log, you'll have to run MGTools.exe again in order to produce a MGlogs.zip. Thanks.
     
  3. marie95

    marie95 Private E-2

    Ok, attached is the mbam log.
    I reran the MGtool and it stops mid analyzing and a popup with a red x says
    " c:/MGTools/analyse.exe is not a valid Win32 application"
    Only option given is ok. If I press ok another pop up comes up called 'system information' that refreshes system information. Then both the MG tool window at it disappear. The only mg thing i find is the temp folder.
    Im not sure how to find the zip file, or if im running the MGtool incorrectly.
    I did print instructions and followed them.

    One more thing i didn't mention in the first post is that about 5 days ago i downloaded (from majorgeeks) slimdriver and ran it. I did have some drivers that needed updating. All went well with that though.
     

    Attached Files:

  4. marie95

    marie95 Private E-2

    Is this the mg log?
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove all that it finds.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  6. marie95

    marie95 Private E-2

    Thank you for your help and prompt reply.

    I could not delete files on hitman as it needed an activation code, I couldn't get the free to try for 30 days. Kept saying code already expired. im guessing i had already used it in the past?

    I'm still attaching the hitman log.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :files
    C:\Windows\Installer\{b4e4cddf-6429-9421-715a-1c9f61201d44}
    C:\Windows\Installer\{b4e4cddf-6429-9421-715a-1c9f61201d44}
    
    :reg
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASMANCS]
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Re run Hitman Pro and attach log.
     
  8. marie95

    marie95 Private E-2

    When running fix on OTL there was no image to click on,
    it just ran its course.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running? :)
     
  10. marie95

    marie95 Private E-2

    great actually. I noticed that it starts up faster.
    At start-up it used to go from windows splash screen, to welcome screen, then a blank blue screen for about 20 seconds. That blue screen is gone which is very nice.
    thank you.
    Should i do anything with the Hitman Pro last scan finding?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Funny, because this entry didn't show on the scan before last. You can indeed have it fix it if you like.
     
  12. marie95

    marie95 Private E-2

    I noticed that too.
    So I ran Hitman and had it fixed. Then ran it again and all was clean.
    enclosed are both logs.

    Thank you very much for all your help, really appreciate it.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) Safe surfing!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. marie95

    marie95 Private E-2

    I went through all the steps you previously mentioned.
    after i did the disable restore point, and enable it again, I still had some image restore points left under "backup"
    Is that normal because i backup in a separate drive?


    Do I delete all the programs that i had downloaded for this cleanup? except malware bytes of course.


    Otherwise all is good, again, thank you
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You'll have to ask about this in the softwrae forum.
    You can delete OTL.exe and any files/folders it created. What else is there that remains after following final steps?

    You're welcome. :)
     
  16. marie95

    marie95 Private E-2

    The remaining programs are Hitman pro, TDSskiller, and Roguekiller.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can uninstall/delete those. :)
     
  18. marie95

    marie95 Private E-2

    could my external hardrive which i use to periodically back up my computer, be infected with malware/virus like computer was?
    if so what steps do i perform for it.
    its a seagate expansion external hardrive.
    is it safe to just connect it to computer and run malware and avast?
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes indeed. That's what I would have suggested but you're onto it. ;)
     
  20. marie95

    marie95 Private E-2

    Connected external hard drive to computer and ran Avast and Malwarebytes.

    No issues were found!

    I only worried because i don't have the external drive connected all the time.
    I only connect it when i back up the computer. I was afraid that the issues i had with the computer before you helped me out, could be in the external hard drive too.

    Thank you for all your help.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds