Still Seem to have malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by briguyz71, Oct 28, 2014.

  1. briguyz71

    briguyz71 Private E-2

    Ok, so I have tried to get the bottom of the proxy server issue and I have to assume that it is not work related. Is there something I could try in order to go forward and remove the proxy server stuff. I also have seen more malware from pop ups on chrome. Also we are not opposed to reinstalling windows 8 if necessary. Thank you for your patience with us!
    Thanks again,
    Brian
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hang in there please. There's been a few of these stubborn proxy problems floating about lately, and most things we try are not working. Let me look into it further.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall your anti virus temporarily. Re scan with RogueKiller and have it fix the proxy entries. Reboot and then rescan with RogueKiller again and attach log.
     
  4. briguyz71

    briguyz71 Private E-2

    No worries, we are good. I appreciate all of your hard work! :)
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you do what I asked previously?
     
  6. briguyz71

    briguyz71 Private E-2

    rk report. A website did pop up about Userland rootkits: Part 1, IAT hooks from adlice.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you uninstall your antivirus before running that scan?
     
  8. briguyz71

    briguyz71 Private E-2

    Yes, I uninstalled mcafee.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions below in the order written.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files". We are only saving this to your Desktop at this time. We will use it later. Make sure that it shows up on your desktop as a registry patch. Notice the icon.
    Now reboot your PC info safe boot mode. Remember to keep your antivirus uninstalled until requested to reinstall.


    Once in safe boot mode, click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the fixme.reg file saved to your Desktop and double click it. Allow it to be added to the registry. Please observe whether you receive a success message.
    Now right click on RogueKiller.exe and Select Run As Administrator and run a scan. After it finishes the scan, select the Registry tab and then select any of the below that exist and then click the Delete button.

    Then immediately reboot your PC. But this time reboot into normal boot mode.

    After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the new RogueKiller log
    • C:\MGlogs.zip
     
    Last edited: Nov 26, 2014
  10. briguyz71

    briguyz71 Private E-2

    Logs as requested.
    Thanks,
    Brian
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good now. Are you having any more problems?
     
  12. briguyz71

    briguyz71 Private E-2

    The computer seems to be running great. Thank you to you and Kestrel! Anything left to finish up?
    Thanks again,
    Brian
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  14. briguyz71

    briguyz71 Private E-2

    There is one thing I have noticed, seem to be having a redirect when the wife uses Google Chrome.
    I've attached a log from mbr.
    Sorry it has been so long in between posts, we are dealing with some health issues with our son and have been working thru some stuff with him.
    Thanks,
    Brian
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to hear about your son. Hope things are okay.

    There is nothing wrong with your MBR. MBRcheck just is not real reliable anymore at detecting all the various types of MBRs that exist.

    See if the people simple approach works to solve your problem with Google.

    Reset Chrome to Defaults
     
  16. briguyz71

    briguyz71 Private E-2

    Thank you for the kind words about my son. He's been having seizures and we are having tests done to determine why. He is alright most of the time, just very scary when he has them.
    I reset Chrome and it seems like it is ok. I will proceed with the clean up and see how we are doing.
    Off topic, my sons have expressed interest in computers and have been interested in what you guys have been doing for this one. Is there some information or resource that I could research to get them started on this type of work. They home school and we are letting the learn different topics they show interest in. Please feel free to PM me if that is more appropriate.
    Thanks!
    I will let you know how things are going.
    Brian
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unfortunately we are too busy to offer training to anyone who is not already a recognized expert. There are a few websites that provide training rooms. The process can take awhile to complete since there is a lot to learn and the people training you are doing it in their free time. Make sure that you are serious about wanting to spend the time to learn and have the time to perform malware removal this because it takes a strong committment. Check out the below sites:

    BootCamp

    Geek U!

    What the Tech Classroom

    BleepingComputer Malware Removal Training Program
     
  18. briguyz71

    briguyz71 Private E-2

    Thank you. I will see if any of those peek their interest.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds