1. Hi Major geeks, I am just housecleaning my laptop for any malwares.

    I have a Sony Vaio Windows 7 Home Premium SP1, 4 GB Ram, Intel core 5 M430.

    My laptop has slowed down a bit and was just wondering if i have any malware.
    Sometimes when I play cs 1.6, it minimizes randomly. Not sure if that would be considered a problem.

    I have went through the steps you guys have provided:




    No threats were found for malware bytes,hitman pro, and tdsskiller.

    Kind regards,
    Steve
     

    Attached Files:

  2. sorry found the log for tdss :
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the below logs as requested:

    C:\Users\Steven\Desktop\HitmanPro_20131029_0056.log
    C:\Users\Steven\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2013-10-29 (00-30-32).txt

    Am not sure you problems are due to malware but there is some junkware to remove so let's do that.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com?type=198484&fr=spigot-yhp-ie
    R3 - URLSearchHook: (no name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - (no file)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
    C:\Windows\tasks\Registry Winner Schedule.job
    C:\Users\Steven\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6CB33CC7-0C10-4AB1-991A-67628BB033B7}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D72A3D5D-ECBF-4D18-937E-B576610D83E1}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the the original Malwarebytes and Hitman logs
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Hi Chaslang, I would like to thank you for ur help and quick reply. I was running through the steps you instructed, and as i was pasting your code to OTM, my AVG detected OTM.exe as a threat. Threat: IDP.Trojan.5bD43515. I wasnt sure if i should allow it or deny it.
     
  5. Okay so I clicked "Allow" on AVG. I did some research and they said it was a false positive which i hope is the case. Anyways here are the logs that you requested.

    I have also attached two logs from OMT.
     

    Attached Files:

  6. and here are the MGlogs.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes these are false detections. Many of the tools used to remove malware will trigger false detections like this due to the nature of what the tools do ( like deleting files/folders and modifying registry keys...etc ). Shut down AVG when trying to do the below so it does not get in the way.


    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  8. I see, here is my otl .txt

    By the way, I am having trouble when i type in dxdiag in run, message will pop up and say "Dxdiag has detected there might have been a problem accessing the Direct3D the last time this program was used..." then it gives me an option to bypass direct3d or not. If i click no, a pop up saying "Microsoft Direct x has stopped working" and it will close. It will only work when i click yes (bypass direct3d). I was wondering if that is malware related.
     

    Attached Files:

    • OTL.Txt
      File size:
      135 KB
      Views:
      2
  9. Hi chaslang, I am also experiencing randomly occuring messages where my vaio event services(service sub module) has stopped responding and asks me if i would like to send error report. I sometimes get vcadmin has stopped responding as well. Is there anything i can do to fix these? Here are some files that might help
     

    Attached Files:

    Last edited: Oct 31, 2013
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The problems you mention in your last two messages are not related to malware. And since your logs are basically clean as I mentioned earlier, I suggest that you post in the Software Forum. What I would suggest you try first is to uninstall ALL of AVG and all of the IObit software and then reboot your PC and see how it is running.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  11. Thanks for your help, really appreciate it. :-D.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds