Generic Load Point

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gAB72, Dec 31, 2013.

  1. gAB72

    gAB72 Private E-2

    Hi,
    My recently installed Norton 360 scanned my system and found this:

    A generic load point detected by virus scanner.
    Under view more details it says:

    File:C:\Windows\Tasks\At8.job
    File:C:\Windows\Tasks\At7.job
    File:C:\Windows\Tasks\At6.job
    File:C:\Windows\Tasks\At5.job
    File:C:\Windows\Tasks\At4.job
    File:C:\Windows\Tasks\At3.job
    File:C:\Windows\Tasks\At2.job
    File:C:\Windows\Tasks\At1.job

    Delete Failed

    Someone hacked into our computer around a year ago and we had it repaired but some things seem "off" so we'd like to check the system out to be sure that it's secure.

    Thanks,

    Gab
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide

    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual update Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only RogueKiller and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run the rest of the READ & RUN ME FIRST instructions on the infected account.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. gAB72

    gAB72 Private E-2

    Hi Kestrel13,
    I'm going to have to do these tests little by little. I am not sure if this one was done correctly so bear with me. Thank you for your help.
     
    Last edited by a moderator: Jan 1, 2014
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. gAB72

    gAB72 Private E-2

    Is this better?
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, continue on now please with all of the other requested logs. Thanks. :)
     
  7. gAB72

    gAB72 Private E-2

    Here's the malware bytes log.

    tdsskiller failed to upload.

    Hitman Pro: I received this message:
    vBulletin:
    Your submission could not be processed because a security token was missing. If this occured, please inform your administrator and describe the action you performed before you received this message.

    MGTOOLS:
    It says Invalid File.

    I could upload the MGlogs.zip file. Will that help?

    This is so annoying.
     

    Attached Files:

  8. gAB72

    gAB72 Private E-2

    mbam log:
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. Can you try zipping up the Hitman log and attaching it that way?
     
  10. gAB72

    gAB72 Private E-2

    Can you please tell me what steps to take to zip up the hitman log? I am not too good at this stuff.

    Thank you!
     
  11. gAB72

    gAB72 Private E-2

    Does this work?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just an FYI: These are not malware. They are from iolo System Checkup that you have installed.
     
  13. gAB72

    gAB72 Private E-2

    Thank you for pointing that out. I didn't know what that was.

    I saw some unwanted/strange things on the Hitman log and now I wait to see what happens next.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can just rerun Hitman and allow it to fix the Potential Unwanted Programs that it showed. The other items are not issues.

    You should also run the below.

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  15. gAB72

    gAB72 Private E-2

    Hi Chaslang,
    I turned off my Norton 360 and downloaded the junkware removal tool.

    After it finished, it just closed the black box down. It didn't add a JRT.txt log to my desktop. I ran it again and it did the same thing.

    I wrote down the info:

    Creating a registry backup
    The system cannot find the path specified.

    Checking startup:
    Checking modules:
    The system cannot find the path specified

    Checking Processes
    Checking Services
    Checking Files
    Checking Folders
    Checking Registry

    It closes shortly after it gets to checking Registry. Any ideas?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try booting in safe boot mode and run it there.
     
  17. gAB72

    gAB72 Private E-2

    I'm getting the same thing running it in safe mode.

    I'm not sure what to try next. I'm also noticing ads for dating chinese women on your site now. Is that normal?
     
    Last edited: Jan 1, 2014
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay try the below instead. If it does not run then your problem may be Norton 360 even if disabled.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    Yes there are some ads that will come up with this stuff in it. Just ignore it. It is not malware. Just advertisements.
     
  19. gAB72

    gAB72 Private E-2

    Here's the info:
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are just a few minor things to clean up.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Documents and Settings\Sue & Tom\Local Settings\Application Data\Conduit
    C:\Program Files\Conduit
    C:\Documents and Settings\Sue & Tom\Local Settings\Temp\*.*
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect]
    [-HKEY_USERS\S-1-5-21-1343024091-2111687655-1177238915-1004\Software\Conduit]
    [-HKEY_USERS\S-1-5-21-1343024091-2111687655-1177238915-1004\Software\SmartBar]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. gAB72

    gAB72 Private E-2

    I downloaded OTM program and ran it. I copied and pasted the info into the correct box and clicked on MOVE IT! Now I'm getting a (Not Responding) in the upper blue bar portion on the box. I had to shut down the computer and retried the same thing and got the same Not Responding message.

    Not sure if I need to do it differently?


    I appreciate all of your help on this!

    One other item. Our system is now super slow since installing Norton 360. We installed it a few weeks ago. We're also missing a BUS Driver. I will probably put those items under another forum if necessary.

    Thank You!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well you seem to have problems just about running everything. ;) I want to point out something here though. There has been no real significant malware found. You just have a few minor adware issues and that is all. It is really not that important that we make sure these last few items are removed.

    The new item you just mention about your PCs performance is due to your PC specs:

    Code:
    Processor x86 Family 15 Model 4 Stepping 4 GenuineIntel ~2793 Mhz 
    Total Physical Memory 1,024.00 MB 
    Available Physical Memory 192.43 MB 
    This shows you have an older slower processor design and also that you have about 1/3 of the memory I would recommend for running Windows XP SP3 especially on a slower computer style. Also your available ( free ) memory is low by standards required to keep Windows running efficiently. Norton 360 may just be too much for your PC, but with such low memory and old processor style, most modern day protection software is going to cause performance issues.
     
  23. gAB72

    gAB72 Private E-2

    Hi Chaslang,
    I thought that we were already running Windows XP SP3 on this computer. I am also wondering what we can do to improve this system or should we look into buying a new computer?


    I hope your new yr is going great!

    PS
    For the time being, if we do decide to buy another system (which is highly likely) should we keep the Norton 360 plus the Malware Bytes and CCleaner, too? I'm not sure if they're all needed so I'll go by your recommendations. I am also wondering if I can remove all of the tools that I downloaded from Major Geeks from the desktop?
     
    Last edited: Jan 2, 2014
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what I said in my last message. I was just stating you don't have enough memory to run it properly.

    As mentioned in my last message, triple your memory is the fastest solution. But one other thing to keep in mind is that Microsoft will officially stop supporting updates to Windows XP this April ( see http://windows.microsoft.com/en-us/windows/end-support-help ). This does not mean you cannot run your PC anymore, it just means there will be no official support from Microsoft anymore.

    So the choice is really in your hands. Do you want to send any money to keep this PC running better for any length of time or do you want to put that money towards a new PC with more capabilities and more future? ;)

    You could price out memory upgrades in the below link which will also analyze your PC to tell you exactly what you can add.

    http://www.crucial.com/systemscanner/

    And then you can research the cost of new PCs.


    Just an FYI: I have quite a few PCs running Win XP that I will not be changing yet. Obviously I need them to do all this kind of malware removal work. But they work just fine. I have no less than 2 GB of memory in any of them and that is on the ones that are at least dual core processors ( which are faster/newer than yours PC type. I do have one older PC than is similar to yours. It is a 3 GHz processor which is faster but it is the same vintage. I have 3 GB of memory in this one. And while it is slower than other newer PCs, it runs fine. But I Norton 360 would probably slow it down a bunch too.
     
  25. gAB72

    gAB72 Private E-2

    Hi Chaslang,
    Thanks for the link. I'll look at pricing out memory upgrades for this system and then decide if we keep using this one or trade it in for a newer model.

    Do I have to do anything special to remove all of the Major Geeks tools that are on the desktop? Or just click on them for removal?

    Thanks again for all of your help!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     
  27. gAB72

    gAB72 Private E-2

    Hi Chaslang,
    Thank you for all of your help and for all of the info and links, too! I've already added them to a file for future reference. It's nice to have sites such as Major Geeks out there that offer help and ideas to keep your system running clean. I'm going to work on your Protect Yourself From Malware link next.

    Happy New Year!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!

    Happy New Year!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds