Step 4: malware logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by Raghnall, Oct 8, 2014.

  1. Raghnall

    Raghnall Private E-2

    I'm posting this thread because ESET online scanner found something. I'm unaware of any problems being caused by what it found.
    RogueKiller put a .log file on my desktop, not a .txt file.
    I received the "No threats found" screen from TDSSKiller.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    No real major issues found. Only the Disk Speedup and Advanced Driver Updater software which we categorize as junkware to remove. Did you knowingly install this? If not then uninstall them.
     
  3. Raghnall

    Raghnall Private E-2

    1) Did CCleaner, RogueKiller, MalwareBytes, TDSSKiller, HitmanPro, MGTools (as well as the online scanners F-Secure, PandaSecurity, ESET, BitDefender) create any unnecessary files that can be deleted? If yes, where are they located?

    2) When I click Start, Control Panel, Uninstall a program:
    CCleaner and MalwareBytes are listed
    but
    RogueKiller, TDSSKiller, HitmanPro, and MGTools are not listed. Why?

    3) In "Step 5: Enable User Account Control (UAC)", should it remind us to move the slider back to its original position? Mine was still on "Never Notify" after enabling it.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the procedure below to cleanup from what we had you do. Anything you did on your own without our instructions is up to you to cleanup logs....etc .

    Tools like RogueKiller, MGtools and even Hitman ( depending on which version gets installed ) are quick runs that do no get installed.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  5. Raghnall

    Raghnall Private E-2

    1) Malwarebytes quarantined this:

    Registry Keys: 1
    PUP.Optional.Softonic.A, HKU\S-1-5-21-2131205115-2283795236-811445278-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [e6066da4601c54e2ad0dfe373cc7f907],

    Should I leave it in quarantine or delete it?

    2) After running the MGclean.bat file, the C:\MGtools folder remains. Can this folder be deleted?

    3) Two desktop.ini files remain on my desktop. Can they be deleted?

    4) Is there anything else that remains after running MGclean.bat that can be deleted?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.

    The ini files and the MGtools folder remain because MGclean.bat did not run properly. Did you have any protectin software running? Was UAC still disabled? The ini files are part of Windows. They were hidden in the past but as part of are instructions, we had you unhide system. You can rehide them now. There is no reason to delete those system files.


    Well if MGclean.bat did not run properly, many of the programs we had you download or log files could remain. You can check and manually delete them and the C:\MGtools folder too.
     
  7. Raghnall

    Raghnall Private E-2

    "Yes" it should be left in quarantine or "Yes" it should be deleted?

    There wasn't any protection software was running.
    These two features of CCleaner were running (I do not believe they are protection software):
    CCleaner's, "Enable system monitoring, If cleaning saves more than 0.5GB, then Prompt me to clean", was running.
    CCleaner's, "Enable Active Monitoring", was running. When I go to disable it, I receive this message:
    "Warning - this action is not recommended. Active Monitoring will ensure that CCleaner is kept up-to-date and your computer as clean as possible. Are you sure you want to do this?"

    UAC was not still disabled. I enabled it by clicking on the C:\MGtools\enableUAC.reg file.
    I then moved the slider back to its original position because it was still on "Never Notify" after enabling UAC. Should I have moved the slider back to its original position?

    In Folder Options, I switched back to, "Don't show hidden files, folders, or drives".
    The desktop.ini files no longer appear on the desktop.

    Was everything saved to the desktop except for the C:\MGtools folder?
    Beacause I'm unsure of where to check manually for the programs I was instructed to download, or the log files, I'd prefer to have MGclean.bat do the job of removing the files and folders related to MGtools and the other items from the cleaning procedures.
    If MGclean.bat did not run properly, is there a way to get it to run properly?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! Yes delete them.


    It should not have mattered if you used Run As Administrator

    No. TDSSKiller will save logs in the root folder of your harddisk.

    Logs for other programs will be where you save them or in the default folder for the program. Like RogueKiller saves logs in C:\programdata\roguekiller folder which you will not be able to see now that you have disabled viewing of system files...etc.

    You could download a new version of MGtools and save it to your Desktop this time. Then disable UAC ( change the slider ) then right click on MGtools.exe and select Run As Administrator. Attach the new C:\MGlogs.zip file so I can see if anything remains that can be removed. Don't run MGclean.bat again until requested.
     
  9. Raghnall

    Raghnall Private E-2

    I follow the steps in, "Step 2: Disabling User Account Control". However, a red shield with an X in it never appears in the system tray whenever I disable User Account Control.
    Why?
    Is this a concern?

    I deleted the object Malwarebytes put in quarantine.

    I switched back to, "Show hidden files, folders, or drives". I don't see any TDSSKiller folders or files. Did TDSSKiller not create any (I received the "No threats found" screen from TDSSKiller the one and only time it was run. I did not run it again) or did MGclean.bat delete them the first time MGclean.bat was run?
    MGclean.bat was run only once - after the first MGtools.exe file was run. Per your instructions, I:
    Downloaded a new version of MGtools and saved it to the Desktop this time.
    Disabled UAC ( changed the slider ).
    Right clicked on MGtools.exe and selected Run As Administrator.
    Attached the new C:\MGlogs.zip file. (It was on the desktop.)
    Won't run MGclean.bat again until requested.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!

    Everything looks fine. MGclean.bat did cleanup everything. Right click on it and select Run As Administrator again to remove the MGtools folder and MGtools.exe


    After a reboot, check to make sure your UAC slide is back to normal.
     
  11. Raghnall

    Raghnall Private E-2

    Before the first time MGclean.bat was run, the instruction was to, "...make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry."
    For the second running of MGclean.bat, is UAC to be re-enabled afterwards?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run MGclean.bat first. MGclean.bat will attempt to automatically set it by using a registry patch. If it does not seem to work ( like you see a popup warning or Windows Security Alert shield about User Account Control being disabled ) then let Windows repair or fix it yourself.
     
  13. Raghnall

    Raghnall Private E-2

    There weren't any TDSSKiller logs after the first run of MGclean.bat when​
    1) Is it possible the first run of MGclean.bat removed some folders and files but not all of them?​
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    2) Attempt? What could prevent it from doing so?​
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    After running MGclean.bat the second time :

    3) The UAC slider was still on "Never notify". I moved the slider to "Always notify". Is moving the slider to something other than "Never notify" the same as re-enabling UAC?​

    4a) "Don't show hidden files, folders, or drives" is now selected in Folder Options. Did MGclean.bat switch it back to this setting?​


    4b) When I change the Folder Options setting to "Show hidden files, folders, and drives", the desktop.ini files do not appear on the desktop.​
    If :
    Then : Why do these system files not appear on the desktop?​



    5) MGclean.bat did not remove Malware Bytes log from the desktop.
    Should it have?
    Should I delete it?​

    6) MGclean.bat did not remove the C:\ProgramData\Malwarebytes folder.
    Should it have?
    Should I delete it?​

    7) MGclean.bat did not remove the C:\ProgramData\RogueKiller folder.
    Should it have?
    Should I delete it?​

    8) MGclean.bat did not remove the C:\ProgramData\HitmanPro folder.
    Should it have?
    Should I delete it?​
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    9) If there are folders and files that should have been removed by either the first or second running of MGclean.bat, but were not removed, where will they be located?

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    The only difference between the first and second running of MGclean.bat, that I'm aware of, is:
    Before running MGclean.bat the first time, UAC was re-enabled by clicking on the C:\MGtools\enableUAC.reg file.
    Before running MGclean.bat the second time, UAC was not re-enabled.
    10) What might have caused MGclean.bat to​
    the first time?​

    .
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes.
    Yes.
    Then if you are concerned about this, it is topic for the software forum. Once hidden files and folders are PROPERLY set to show, you should be seeing desktop.ini file(s)

    Not topic for this forum I'm afraid.

    I doubt it should have removed it. You can delete it if you wish. And anything else left behind like you described in points 6, 7 and 8..

    Which files and folders are we specifically talking about?

    Any other questions you have I cannot answer. As long as you are malware free that is the main thing. Chaslang has been extremely busy lately and that's why I have popped in. This forum is also quite busy at the moment, so please understand that I cannot answer every one of your questions, there is lots to do elsewere. :)
     
  15. Raghnall

    Raghnall Private E-2

    I hope I didn't give the impression of being impatient. If I did, I apologize. I've been pleasantly surprised with the response times.
    I am aware (as it says in the READ & RUN ME FIRST, Forum Rules and Guidelines, and Don't Bump! It Only Hurts You!!! threads) that this forum is run by volunteers who are available only when they have free time, that assistance in removing malware is extremely busy resulting in waiting times for help to grow significantly (currently about 5 days ), and that we need to respect the volunteers' time and be patient waiting for responses.​



    Sorry about that. I thought this topic belonged here since it was a result of the malware removal instructions.​



    I'm referring to any folders and files that were the result of the malware removal instructions.
    For example, MGclean.bat removed TDSSKiller, RogueKiller, MGtools and HitmanPro. But it did not remove the C:\ProgramData\RogueKiller folder nor the C:\ProgramData\HitmanPro folder.
    How do we know if there are other folders or files that were created but were not removed?​



    Do you have any tips on choosing an antivirus program?​
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Chaslang will swing by and post soon, but as I said he's been very busy so please be patient. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds