windows 7 Explorer issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by the_hammer, Aug 4, 2015.

  1. the_hammer

    the_hammer Private E-2

    Hello,

    Today when moving and deleting large files from windows explorer my computer froze, and I had to hold the power button to get it to shutdown. I have been having other issues in explorer for the past month where it was behaving very slowly.

    I have followed your malware removal guide and the log files are attached. While uploading the log files, the roguekiller file was in the wrong format, I changed the extension to a .log, hopefully that was the right thing to do.

    Thanks muchly!

    Aaron
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Malware Bytes and this time have it remove everything it finds.

    You did not attach the correct log for RogueKiller. You need to click on the EXPORT TXT button and get us a proper log. Please attach it in your next response.



    Download OTL to your desktop.


    We need to run an OTL Fix

    • Right-click OTL.exe to run it as admin. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :files
    C:\Users\Aaron\Downloads\m4a-to-mp3-converter-23185938.exe
    C:\Users\Gina\AppData\Local\Temp\APN-Stub
    C:\Windows\SysNative\drivers\yxgplib.sys
     
    :reg
    [-HKLM\SOFTWARE\Wow6432Node\Auslogics\Google Analytics Package]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApnStub_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApnStub_RASMANCS]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskInstallChecker_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskInstallChecker_RASMANCS])
    [-HKU\S-1-5-21-931283527-2298355919-176357012-1005\Software\Classes\Wow6432Node\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}]
    [-HKU\S-1-5-21-931283527-2298355919-176357012-1005_Classes\Wow6432Node\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}]
     
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    • Re run Malware Bytes again and save a log, hopefully showing no threats.
    • Re run Hitman Pro now and attach the new log for that too.
    • Don't forget the RogueKiller log.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • How are things running?
     
  3. the_hammer

    the_hammer Private E-2

    Thank you Kestrel13!

    I followed your steps to the letter. I will be posting the logs in order as instructed below. I have named the ones that I ran after the OTL program as ...post-OTL

    I am concerned about the things that roguekiller still finds even after running OTL.

    Windows hasn't increased in speed at all, but it hasn't crashed after running OTL and MalwareBytes either.

    Thank you for your help!
     

    Attached Files:

  4. the_hammer

    the_hammer Private E-2

    hers my MG tools zip file also.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome ;)
    RogueKiller is showing nothing to be concerned about. I presume you installed the Keylogger?
     
  6. the_hammer

    the_hammer Private E-2

    I may have, but I don't remember. if so, it was some time ago and unnecessary now. Did we remove it? if not, can you help me fully remove it?

    Thanks,
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sure, it's just this to delete - this is all that remains

    C:\Program Files (x86)\FK_Monitor

    Ready for final steps? :)
     
  8. the_hammer

    the_hammer Private E-2

    yes please give me the final steps
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  10. the_hammer

    the_hammer Private E-2

    you guys rock!

    Thanks so much
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. ;) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds