Logs - Hp Laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jadenbobaden, Sep 8, 2016.

  1. jadenbobaden

    jadenbobaden Private E-2

    I'll get this out of the way: I know exactly where I went wrong and this wasn't worth the $30 I would've spent on a software license...


    #NeverAgain

    I'd appreciate some help getting myself sorted out.

    Thanks....

    PS: Start with the HitManPro Log
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please explain, while I go over your logs.
     
  3. jadenbobaden

    jadenbobaden Private E-2

    Pirated copy of CleanMyPC, for maximum irony. Now my svchost is working overtime and eating up both memory and CPU
     
  4. jadenbobaden

    jadenbobaden Private E-2

    Just got a hanging black screen with a cursor when I attempted a restart.

    The Windows Error Logs Have something called the cron service crashing at fairly regular intervals.
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    NOTE: You are very low on available free space and it is bound to have an effect on your system's performance.
    Delete this now using Windows Exlorer:
    C:\Users\Keitlah\Documents\Downloads\CleanMyPC 1.7.1 + Crack\WinRAR 5.30 Final x86 & x64 +NEW Key\Cracked\x86\CleanMyPC.exe

    Re-run RogueKiller.exe. (Vista/Windows7/8/10 users should right-click and select "Run as Administrator")
    After it finishes the scan, under these tabs select and then click the Delete button these items.

    ¤¤¤ Registry ¤¤¤
    All PUP only
    ¤¤¤ Files ¤¤¤
    ¤¤¤ Tasks ¤¤¤
    ¤¤¤ Web browsers ¤¤¤

    Then immediately reboot your PC.

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Upload RKreport[2].txt to your next message.
    After uploading RKreport[2].txt, now run a new scan with RogueKiller and save a log as in the original instructions and upload that new log also.

    Next, copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Next please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.

    Finally, download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
    *New and updated logs to upload:
    • RKreport[2].txt plus updated log
    • the JRT.TXT log
    • AdwCleaner[S#].txt
     
  6. jadenbobaden

    jadenbobaden Private E-2

    Here's the first RK Log. The registry edit was successful. Now I'm doing the third RK Scan.
     

    Attached Files:

  7. jadenbobaden

    jadenbobaden Private E-2

    and now the latest set of logs.... including one which I now realize might be superfluous.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Using AdwCleaner.exe previously downloaded:
    • Double click on AdwCleaner.exe to run the tool. (Vista, Win7/8/10 users should right-click and "Run As Administrator")
    • Click on the Scan button.
    • When the scan has completed, select these items ONLY
      • All the listed Folders, Files, and Web browsers detections
    • Now click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
    Tell me how the pc is running now.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Additional Fix:

    I have double-checked and these are ok to remove also using AdwCleaner.
    *Include all of the Registry keys detected also.

    Upload an updated AdwCleaner[C#].txt logfile.
     
  10. jadenbobaden

    jadenbobaden Private E-2

    Attached are the logs for the initial cleaning and the registry cleaning.

    My CPU is still constantly hovering around 40% with the bulk of it coming from a svchost.

    When I go to processes from there it highlights the following:

    Desktop Window Manager Session Manager

    Diagnostic System Host

    Distributed Link Tracking Client

    HomeGroup Listener

    Human Interface Device Access

    Network Connections

    Portable Device Enumerator Service

    Program Compatibility Assistant Service

    Superfetch

    Tablet PC Input Service

    Windows Audio Endpoint Builder

    Windows Driver Foundation - User-mode Driver Framework

    WLANAutoConfig

    ---

    When I poke around in the resource monitor, there are a couple processes that are followed with (network restricted) messages.....
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    None of the logs that I request are superfluous. They are what helps me provide you with FREE malware removal advice. ;)

    Now download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
     
  12. jadenbobaden

    jadenbobaden Private E-2

    Thanks for the free help. I appreciate it ;)
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    NOTES: Something is using MSconfig to control startups and that's the improper tool for that. See => Dealing with Startup Processes
    You are allowing Utorrent to run at start up. This is a serious security flaw. It opens your computer to anyone. You should only run it when you need it and then close it out!

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.
    How is your pc running now?
     

    Attached Files:

  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    It's been four days since my last instructions, jadenbobaden. Let's complete this thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds