Malware- Dprhb11- 2016-11-25

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by manilka835, Nov 25, 2016.

  1. manilka835

    manilka835 Specialist

    Malware were found and therefore, I ran READ & RUN ME FIRST Malware Removal Guide Procedure on 28-07-2016. However the logs were not posted as the Computer began to restart when booted.

    The Power Supply was replaced and the RAM was increased upto 750 MB (Which is not adewuate still, but managed with the available resources).

    The CD-ROM was replaced.

    The Weekly Malware Scan was then run and Avast Anti Virus found some threats (scanning the whole system & Boot Scan) and removed them.

    The logs of READ & RUN ME FIRST Malware Removal Guide are attached herewith for your advice. Avast Anti-Virus Logs (Full System Scan & Boot Scan)are attached in the next message.

    Dr. K.D.J.H. Manilka Jayawardena,
    Medical Officer,
    National Tuberculosis Reference Laboratory (NTRL/Central Laboratory of NPTCCD),
    Chest Hospital Premises,
    Welisara.
    Proud to be a Sri Lankan!
     

    Attached Files:

  2. manilka835

    manilka835 Specialist

    Avast Anti-Virus Logs (Full System Scan & Boot Scan) are attached
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The logs from running the READ & RUN ME FIRST Malware Removal Guide are over three months old, and are of little use. Please re-run the tools and provide updated logs for accurate diagnosis.
     
  4. manilka835

    manilka835 Specialist

    Updated logs are sent herewith.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re-run RogueKiller.exe. (Vista/Windows7/8/10 users should right-click and select "Run as Administrator").
    After it finishes the scan, select the following tabs and then select any of the below that exist and then click the Remove Selected button.
    Then immediately reboot your PC. Now run a new scan with RogueKiller, save a log as in the original instructions and upload that new log.

    Now download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run JRT.exe by double-clicking it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Right- click on AdwCleaner.exe and select Run as Administrator.
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
    Your MGlogs.zip is very incomplete... run it again ensuring that protection software is disabled, that UAC is turned off, you are running it as Admin, and you must wait for it to tell you it is finished. Please run the GetLogs.bat file again and upload the new log.
     
    manilka835 likes this.
  6. manilka835

    manilka835 Specialist

    RKreport[2], JRT.txt, AdwCleaner Report and MGlogs.zip are sent herewith.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Using AdwCleaner.exe previously downloaded:
    • Right-click on AdwCleaner.exe and "Run As Administrator".
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.

    Tell me how the machine is running, now.
     
    manilka835 likes this.
  8. manilka835

    manilka835 Specialist

    AdwCleaner[C0].txt is attached herewith.

    There were no problems identified when the machine was run. I also ran the weekly Malware scans SUPERAntiSpyware, Malwarebytes Anti-Malware and Avast Free Antivirus and they did not detect any infections. The logs of these scans are attached herewith.

    Is there a compatibility issue between AVAST Antivirus and the COMODO Firewall?

    <Moderator edit: Remove unnecessary links to well-known programs>
     

    Attached Files:

    Last edited by a moderator: Nov 30, 2016
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    That is the combination that I am using. :)

    NOTE: Windows XP is an outdated, insecure and unsupported operating system. Even when it was fully supported, its security weaknesses were largely known and exploited. Such machines still being connected to the internet are huge malware magnets and are used to aid the spread of malware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. Go to add/remove programs and uninstall HijackThis.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    manilka835 likes this.
  10. manilka835

    manilka835 Specialist

    Unfortunately this machine cannot be upgraded to Windows 7 due to inadequate Hard Disk Space. In addition this is a very old machine which might go out of order soon. Therefore it is not cost-effective for upgrading the hardware.

    Thank You for your help. Another machine which was out-of-order will be repaired soon and brought to the lab. As I remember there were Malware in it. When time permits, I will run the READ & RUN ME FIRST Malware Removal Guide Procedure and post the logs in a new thread.

    This is yours truly signing off.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds