Possible Malware Problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rb3bm4, Mar 24, 2018.

  1. rb3bm4

    rb3bm4 Private E-2

    I'm working on a Surface Pro, 64 bit, Windows 10 Pro, Office 2013. I tried to run CCleaner after I logged on this morning and it wouldn't boot up. Was able to uninstall but not reinstall. Same problem with SlimCleaner. Tried to used both Word and Excel and was unable to do so. Got "need to repair" error messages with both. Ran scans with Superantispyware, Malwarebytes, and Spybot but nothing unusual turned up. Assuming the worst I'm thinking this is malware related. Anything else to try before I run through the procedure outlined in the other forum forum? I did run Malwarebytyes a second time and it got hung up at "scan startup files". Would not move beyond this point after 20 minutes. Thanks, RB
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may have to do the Read and Run instructions. But let's see what this finds:

    Please download Zemana Malware Removal to your desktop and run it please.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  3. rb3bm4

    rb3bm4 Private E-2

    Zemana scan log attached. Looks like two hits related to SlimCleaner install. RB
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you can now install CCleaner.
     
  5. rb3bm4

    rb3bm4 Private E-2

    No. Cannot install CCleaner. Endless spinning circle. Task manager says program not responding. Note did not quarantine two files from Zemana scan. RB
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Zemana quarantined them.

    Download ZHPCleanerto your desktop.

    Close all applications (including your web browsers and antivirus)
    Double-click on ZHPCleaner to run the tool.
    If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    Please click the "J'accepte/I agree" button.
    First press the "Scanner" button. Be patient, the scan may take some time.
    Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.
     
  7. rb3bm4

    rb3bm4 Private E-2

    Here is ZHPCleaner scan report. RB
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove everything it found.

    Go to the Read and Run first instructions and run both Hitman and RogueKiller/

    I am moving the thread.
     
  9. rb3bm4

    rb3bm4 Private E-2

    Thanks. Will do. RB
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the requested logs when you are ready.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  12. rb3bm4

    rb3bm4 Private E-2

    Running Rogue Killer. (Did not run Malwarebytes. Have not run Hitman.) After about 30 minutes, scan is hung up at "searching for TASKS...". At this point items detected is 0. Let it run? Do something else? RB
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  14. rb3bm4

    rb3bm4 Private E-2

    Will do. Rogue Killer? Still running. Let it run? Or cancel? RB
     
  15. rb3bm4

    rb3bm4 Private E-2

    Two Farbar scans attached. Done while RogueKiller still running. RB
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First let's clean up a few issues:
    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After doing that, turn off your protection software and try to either install CCleaner or CCleaner portable. (P0st #11)
     
  18. rb3bm4

    rb3bm4 Private E-2

    CCleaner will not install. Ccleaner portable will install. Run? RB
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do the Fixlist fix? Do that first and then see if you can run the portable. Did you try disabling your protection software before trying to install the regular CCleaner?
     
  20. rb3bm4

    rb3bm4 Private E-2

    Sorry lost the thread. I see your Fixlist.txt in #16. Do not see frst64.exe on desktop though. Go back to #13 and then back to #16? RB
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  22. rb3bm4

    rb3bm4 Private E-2

    Got it; here you go.
     

    Attached Files:

  23. rb3bm4

    rb3bm4 Private E-2

    To fast forward a bit using #19, was able to download CCleaner. It runs with Analyze but did not fix problems yet. RB
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what you mean....you can have it analyze your system but it will not remove the selected items?
     
  25. rb3bm4

    rb3bm4 Private E-2

    I just ran the Run Cleaner option in CCleaner and it detected and removed. Appears to working as usual as it did about 24 hours ago. RB
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Any other issues?
     
  27. rb3bm4

    rb3bm4 Private E-2

    Don't think so. Problems started with being unable to open Word and Excel docs. Can access them now. What malware was infecting computer? Most likely pathway of infection (if possible to answer)? Don’t have to use Major Geeks very much. However, when I do, the support is great. Thank you very much for your time and expertise over the last 24 hours. Much appreciated. RB
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There was no real malware....just the scareware Zemana found.

    And you are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds