Check Log Files on Slow HP

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chris Jones, Oct 19, 2015.

  1. Chris Jones

    Chris Jones Private E-2

    do i need a new box or just a little tech help?

    cleared cache for Net Browsers, DNS, JAVA,

    ran JRT
    ran the big 5,

    here ya go. let me know if you want the JRT log,

    thanks!

    cj
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Chris :)

    Internet Explorer Toolbar 4.8 by SweetPacks <<< Uninstall this.

    Re run Hitman Pro and have it remove all under the headings of Malware Remnants and Potential Unwanted Programs.

    Delete this:
    C:\Program Files\GUM9B6C.tmp

    Give Ccleaner a run (not the reg scanner) just the cleaner itself to be rid of a chunk of temp files.
    Re run Hitman just a scan and attach log.
    Same for RogueKiller.
    Attach the JRT log too.
    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  3. Chris Jones

    Chris Jones Private E-2

    HitmanPro free license expired, rolleyes

    any alternatives or do i spring for $24.95?

    tried different emails for free reg, no joy,
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's remove what it shows manually. How are you in the Windows Registry? Do you feel comfortable deleting what Hitman shows?
     
  5. Chris Jones

    Chris Jones Private E-2

    i would love to go in there and work in those reg files,

    would bring back memories of running DOS 3.2 and the C prompt! :)

    went to highschool with Jobs and Woz, if they can handle it...
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    In the Windows Registry remove all that Hitman shows under the headings of Malware Remnants and Potential Unwanted Programs.

    Once done, reboot the machine and rescan with Hitman again and attach new log. :)
     
  7. Chris Jones

    Chris Jones Private E-2

    here is the latest file for HMP,

    was able to delete about 4 reg remnants,

    but most seem to located in hidden directories like "Installer'

    Thanks! Machine is starting to run a bit faster already,
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    
    :reg
    [-HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}]
    [-HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}]
    [-HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}]
    [-HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}]
    [-HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}]
    [-HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32]
    [-HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{eafe8ae2-593d-4535-8919-0f4e7a4eebe3}]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}]
    [-HKU\S-1-5-21-1191676146-3066468000-445628376-1000\Software\AppDataLow\Software\Yahoo\Companion]
    [-HKU\S-1-5-21-1191676146-3066468000-445628376-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\SnapDo.exe]
    [-HKU\S-1-5-21-1191676146-3066468000-445628376-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\StormWatchApp.exe]
    [-HKU\S-1-5-21-1191676146-3066468000-445628376-1000\Software\Microsoft\Internet Explorer\Stats\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}]
    [-HKU\S-1-5-21-1191676146-3066468000-445628376-1000\Software\Smartbar]
    [-HKU\S-1-5-21-1191676146-3066468000-445628376-1000\Software\Yahoo\Companion]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Re run Hitman again and attach log, let's see if OTM could work it's magic on them or not.
     
  9. Chris Jones

    Chris Jones Private E-2

    Thanks for the continued help and o apologize for the delay since the last post,

    here is the OTL file,

    working on the Hitman log ...
     
  10. Chris Jones

    Chris Jones Private E-2

    attach did not take in previous post, renamed to txt file, :yum
     

    Attached Files:

    • OTL.txt
      File size:
      14.7 KB
      Views:
      3
  11. Chris Jones

    Chris Jones Private E-2

    since HMP license expired, no lig file is generated,

    however, we were able to do a screen shot before it defaulted to registration menu page,

    only four remnants left!

    Thanks and sorry for multiple posts,

    cj
     

    Attached Files:

    • HMP.jpg
      HMP.jpg
      File size:
      63.5 KB
      Views:
      4
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you delete what remains manually?
     
  13. Chris Jones

    Chris Jones Private E-2

    Yes! finally learning which DIR those pesky files are in,

    Thank You So Much!!!

    cj
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Once done, rescan with Hitman Pro, it should be able to produce a log for you to attach here. :)
     
  15. Chris Jones

    Chris Jones Private E-2

    throw another log on the fire, :-D

    buy some more ram and we could really be in business,

    Have a Nice Day!
    cj
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    :-D

    Is everything running nicely again now?
     
  17. Chris Jones

    Chris Jones Private E-2

    yes, the hard drive LED does not stay on all the time, it is flickering like it did when the laptop was new, Thanks Again!

    cj
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds