Chrome and system issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheTick, Nov 20, 2012.

  1. TheTick

    TheTick Corporal

    Hi guys

    I have been having issues with chrome for about 3 weeks now (I was researching for an assign and clicked on links that automatically downloaded word/PDF's onto my comp, i think that this is when my issues started), every time i try and click on the icon it will not load but when i look in task manager there are 5 chrome.exe processes running. It takes like 4 repeated clicks to get chrome to work. I have run basic antivirus scans and ccleaner, as well as malwarebytes (All before i attempted your cleaning procedure) all turned up clean

    Other than that my system has slowed down greatly, since i have run the cleaning procedure things have improved but the hitman pro scan brought some issues up that concerned me. I followed your procedures and did not quarantine or delete the i clicked ignore.

    The other scans came back clean i think but its the hitman scan that picked up some issues.

    My comp is a dell N5010 laptop
    Win 7
    service pack 1
    intel i3 2.53 processor
    3gb Ram
    64 bit operating sys
    320gb HD

    I hope i have run everything properly and that it is a quick fix to let you guys get back to your excellent work

    Thanks very much
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes Hitman Pro found some issues. Uninstall the below but before uninstalling it, make sure that ALL browsers
    are terminated.


    Browser Manager

    The run Hitman Pro again and if it finds any of the same items, remove them. And then REBOOT.

    After reboot, run the below.



    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run another scan with HitmanPro and then attach the latest hitmanpro.zip log

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the new Hitman log
    • the JRT.txt log
    • C:\MGlogs.zip
     
  3. TheTick

    TheTick Corporal

    Hi chaslang

    Cheers for the reply :)

    I attempted to run Hitman again and it found the issues but would not let me delete or quarantine them, it said i needed a product key which i dont have. any ideas?

    Also i downloaded Junkware removal tool and it said it was harmful and hitman picked it up, i am assuming its not dangerous just wondering if this is common.

    cheers
    The Tick
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm betting that you had in the past used the free removal and it now will not do it for free. Run JRT and the rest of my instructions.

    It's a false detection. It also picks up MGtools. MGtools and JRT could just as easily declare Hitman to be malware but we are smarter than security companies and know what is good and what is bad. ;)
     
  5. TheTick

    TheTick Corporal

    Hi chaslang

    It times like this when i wish i had continued to study IT :( thank god for majorgeeks :)

    I have run the two scans that i could and here are the logs. Obviously i could not run Hitman so i had to run JRT and then MGTOOLS :)

    Thanks a lot
    The Tick
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now run a "scan only" with Hitman and attach the new log. Anything remaining we will manually clean.
     
  7. TheTick

    TheTick Corporal

    Hi

    Ok here is the hitman log, hope its pretty clean :)

    Cheers

    Tick
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still more to do as JRT was not able to remove a few items.

    Shutdown all protection software and then do the below.
    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\DataMngr]
    [-HKEY_USERS\.DEFAULT\Software\DataMngr]
    [-HKEY_USERS\.DEFAULT\Software\DataMngr_Toolbar]
    [-HKEY_USERS\S-1-5-18\Software\DataMngr]
    [-HKEY_USERS\S-1-5-18\Software\DataMngr_Toolbar]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. TheTick

    TheTick Corporal

    Hi chaslang

    I have run the requested programs and everything seemed to go ok.

    Quick question is it ok to run the programs with a browser open, as a rule i always shut them down, its just hard to remember the instructions sometimes. A pointless question i am just interested :)

    Anyway here are the logs

    thanks

    Tick
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    It is best to close browsers and all other programs to avoid potential problems with the fixes due to the other programs having file, folders, registry keys opened and locked and thus blocking fixes. You can leave the browser open up to the point where you are actually ready to run the fix. Before running, shutdown the browser.

    Your logs are clean. Are you having any more problems?
     
  11. TheTick

    TheTick Corporal

    Hi chaslang

    Chrome seems to be working again now it loads when i click twice now, when it took 4-6 times before the cleaning, my computer seems to be running faster now as well, so as far as i can see its working ok :) thanks a lot.

    I have one question, when i boot my machine and it gets to my desktop a window called autoruns pops up saying autoruns has been disabled, is this something to be concerned about?

    Thanks for all your help it is much appreciated :)

    Tick
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you using CCleaner or similar to control startup processes?? I see the below all stuck in MSconfig registry keys but the do not seem to be due to using MSconfig itself
    Also I still see Browser Manager installed. Did you not uninstall it when I requested in message #2 ?
     
  13. TheTick

    TheTick Corporal

    Hi

    Shit i misread your message two and didnt uninstall browser manager, should i run the scans again? and attach the logs?

    Yes i use Ccleaner to manage startups should i not?

    Cheers and sorry for the mistake

    tick
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall it now? Was it successful?

    No! See the below which used to be part of the READ & RUN ME.

    Dealing with Startup Process
     
  15. TheTick

    TheTick Corporal

    Hi

    I didnt know about Ccleaner i have always used the read and run me and it seems as though dealing with start up process is not in it.

    I uninstalled Browser manager it disappeared but said something like 'a problem occured in the uninstall, a cause for this might be that it has already been uninstalled, would you like to remove browser manger (the part that was still showing in uninstall a program section)' i clicked yes and it went. (apologies if this is not easy to read, i clicked yes before i had chance to read it)

    I have not run the HiJack this program yet as i am not 100% confident enough to do it at present, would you like me to run it and post logs?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was always in it until recent changes to shorten up the process a little and to use new tools. You can see it in one of the old versions here: http://forums.majorgeeks.com/showthread.php?t=208809

    Are you talking about for managing startups? If yes, try Autoruns instead. It was mentioned in that link too.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  17. TheTick

    TheTick Corporal

    Hi Chaslang

    Yes i was on about autoruns, i will read up on that in my own time :)

    i have followed the instructions but at number 8 'refer to the cleaning procedures pointed to by step 6 of the read me' is that running a whole new clean or step 6 toggle system restore?

    Another quick question, in task manager how many chrome.exe*32 should be running, i have 4 tabs running and 5 chrome.exe*32 are running.

    I might run extra scans to make sure nothing is here.

    Cheers
     
  18. TheTick

    TheTick Corporal

    Hi Chaslang

    sorry to be a pain but i ran the scans again as i was not sure if i closed my browser the first time. Apologies.

    If you have the time could you have a quick look? no rush and it would be greatly appreciated

    The Tick
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to move on. Your logs are clean. Just finish the final instructions and read them carefully. They do not say to run the cleaning steps again in step 8. It was explaining how to find the system restore instructions for your version of Windows.
     
  20. TheTick

    TheTick Corporal

    Hi Chaslang

    Sorry about the extra clean guess i got a bit to panicky

    I have completed the other steps and everything seems to be working ok and loading properly.

    I have downloaded comodo and re installed microsoft security essentials (64 bit version) and read the how to protect yourself section.

    Cheers for the help dude :) much appreciated
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds