Cleaning My Kids Computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Stiina59, Dec 23, 2016.

  1. Stiina59

    Stiina59 Private First Class

    I'm running through the process on my daughter's laptop and I can't get TDSKiller at all. The link redirects to a Kaspersky site to purchase software every time. Do you want me to run the antivirus or what? It isn't the software described in the TDSKiller section. I will skip this one for now and wait for your instruction on completing the Run First section.

    Thanks for your help!

    Stiina / Laura
     
  2. Stiina59

    Stiina59 Private First Class

    Before I realized that it wasn't exactly what you were asking to be run, I purchased the antivirus and installed it and forgot about it, so its been running in the background. After I left the previous message, a popup came up that it has detected the Trojan.Multi.GenAutorunTask.b located in the System Memory. It is my inclination to go ahead and Disinfect & restart as trojans get me nervous. I hope that doesn't mess anything up.
     
  3. Stiina59

    Stiina59 Private First Class

    I am finished with the other scans and am attaching them. I hope these are related to the Trojan deleted. After deleting the trojan, I am now getting log in errors to MS that Win10 requires you to do now. Apparently it caused some damage to the system files.

    Thank you for your help!

    Stiina59 / Laura
     

    Attached Files:

  4. Stiina59

    Stiina59 Private First Class

    Tried to download TDSSKiller and it was working now. Here is the log file...well crap, all I get is an error message saying that the file is empty, all 273k of it. Now what?
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Having two anti-virus programs installed causes huge problems. Choose only one to keep --> Kaspersky Anti-Virus or Webroot SecureAnywhere

    Please run Hitman Pro, then remove all PUP detections. Reboot and rescan with Hitman Pro, upload an updated log.
    Re-run RogueKiller.exe also, fix all detections; re-scan and upload a fresh log.

    In your next reply also include the C:\AdwCleaner\AdwCleaner[S#].txt log.
     
  6. Stiina59

    Stiina59 Private First Class

    Thanks, dr.moriarty. I didn't realize she already had an antivirus when I loaded Kaspersky. I got rid of the one she had. I forgot to include the AdwCleaner, it had quite a lot too! I ran the Hitman twice and RogueKiller three times. I was having trouble with the windows login. It was only allowing me access, but no changes. The third time I ran RK, Windows finally loaded correctly and allowed me to update the RK program. Still am getting detections in both Hitman and RK.

    Stiina / Laura
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Using AdwCleaner.exe previously downloaded:
    • Right-click on AdwCleaner.exe and "Run As Administrator".
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
    Run new scans with both tools and upload those updated logs also, please.
     
  8. Stiina59

    Stiina59 Private First Class

    Thank you again, dr.moriarty. I have run the scans and the logs are attached, but of course, the RK says the file is empty. If it helps, there were no detections in the RK scan.

    Stiina59 / Laura
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Using AdwCleaner.exe previously downloaded:
    • Right-click on AdwCleaner.exe and "Run As Administrator".
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
    • Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.
     
  10. Stiina59

    Stiina59 Private First Class

    ADWCleaner found nothing the first time through (sorry-guess I forgot the second run through last night. Had a 4 yr old distraction, lol)
    The ZHPCleaner was another story, log attached.

    Thanks!

    Stiina59 / Laura
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Tell me how the PC is running, after completing the following -

    Re-run ZHPCleaner per previous instructions
    • After the scan has completed - press the Repair button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
     
  12. Stiina59

    Stiina59 Private First Class

    Ok, here it is! Thanks again, dr.moriarty.

    Stiina59 / Laura
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You forgot to tell me how the PC is running....
     
  14. Stiina59

    Stiina59 Private First Class

    It seems to be running just fine. :)
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Ok

    Please review all of the snake-oil registry cleaners, pc optimizers and driver download managers the cleaning tools removed from the PC with your daughter .

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  16. Stiina59

    Stiina59 Private First Class

    dr.moriarty, have you read the "Read Me First" process lately? I was stunned that the Defogger was no longer listed nor the System Restore toggle. Now, I could have missed it as I'm getting pretty old and fairly blind. Remember, I started on a DOS machine with a 10k hdd. You know, back when Gates was still wearing diapers, lol. (Sorry, it's 4 am and I'm getting a bit slap happy)

    I did find that I was able to find the System Restore and do the toggle operation even on the Win10 OS, guess I've not totally lost it.

    I will discuss with my daughter what she needs to do about the protection and staying away from, those snake oil registry cleaners etc. I think she will talk to me in the future. She wasn't happy with her computer being so corrupted and will probably listen next time (kids all think they know more about this stuff then their parents) I do have one son that constantly reminds me that he WAS listening to me. Now that's defying the odds!! Not really, he's a programmer genius type, just not a malware expert. ;)

    Hey, thanks again for your help and have a Happy New Year!

    Stiina59 / Laura
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, and best wishes for the new year.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds