Could You Please Have A Quick Look At My Logs?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by millermaster, Oct 28, 2017.

  1. millermaster

    millermaster Private E-2

    I had found my PC to be running slow at times and it appeared to me that something was running in the background which made no sense to me.

    I am using Microsoft Security Essentials for real time protection and MBAM on a regular basis to scan for malware. After I looked into some of my settings I found that MBAM had the rootkit scan option (under settings => protection) turned off which I manually changed to on. Also, I found the Remote Assistant Connections (Control Panel => System => Remote Settings) to be set to "Allowed" which I now changed by unchecking that box. I never had given that permission in the past. Therefore I was concerned and followed the instructions given in the "Read & Run Me First" section.

    I am not sure if the [PUM.Policies] found in RogueKiller or if one or both of the two files found by HitmanPro are of concern. Could you please have a look at those files for me?

    I appreciate your help and thank you very much in advance!

    millermaster
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, right click start and click "Run" and when it opens, type in:
    %temp%

    Remove everything that it finds and then clean out your Recycle Bin.

    Then please attach the log from running ADWCleaner.
     
  3. millermaster

    millermaster Private E-2

    TimW,

    Thank you so much for your quick reply.

    When trying to remove all %temp% there appears to be a file FXSAPIDebugLogFile.txt dated 7/12/2017 with a file size of 0 bytes which gives me the following message "The action can't be completed because the file is open in Windows Explorer" "Close the file and try again" which makes no sense because there is nothing open.

    On a different note, I have multiple accounts on my PC with only one which has administrator rights. I am performing everything posted and instructed to do only in this account or do I have to perform everything in the other accounts, too?

    I am attaching the ADWCleaner log.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs.

    A slow computer is not always due to malware:

    Please explain what operations are slow! For example answer the below:

    * Is boot up slow?
    * Is shutdown slow?
    * Is browsing/surfing slow?
    * Is downloading slow?
    * Is running any application?
    * Is it also slow in safe boot mode?
    * Also are any process showing in Task Manager to be using a lot of CPU time?
    * Anything else slow?
     
  5. millermaster

    millermaster Private E-2

    TimW,

    The PC is slow to start and eg. does not display the specific icons for desktop icons. Instead of showing the recycling bin, pdf-icons or the hitmanpro icon it displays a white empty page icon for about 8 minutes.

    Looking at task manager => processes, I see svchost.exe for user "system" multiple times. The largest with 329MB and with 125MB. Further down I see svchost.exe a total of 15 times in the list: 7 times in "system", 6 times in "local service" and 3 times in "network service". Once I start firefox with one window firefox.exe appears 4 times (151MB and 125MB as largest memory using process). Also while doing nothing the CPU usage shows just around 30%. I understand it doesn't have to be anything maliciouse and everything should be fine. Perhaps this is due to another windows problem.

    Is the [PUM.Policies] found in RogueKiller and is one or are both of the two files found by HitmanPro of any concern?

    I had used the premium trial version of MBAM at the beginning of October. I just looked at my notes and on 10/08 MBAM reported "MBAM is unable to load the Anti-Rootkit DDA Driver. This error may be due to rootkit activity". The same message appeared on 10/15. Also during the same time frame on 10/09 and on 10/20 MS Security Essentials had Real Time Protection turned off even though I never had turned it off. Not sure if MBAM and MS Security Essentials just conflicted while running and starting up at the same time or if something else was going on. I had no more such issues since the premium version of MBAM has expired.

    Thank you for your help,
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.

    For x64 bit systems downloadFarbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC. Enter System Recovery Options.


    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:
    Startup Repair
    System Restore
    Windows Complete PC Restore
    Windows Memory Diagnostic Tool
    Command Prompt

    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  7. millermaster

    millermaster Private E-2

    TimW,

    Here is that file.

    For a split second there is a window popping up only in the administrator account. I was able to capture a screen shot. It reads "Catalyst Control Center: Host application has stopped working". This window pops up two or three times but always disappears immediately.

    Thank you
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding malware in any of your logs. If you wish to pursue your issues, I suggest you post in the software forum.

    Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds