Dont know where to start

Discussion in 'Malware Help (A Specialist Will Reply)' started by KirbyK, Aug 7, 2013.

  1. KirbyK

    KirbyK Private E-2

    This computer has been running very slow. Ran a scan and found conduit search, snap.do, search.nu, and adware helpers. I removed some files... but still have problems. Then a ran all your tools and it appears I have a mess on my hands. The logs show hundreds of viruses...... I have attached all but the HitmanPro log. It is 1.21MB and I cant attach (exceeds the 375KB limit). Thank you for helping.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below programs:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 25
    Java(TM) 6 Update 5
    Java(TM) 6 Update 6
    Java(TM) 6 Update 7


    Now install the current version of Sun Java from: Sun Java Runtime Environment Make sure that when you see the form asking about installing Ask Toolbar that you uncheck this.

    Now you need to rerun Malwarebytes and fix all the items you did not fix on you original scan. Make sure you fix them first and then save the log to attach later.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run a new scan with Hitman Pro and save a new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the newMalwarebytes log log.
    • the newHitman Pro log. If still too large, compress into a ZIP file and attach it.
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. KirbyK

    KirbyK Private E-2

    Wow... things are running so much better. I used malware bites to fix 178 issues (quarantine), re-scanned, then deleted the PUP reg (in log). Hitman thinks everything is a virus.... or is it? I've attached logs. Thanks so much.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes it is correct. You have a very serious infection that will infect executable files. This may not be safely fixable. By safely I mean:
    • Potentially fixing could result in an unbootable PC because required system files could be deleted or corrupted.
    • The fix/cure may not even work.
    • Even if still bootable, many installed programs could be broken due to their files being infected/corrupted and some may be deleted during fix operation.
    • Even if it appears that everything is working afterwards, you may still have one single file somewhere that still carries the infection ( could even be located on another drive or external drive ). If you run this file, the reinfection will spread to all executables again.
    • The trustworthiness of your PC may always be in question.
    So if you want to attempt to fix this rather then reinstall from scratch, first suggest before doing anything else is to make a backup to another drive ( external drive ) of all IMPORTANT data files, pictures, etc that you cannot replace from anywhere else. DO NOT backup any executable files ( this means even programs you downloaded .... any of them..... even MGtools.exe ) as they are all infected!!!!

    After you have your files backed up we can attempt to cure your infection. Let me know when ready.
     
  5. KirbyK

    KirbyK Private E-2

    I've saved my docs, outlook and excel files.... these are safe I hope? I'm on a network with 10 drives... we run trend micro security... hope they are safe... Otherwise, I'm ready. Worst case, IT will have to re-install. Thanks again Chaslang
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Most likely they are okay. Any EXE file for sure could contain the infection.

    The infection could have spread to all of them especially if you share files/folders or have copied executable files from one to the other.

    Since you have TrendMicro installed, shutdown everything else and run a FULL scan with it and see if it finds and fixes the problems. If not, you will have to uninstall Trend Micro. If could even be infected. And then try downloading, installing and running a full scan with Microsoft Essential Security which is supposed to be able to fix this infection.

    http://windows.microsoft.com/en-us/windows/security-essentials-download
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds