First Set of Scans

Discussion in 'Malware Help (A Specialist Will Reply)' started by linuxpowers, Dec 24, 2014.

  1. linuxpowers

    linuxpowers Specialist

    Working on an HP Touchsmart 520
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and let it remove all it sees...


    Delete these:
    • C:\Program Files (x86)\SweetIM
    • C:\Program Files (x86)\Tuguu SL



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    • Re run Hitman Pro and attach log.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  3. linuxpowers

    linuxpowers Specialist

    Ok Kestrel13!, I'm running into an issue right now.

    I completed the following:
    but, now I can't get anything to load in the browser "except" majorgeeks.com! I only receive the following message, "This wepage is not available".

    The details tell me , "This server can't be found because the DNS lookup failed. This error is most often caused by having no connection to the internet or a misconfigured network. It can be caused by an unresponsive DNS server or a firewall preventing Google Chrome from accessing the network. ERROR CODE: DNS_PROBE_FINISHED_NXDOMAIN"

    I've tried to use IE with the same results!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nothing that I told you to remove with Hitman should have caused this, It was just junk, hmm, you may have to post in the software forum about this, but not yet, can you attach the requested logs please?
     
  5. linuxpowers

    linuxpowers Specialist

    OK hang on a sec. I misspoken. I didn't go far enough with my reply.

    I was also able to download and run JRT, and that's when I started having issues with the browser! My apologies!!!

    I'm keeping this conversation going using my personal computer. I need to see if I can email the JRT log to this computer and then post it to you. Give me a some time to figure something out.
     
  6. linuxpowers

    linuxpowers Specialist

    Seems my dsl modem has went offline...using my cellphone right now. Rebooting modem!

    Get back with you in a few! :-o
     
  7. linuxpowers

    linuxpowers Specialist

    Wow...things are crazy around here.

    Ok, I'm back online with my personal computer but the one I'm working on is still not connecting. It shows it has an internet connection but the browser still gives me the same message.

    I was able to use my personal computer to grab the JRT log file through the network and I'm sending that to you now. As a side note....since I was able to use my personal computer to grab the log file from the one I am trying to clean up, couldn't I just do the reverse and grab ADWCleaner from my personal computer? I could download it onto my PC!

    After running Hitman Pro and letting it remove all that it sees, I kept no log of that session!

    I also couldn't go any farther after JRT, so I don't have logs for ADwCleaner or MGTools

    Sorry for all the confusion!
     

    Attached Files:

  8. linuxpowers

    linuxpowers Specialist

    ok...now i'm back online with the infected computer!

    do you want me to continue with your last procedure, adwcleaner & mgtools with a rerun of hitman pro for the log?
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please complete Kestrel's instructions from post#2 and attach the logs.
    NOTE: The HitmanPro logs are found here > C:\ProgramData\Hitman Pro\Logs
     
  10. linuxpowers

    linuxpowers Specialist

    Alright, everything went as planned and here are the resulting logs.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs look clean. How are things running?
     
  12. linuxpowers

    linuxpowers Specialist

    Well, I had to turn off the touchscreen because it had the mouse courser jumping all over the screen clicking on icons and opening programs at random. Once I got that taken care of, everything seemed to settle down and I was able check things out.

    First off, I notice that Windows Update is not working. When I open the update dialog box, I have a red shield sitting there. When I click on, "Check for updates for your computer", i get an error message popping up that says that windows update cannot currently check for updates, because the service is not running. That I may need to restart the computer".

    I went to services and looked at "Windows Update" and is is running and is set to start "Automatically (Delayed)". I also check out all dependencies and everything seems to be started and running.

    I figured I might have a corrupted "download" folder so I renamed the current one to "download_old", rebooted, made sure a new "download" folder was created, and tried to run Windows Update again....with same error message appearing!

    Before I move on, I thought I might try to figure out whats up with Update! So far, everything else seems to be working just fine!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should ask about that in the software forum. Thanks. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  14. linuxpowers

    linuxpowers Specialist

    Thanks so much Kestrel13!, happy holidays and have a great new year!!!;)
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thankyou very much! You too! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds