Heavy Disk usage

Discussion in 'Malware Help (A Specialist Will Reply)' started by kprokasky, Sep 23, 2013.

  1. kprokasky

    kprokasky Private E-2

    Hello,

    I noticed the hard drive light on my wife's laptop going Thursday evening and no one had been using it for a few hours. I left it overnight and it was still chugging away Friday morning. We were out of town and the computer off until today at which time I noticed it again.

    I went through the "Read Me First" instructions and the hard drive light is still flickering more than I would expect, but it is better. There were a large number of items found, so I thought I would attach my logs thinking there was still something affecting the system.

    Note, when I ran Malwarebytes' Anti-Malware - I accidentally clicked the Remove selected before I had finished clicking all the items. I wasn't sure what to do so I ran it again - made sure I had checked everything and then I clicked Remove Selected again. I attached both of the log files to this post and I will attach the MG logs to a follow up post.

    If I need to start over from scratch because of that I understand. I will do that.

    Thanks!
     

    Attached Files:

  2. kprokasky

    kprokasky Private E-2

    Here is the MG Tools log file which I could not fit onto my original post.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Potential Unwanted Programs.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 2 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Users\Keith\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-574178813-650693855-428132013-1008\[...]\Run : SearchProtect (C:\Users\Keith\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Explain how things are running. :)
     
  4. kprokasky

    kprokasky Private E-2

    Thanks!

    The Hard Drive access appears to be what I would call "normal" now. It took about 10 minutes after I ran Junkware Removal tool to get to that state. I am a bit embarrassed to say that the active HDD light may have been Carbonite (or at least partially to blame). I suspended the Carbonite backup and the HDD lite stopped - after I started it again the light started at a bit more rapid pace. :-o

    Regardless - the system seems ok, but there were still some items found when I ran Rogue Killer. Note here that the 2 items you asked me to delete were not found when I ran the scan. I created a logfile showing this and I attached that instead.

    Please let me know if there is something more I need to do with the other items found.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Everything that is in the RK log you attached now is fine. :) Ready for final steps?
     
  6. kprokasky

    kprokasky Private E-2

    Yes - all ready for final steps!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  8. kprokasky

    kprokasky Private E-2

    Done!

    Thank your very much!!:-D
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds