Help With Malware: Can't Burn Dvds And Cds And Computer Now Running Slow

Discussion in 'Malware Help (A Specialist Will Reply)' started by okos, Dec 24, 2015.

  1. okos

    okos Private E-2

    Two months ago I was unable to burn CDs and DVDs and my CDRW/DVD device made strange noises and recognized no disks. Thinking I had a virus, I contacted Malwarebytes; they advised me to run AdwCleaner, which found two pieces of malware. Since AdwCleaner removed the malware, I did not write down the exact names of the malware. However, I was still unable burn CDs and DVDs.

    Something hijacked my homepages in IE and FF shortly thereafter. I was able to select my homepages again, and they were not hijacked a second time. Norton Power Eraser found one .dll file related to malware named Chromium, and I removed this .dll file.

    In the past week, my laptop has begun to run slowly. Win 7 Pro SP1, Office 2010 SP2, 3 G RAM, and TSST Corp CDRW/DVD TSL462 ATA device.

    After following the directions for removing malware, problems turned up with TDSS killer. Attempting to unzip this file resulted in a message stating the folder was empty. Hitman Pro said my free subscription had expired; therefore, I downloaded a trial version of Emsisoft.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there okos,

    I would still like to see the log from Hitman Pro, even though the trial has expired, it will still produce a log to show what it finds. Please attach it.
    Your MGlogs.zip are very incomplete... do this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  3. okos

    okos Private E-2

    "The system cannot find the path specified." This appeared after I entered ed\MGtools and clicked enter.

    Entering nwktst resulted in this message, "nwktst is not recognized as an internal or external command, operable program, or batch file."

    Finally, entering GetRunKey lead to the appearance of this message, "GetRunKey is not recognized as an internal or external command, operable program or batch file."

    Should I attempt to enter the other commands?

    Regarding Hitman Pro, I downloaded this years ago on another computer and never ran a scan on this computer. If you advise me to, I'll purchase it and then send you the scan.

    Thanks for your help with this. Hope you have a Merry Christmas and a happy and healthy New Year!

    Charles

    PS
    In attempting to run alternative scans,
    I tried to run Bit Defender Root Kit Uncover.
    This made my computer suddenly shut down.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You typed ed or cd? Let me know...

    With Hitman you don't need to actually buy it in order to run a scan.... I just want to see what it finds. I can deal with what it finds another way. So run a scan with it and attach the log please.
    Do not run anything unless I advise you to. Thanks.

    You too!

    Run this....
    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  5. okos

    okos Private E-2

    I entered "ed."
     
  6. okos

    okos Private E-2

    Attached are the log from Hitman Pro, the two logs from the Farbar Recovery Scan Tool, and MGlogs.zip.

    Entering nwktst resulted in no error messages. After entering Get RunKey, a message appeared stating, "The system cannot find the file specified." Entering "ShowNew" and "analyse" did not cause error messages to appear.

    I saved a copy of these results and labeled it "cmd" ; however, I can't attach .docx files. Several years ago I saved files so clients running earlier versions of Office could open and read them. Should I now be saving files in other ways? (I write for pharmaceutical companies and researchers.)
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Happy Christmas :)

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.


    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Tasks tab and locate these detections:

    • [Suspicious.Path] %WINDIR%\Tasks\AbundDiscov57.job -- C:\Users\Charles Smart\AppData\Local\HaltiLocke7\Hasegment.exe -> Found
    • [Suspicious.Path] %WINDIR%\Tasks\SkillCraftin600.job -- C:\Users\CHARLE~1\AppData\Local\HALTIL~1\Hamaximum.exe -> Found
    • [Suspicious.Path] \AbundDiscov57 -- C:\Users\Charles Smart\AppData\Local\HaltiLocke7\Hasegment.exe -> Found
    • [Suspicious.Path] \SkillCraftin600 -- C:\Users\CHARLE~1\AppData\Local\HALTIL~1\Hamaximum.exe -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these on the files tab please...

    • [PUP][Folder] C:\ProgramData\{AA6BF06E-316C-487A-9BC2-5F06A43C56B1} -> Found
    • [Hj.Name][File] C:\$Recycle.Bin\S-1-5-21-513130945-461643082-857407046-1000\$RNG3F1I.exe\Chameleon\Windows\rundll32.exe -> Found
    • [Hj.Name][File] C:\$Recycle.Bin\S-1-5-21-513130945-461643082-857407046-1000\$RNG3F1I.exe\Chameleon\Windows\svchost.exe -> Found
    • [Hj.Name][File] C:\$Recycle.Bin\S-1-5-21-513130945-461643082-857407046-1000\$RNG3F1I.exe\Chameleon\Windows\winlogon.exe -> Found

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Then attach the below log:
    • Fixlog.txt
    Also at this point, I want to double check the status of things by having you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.


    Re run RogueKiller (just a scan) and attach that log, too.
    Explain how things are running.
     

    Attached Files:

  8. okos

    okos Private E-2

    Please recommend some third party software to control start up's. Are start ups the same as autoruns?

    Thanks for your advice.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    AutoRuns should take care of start up's quite nicely.
     
  10. okos

    okos Private E-2

    I ran AutoRuns according to the abbreviated instructions in WindowsSecrets. Two items highlighted in yellow,
    FULG and RUShell, could not be deleted.
     
  11. okos

    okos Private E-2

    After running RogueKiller as directed, none of the items you listed appeared under the Tasks tab. No log labelled RK 2.txt appeared on my desktop. After rebooting my laptop, no folder or file labeled fixlist.txt appeared anywhere.

    After disconnecting my wireless connection, running FRST.exe as an administrator, and clicking Fix button once on my computer, nothing happened. My computer did not reboot. I reconnected the wireless internet connection. Fixlog.txt did not appear on my desktop.

    Running FRST again, resulted in only a FRST.txt file. The results after running RK were the same as the previous time (Just like before there were 3 suspicious paths and 6 PUMs under registry and 1 PUM under browsers.)
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run RogueKiller again, save the latest log and upload it here.
     
  13. okos

    okos Private E-2

    Kestrel 13, the latest log for RK is attached.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run RogueKiller, on the files tab have it remove this entry:

    • [PUP][Folder] C:\ProgramData\{AA6BF06E-316C-487A-9BC2-5F06A43C56B1} -> Found

    I'd also like you to run Ccleaner (not the reg scanner) just the cleaner itself to be rid of a chunk of temp files.

    Once done, ensure the machine has had a reboot, and once again run a scan with RogueKiller. Save a log and upload it here.
     
  15. okos

    okos Private E-2

    Thank you so much for your help with this.

    Attached are the two RogueKiller scans you requested. Should I continue to save the earlier scans you requested?
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning :)
    Please uninstall avast before we continue, it might be hindering the fixes.....
    Follow my instructions in post #4 for running a fresh scan with FRST. Upload log once done.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
    Last edited: Dec 28, 2015
  17. okos

    okos Private E-2

    The three logs you requested are attached.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please upload this new log to your next reply
    Then upload the below log:

    Fixlog.txt


      • Fix items using RogueKiller.

        Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
        When it opens, press the Scan button
        Now click the Registry tab and locate these detections:
        • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FULG (C:\Users\CHARLE~1\AppData\Local\Temp\FULG.exe) -> Found
        • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FULG (C:\Users\CHARLE~1\AppData\Local\Temp\FULG.exe) -> Found
        • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\FULG (C:\Users\CHARLE~1\AppData\Local\Temp\FULG.exe) -> Found

        Place a checkmark next to each of these items, leave the others unchecked.
        Now press the Delete button.
        When it is finished, there will be a log on your desktop called: RKreport[2].txt
        Attach RKreport[2].txt to your next message. (How to attach)

        Reboot the machine.





        SystemLook

        Please download SystemLook from one of the links below appropriate for your operating system and save it to your Desktop.
        Download 32 Bit
        Download 64 Bit
        • Double-click SystemLook.exe to run it.
        • Copy the content of the following codebox into the main textfield:
          Code:
          :filefind
          FULG
          :regfind
          FULG
        • Click the Look button to start the scan.
        • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
        Note: The log can also be found on your Desktop entitled SystemLook.txt



        http://img225.imageshack.us/img225/760/blitzblank.gif Please download BlitzBlank to your desktop.
        • Double-click BlitzBlank.exe to open (Vista/7 right-click and select Run as Administrator)
        • Press OK at the warning prompt.
        • Click the Script tab
        • Copy the text inside the code box below and paste it into the text-field.
        Code:
        DeleteFile:
        C:\Users\CHARLE~1\AppData\Local\Temp\FULG.exe
        • Now click the Execute Now button.
        • The fix will require a reboot in order to complete successfully.
        • Upon reboot, locate C:\blitzblank.log and attach this log to your next message. (How to attach)

        Re run RogueKiller, and upload latest log.
     

    Attached Files:

    Last edited: Dec 30, 2015
  19. okos

    okos Private E-2

    Should I disable my antimalware protection before performing the above?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.
     
  21. okos

    okos Private E-2

    How do I download fixlist.txt?
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Same way you have done so twice before...click on the fixlist.txt at the end of my post #18 and save the file.
     
    Last edited: Dec 29, 2015
  23. okos

    okos Private E-2

    After selecting to run FRST.exe as administrator, clicking once on the Fix button makes this message appear, “Looks like you don’t know what to do. To prevent damage to the system, the tool will close.”


    First.exe did not make Fixlog.txt on the desktop.


    Items were fixed using Rogue Killer. Rogue Killer created RKreport2.txt on the desktop.


    System Look created SystemLook.txt


    Right clicking on BlitzBank.exe leads to to a message stating the item may have bee moved, its name may have been changed, or it may be temporarily unavailable.


    Rogue Killer reran and uploaded latest log.
     

    Attached Files:

  24. okos

    okos Private E-2

    I followed the directions for Emsisoft BlitzBank a third time and pasted the message under the script tab. Clicking Execute Now leads to this message, "Syntax error, invalid file path."
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, despite all the problems you ran into, it's looking good. ;)

    Address this:
    Run Autoruns again, do those items still show? I want to be sure....
     
  26. okos

    okos Private E-2

    RUShellExt File not found: C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll

    This message appeared regarding RUShellExt. FULG didn't appear.
     
  27. okos

    okos Private E-2

    RUShellExt File not found: C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll

    This message appeared regarding RUShellExt. FULG didn't appear.[/QUOTE]
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's good. How are things running?
     
  29. okos

    okos Private E-2

    My CD burner works slowly and wanted to format a new CD before burning a Kaspersky Rescue Disk.

    Also, I have EasyTech PC Health Check on my computer--how do I remove this? Never go to Staples; they put EasyTech into my computer.

    The site for Advanced Uninstaller put 52 cookies in to my computer along with GOK what else. Please recommend some scans to see if the site unloaded other malware into my computer.

    Thank you for your help and advice.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this:
    C:\Users\Charles Smart\Desktop\EasyTech PC Health Check.mht

    Is there anywhere else you are seeing signs of EasyTech?

    Cookies can be cleared away with the likes of Malware Bytes and Superantispyware. They are not problems. What is GOK?

    You are very welcome.
     
  31. okos

    okos Private E-2

    Well, my CD/DVD burner works strangely. When I attempted to burn a current version of Kaspersky Rescue Disk and Norton Boot Repair Tool, I often got a message telling me to erase my disk followed by one telling me to format the disk. The same messages appeared whether I was using a CD-R, CD-RW, or DVD-RW. After trying to format the disk for half an hour, the genies in my lap top stated, "There is no disk in drive D: Insert a disk, and then try again."

    I tried to follow the directions for burning CDs and DVDs in Windows Help and did not finalize or close my disk. Inserting a new disk in the drive enabled to me to ultimately create a Kaspersky Rescue and a NBRT.

    Again, thank you for your help and advice. If you or your colleagues, would like me to edit a topic you've written up, please let me know. In real life, I'm a physician who is also a medical and science writer.

    Best wishes in your endeavors,

    Charles

    PS
    I sometimes use okos for my first name. A rough translation
    of my name in Hungarian is okos enus, "smart boy."
     
  32. okos

    okos Private E-2

     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome for the assistance.
    I'm afraid the issue with the CD burner will have to be posted about in the software forum, that is not topic for this forum. :) Best of luck!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds