I need assistance please

Discussion in 'Malware Help (A Specialist Will Reply)' started by mratliff, Oct 25, 2014.

  1. mratliff

    mratliff Private E-2

    I have followed the instructions on the website to scan my laptop. I have attached the logs to this message.

    I am using my laptop to try this as a solution to my husband's computer problems. My operating system is Windows 8.1. My husband's computer is running on Windows 7.

    Please help if you can because he is constantly complaining about pop-up windows when he goes to downloading sites, and in his programs on the computer it shows only 20 or so programs installed but he has at least 50 programs on his desktop. When he clicks on the programs he has on his desktop they open, but are not shown in the programs installed.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.


    Why are there two antivirus installed? One must be uninstalled right now before we continue!!

    • avast! Free Antivirus
    • AVG 2014

    Uninstall this too please:
    • KeyBar 2 Toolbar for IE


    Re run Hitman Pro and have it remove all that it finds.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&...CyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1821773149&ir=
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=QuickObrw&dpid=RY_196&co=US&userid=84417afa-ddc5-c387-360a-167670820c99&searchtype=ds&q={searchTerms}&installDate=11/11/2013
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=QuickObrw&dpid=RY_196&co=US&userid=84417afa-ddc5-c387-360a-167670820c99&searchtype=ds&q={searchTerms}&installDate=11/11/2013
    • O2 - BHO: (no name) - {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} - (no file)
    • O2 - BHO: KeyBar 2 - {bc09c55d-0375-4dcc-836e-0e3c8addfbda} - (no file)
    • O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
    • O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    • O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    • O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} -

    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\ProgramData\SPLF702.tmp
    C:\WINDOWS\tasks\AutoKMS.job
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Re run Hitman once more and attach log.
    Same for RogueKiller.
    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  3. mratliff

    mratliff Private E-2

    I have re ran Hitman Pro and let it remove everything it found. I have ran RogueKiller and all the PUM.HomePages that it detected did not delete. I have removed AVG because I really like the way Avast works on my computer. I have attached the report for RogueKiller for you to review. I have also attached the log from the Hitman Pro scan I ran as well.

    I will reboot my laptop and wait to hear from you before I disable my antivirus and anti-spyware programs.

    I thank you so much for your assistance and I hope you will be able to walk me through this procedure when I work on my husband's computer as well.

    I will wait to hear from you.

    Thanks
    Meme
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You deleted some entries from the Tasks tab with RogueKiller according to the log. I did not ask you to do that. Also please avoid making changes like switching antivirus whilst we are cleaning.
    I can't see anywhere where something did not delete...so...rescan again with RogueKiller (just a scan!!) and attach log. :)
     
  5. mratliff

    mratliff Private E-2

    I only ran RogueKiller, checked what you said, and clicked delete. I have no idea where the task tab is, however, you are right, I did remove a spyware removal program that I tried to use today. I will not do anything on my laptop except what you instruct me to do from now on. I am going to run the scan now and I will attach the log when it is completed.

    Thanks, talk to you soon
     
  6. mratliff

    mratliff Private E-2

    Please see the attached report from RogueKiller. I did notice that the scan did not take as long this time as it did before:)
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, now continue on with the other instructions. :)
     
  8. mratliff

    mratliff Private E-2

    So far, so good. I have attached the log from the OTM scan. I will continue with your instructions.

    Thank you, thank you, thank you!!!
     

    Attached Files:

  9. mratliff

    mratliff Private E-2

    I am getting ready to do the final steps of your instructions and run the last programs. On your instructions you wanted to know any problems I had during this process. I had only 2. They are:

    1. After running the OTM scan the system rebooted. When it rebooted, my desktop came back black. I restarted it two more times and it finally rebooted properly with my desktop in tact.

    2. The url you gave me for the Junkware Removal Tool did not work so I downloaded it for this site.

    I will send you the logs when the scans are completed. I can't thank you enough for all the assistance you have been during this ordeal. The funniest part of all of this is that I did this to fix my husband's computer and my laptop needed it just as much!:-D

    I will respond soon....
    Meme
     

    Attached Files:

    • JRT.txt
      File size:
      866 bytes
      Views:
      3
  10. mratliff

    mratliff Private E-2

    Attached are the logs you requested in your instructions. I was checking my computer and found that Avast is no longer active on my computer. Should I reboot my computer now? And can I re-install Avast? I want that antivirus program on my computer...I need your help again for answers.

    I look forward to hearing from you soon.

    Thanks for everything...:)
    Meme
     

    Attached Files:

  11. mratliff

    mratliff Private E-2

    I took it upon myself to reboot my computer and Avast is back. The startup is faster than before. I have not gone through my system to see if there is anything else I need to report to you. If I find anything, I will let you know.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) We'' certainly assist with the other machine too.

    Ready for final steps? Those logs look good. :)
     
  13. mratliff

    mratliff Private E-2

    Yes, I am ready for the final steps.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  15. mratliff

    mratliff Private E-2

    I have completed all of your instructions and am happy to say that my laptop runs smoother and faster than ever! :-D

    Thank you so much for all of your assistance! I will wait until Thursday to begin working on my husband's computer. Until then, thank you and I will talk to you then.

    Thanks again:)

    Meme
     
  16. mratliff

    mratliff Private E-2

    You guys are the best!!!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome Meme, I'm very please to hear things are running beautifully. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds