In need of help

Discussion in 'Malware Help (A Specialist Will Reply)' started by rotika, May 1, 2013.

  1. rotika

    rotika Private E-2

    I have done as much as possible of the read and run me, couldn't get mbam to run, or MG tools. I have Mbam on my pc, when updated, it went unresponsive, and wont load. As for mgtools, I click run as administrater, I get the loading icon by curser, and nothing happens. I tried this from C, and desktop to no avail. Attached are what I could run.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [RUN][SUSP PATH] HKCU\[...]\Run : ahmudblp ("C:\Users\family\AppData\Local\nfxqsidd.exe") [x] -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-3041968378-1935589803-2394603559-1000[...]\Run : ahmudblp ("C:\Users\family\AppData\Local\nfxqsidd.exe") [x] -> FOUND
      [TASK][ROGUE ST] 0 : c:\program files (x86)\internet explorer\iexplore.exe -> FOUND
      [TASK][ROGUE ST] 4823 : wscript.exe C:\Users\family\AppData\Local\Temp\launchie.vbs //B -> FOUND
      [TASK][SUSP PATH] RunAsStdUser Task : "C:\Users\family\AppData\Local\teeveewatchSA\bin\1.0.7.0\TeeveeWatchSA.exe" [x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    Now click the Files/folders tab and locate these detections:


    • [ZeroAccess][FOLDER] U : C:\Windows\Installer\{36799aa1-53ee-7552-7630-e2221bf10deb}\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\Windows\Installer\{36799aa1-53ee-7552-7630-e2221bf10deb}\L --> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now rerun Hitman and have it delete all that it found.

    Reboot and rescan with both RogueKiller and Hitman and attach those logs as well.

    Also attach the log from running ComboFix, since you already ran it and be sure to tell me how things are running now.
     
  3. rotika

    rotika Private E-2

    Hi Tim,

    Thank yo for helping. I have attached the logs, what you saw of combo fix was on old scan, if you want me to run it I will. PC seems to be better, the hard drive is not constantly running anymore.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and remove all of those PUP;s. Then attach a new log from Hitman.
     
  5. rotika

    rotika Private E-2

    Attached is hitman log.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, now what issues are you still having, if any?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds