Infected Laptop, Logs Attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Love3angle, Mar 20, 2016.

  1. Love3angle

    Love3angle Private E-2

    Hello, I ran through the Malware process (I've been using your process for years to stay/keep/get clean, thank you!). Looks like I have something this time. :-(

    I run Windows 10 on an Asus 64 bit laptop. I think my daughter picked it up surfing sites for a school project. It's just been slow & squirrely for about a week. Pages taking longer to load, freezing up. Chome locked up completely and now won't load at all in a Comodo Sandbox. So, I took my Sunday afternoon to run through all the scans.

    Logs attached.
    • RKreport[1].txt from RogueKiller
    • Malwarebytes' Anti-Malware log
    • TDSSKiller log
    • HitmanPro log
    • MGlogs.zip - normally it is C:\MGlogs.zip
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the correct scan log from Malwarebytes.

    Also what is the below that I see loading at startup:
    C:\\Program Files (x86)\\DTLSoft\\DriveTheLife\\DriveTheLife.exe\" /start"


    And can you describe your problems in more technical terms? Like exactly what operations are slow? And what is "squirrely"?
     
  3. Love3angle

    Love3angle Private E-2

    Hey Chaslang,
    Every online page takes a while to load, longer than it used to, and fairly often the browser becomes unresponsive. I had to stop using Chrome altogether and went back to firefox which seems to work a bit better, but it's getting quite slow. Non-web operations seem to work fine, i.e. MS Office is all functioning properly.
     
  4. Love3angle

    Love3angle Private E-2

    And yesterday and today I keep getting a Windows popup saying that an App has caused a problem with my default browser so it has reset by default browser to Edge. I reset it to Firefox. Then it does this again afetr I shut it down or reboot.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to answer my question about DriveTheLife

    None of that really sounds like malware but we will run some minor junk cleanup and see what happens. But first I need to know what DriveTheLife is.
     
  6. Love3angle

    Love3angle Private E-2

    Driver updater program. The driver on my trackpad got corrupted a while back - can't remember how long ago - and it was recommended by a friend as a program to track drivers that needed updating. It worked. Is it doing other stuff, too, that it shouldn't?
     
  7. Love3angle

    Love3angle Private E-2

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I recommend uninstalling it. Also uninstall anything you have installed from IoBit ( like AdvanceSystemCare....etc ). After doing this, then continue on with the below.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of the code box
    • Make sure that you scroll all the way to the bottom of the code box to get the whole fix!
    Code:
    :Processes
    explorer.exe
    
    
    :Files
    C:\ProgramData\cis82D6.exe
    C:\ProgramData\cis8BD8.exe
    C:\ProgramData\cisA841.exe
    C:\ProgramData\cisB664.exe
    C:\ProgramData\ProductData
    C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
    C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
    C:\ProgramData\DriveTheLife2013
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriveTheLife
    C:\MGlogs-old.zip
    C:\MGtools-old
    C:\WINDOWS\TEMP\*.*
    C:\Users\Alyxx\AppData\Local\Temp\*.*
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, Win7, 8 or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7, Win8 or Win10, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. Love3angle

    Love3angle Private E-2

    It took some doing. I deleted Drivethelife and iobit Uninstaller. I did not have Advanced Care installed.
    Firefox kept blocking the download of OTM until I disabled "Block reported attack sites" in security settings long enough to save it in documents then moved it to the Desktop.
    Comodo firewall initially blocked until I granted it unlimited access to my computer. Running it now.
     
  10. Love3angle

    Love3angle Private E-2

    Here's the OTM log. Moving on to Junkware.
     

    Attached Files:

  11. Love3angle

    Love3angle Private E-2

    Hello,
    During MGLogs, a system process started saying I needed .NET Franework 3.5. It attempted to download and install it but failed.
    "The funtion attempted to use a name that is reserved for use by another transaction. Error code: 0x80071A90
    Logs attached
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not tell me how things are working.
     
  13. Love3angle

    Love3angle Private E-2

    Sorry. Things are faster! Trying out Chrome now...
    Way faster, no locking up. Still won't open a Chrome window in Comodo Sandbox, but it will open a Firefox sandbox.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not something that I can help you with as it is not malware problem. But did you try resetting the sandbox? See >> https://help.comodo.com/topic-72-1-522-6277-Reset-the-Sandbox.html

    You may need to post in Comodo's Forum. I believe issues like this have been reported in the past. You will need to provide them with the versions for Comodo and Chrome that you are using and also your version of Windows.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. Love3angle

    Love3angle Private E-2

    Thanks for all your help! I'll check out the sandbox link and finish up the rest myself.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let us know the results just for future reference.
     
  17. Love3angle

    Love3angle Private E-2

    Did the cleanup. Comodo firewall did an automatic update on it's own and browsers now open fine in a sandbox.
    Now Netflix won't connect (error W80072EE4). I though it must be the firewall, but it won't connect when Comodo is disabled either.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. Love3angle

    Love3angle Private E-2

    I will. It's also not letting me reinstall itunes. So I don't know what the %$#@ is going on. I'll consider this closed and head over to the software forum. Thank you for your help so far.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes this are all Windows Related Issues. You may want to check out some of the fixes that the below tool can perform. Some of them may help. Especially permissions fixes for file/folders and registry.

    Windows Repair by Tweaking.com
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds