Internet Blocking Malware [1 Day Time Limit - Need Help ASAP]

Discussion in 'Malware Help (A Specialist Will Reply)' started by Twistid, Sep 6, 2015.

  1. Twistid

    Twistid Corporal

    Note: I have run the READ & RUN ME FIRST process. I will post those logs in my reply below.

    I apologize for how sudden this post is. I have until Monday, 8pm or so (tomorrow after posting this), to try and clean up the infection(s) on a friend's laptop. I am visiting my hometown and will have to head back to where I am usually at for college tomorrow. Otherwise, I'd have to wait a whole month to look at anything again and they do not have enough patience or knowledge to really do what needs to be done to get it cleaned.

    I have a friend who was recently given a hand-me-down laptop computer. I recently discovered from talking to her that the laptop has some sort of malware infection. This was first determined when she was telling me that all of the sudden that she could not access the internet. I've recently been trying to get the infection(s) removed but it appears to be pretty stubborn and also appears to have numerous malware infections.

    She was originally depending upon iOBit Malware Fighter as something to protect from malware and scan/removal. I kept that program on here for Malware scans/removal in the future, but decided to disable the protection and go with AVG Antivirus Free for that, which seemed to be helpful in removing some of the malware infection(s).

    Before I tried some quick scans with iOBit Malware Fighter, Malwarebytes Anti-Malware, and AVG Antivirus, I uninstalled a few things that appeared concerning after some quick Google searches. I used IOBit Uninstaller to uninstall the programs: CliCkForSale and GoldenCoupon. I also uninstalled a Google Chrome extension called SaleItCoupon.

    I have attached the logs that resulted from various scans I did before deciding to go ahead and go for the full-fledged READ & RUN ME FIRST process. AVG would only allow me to save a comma-separated file format for the log. Sorry that that is not more legible. Hopefully there is additional information that is helpful in those.

    I could not attach a picture file of an iOBit Malware Fighter because the filesize was too large. But basically what that mentioned was what appeared to be a likely false positive after a quick Google search. It claimed the file located at C:\Program Files (x86)\Sony\Station\LaunchPad\lp_plugin.exe was infected with Trojan.KIdent.

    I will attach the READ & RUN ME FIRST logs below in reply.
     

    Attached Files:

  2. Twistid

    Twistid Corporal

    READ & RUN ME FIRST logs attached. Hope you guys can help me get all of this removed in time!
     

    Attached Files:

  3. Twistid

    Twistid Corporal

    Also, the operating system for this laptop is Windows 7 Home Premium.
     
  4. Twistid

    Twistid Corporal

    I forgot to mention also that the following Windows error dialogs appeared originally when I was beginning to try and determine what was going on:
    WIN34E.exe has stopped working
    WIN3E47.exe has stopped working

    Malwarebytes appeared to make one go away eventually, and AVG Antivirus appeared to resolve the other one from showing up.

    Also when I was running the MGTools scan, I got a "SteelWerx WhoAmI has stopped working" error dialog from Windows.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not really seeing much to do. Rerun Hitman and have it remove all the Potentially Unwanted Programs, reboot and rescan. Also tell me how things are running now.

    What browsers are you using?
     
    Last edited: Sep 6, 2015
  6. Twistid

    Twistid Corporal

    Ran a rescan with Hitman and removed the items it detected. Restarted and ran a scan again with it and saved the log (as attached). It did not have any results with the new scan.

    So far it seems to be running fine. I will do some more system maintenance to get a better feel for how it's running, but it does seem to be running more smoothly now.

    I was mostly using Firefox to access the internet myself. The owner of the computer I believe usually uses Google Chrome.
     

    Attached Files:

  7. Twistid

    Twistid Corporal

    Correction: The person who usually uses this computer is usually using Firefox.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are the browsers acting properly?
     
  9. Twistid

    Twistid Corporal

    Internet Explorer and Firefox seem to be working fine.

    Google Chrome keeps resulting in an error when trying to check for updates though. And for some reason the Internet Explorer icon on the taskbar actually starts up Google Chrome instead.
     
  10. Twistid

    Twistid Corporal

    The error message says: "Update failed (error: 3)An error occurred while checking for updates: Update check failed to start (error code 3: 0x80080005 -- system level)."
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those are issues you should pursue in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds